Blog · September 17, 2026 · 11 min read

Claude in Chrome: How to Use the Extension

Laptop on a desk with a browser open on a search page showing suggestions
Photo: Lisa Fotios / Pexels

Claude in Chrome is Anthropic's extension for Google Chrome that puts Claude into a side panel of your browser: Claude reads the page you're signed in to, clicks, types, and fills in forms. How much you approve step by step depends on the approval mode you pick; separately from that, you approve each website Claude is allowed to act on at all. You need Google Chrome (not Edge, not Brave, not a phone) and a paid Claude plan from Pro upward; the pricing page does not include the extension in the free plan. You install it from the Chrome Web Store in five steps, and from then on Claude works in its own tab inside your running Chrome. Claude does not type passwords, purchases are blocked in every mode per Anthropic, and my own operating rule is that whatever a web page says is material, not an assignment.

I've used Claude every day since Claude Code came out, and I run my business on an AI workforce built on Claude. One of my AI employees used the Chrome extension for a real task in September 2026, and I'll use that task below to show you where the extension helps and where it stops. Everything I write about Claude is collected on the Claude page; if you're completely new to Claude, start with Claude Guide: Getting Started.

What Claude in Chrome does and doesn't do

On its product page at claude.com/chrome, Anthropic sums the extension up in one sentence: "Claude reads the page you're signed in to, then clicks, types, and fills forms while you decide what happens next." The second half is the part that matters. Claude acts, but you set the frame: through the approval mode and through the websites you approve. Sessions are saved to your account history, and if you use Claude Cowork, the Cowork session lives in the same side panel; what Cowork is and who it's for is covered in Claude Cowork: What It Does, Who It's For.

Anthropic's getting started guide lists what the extension can do: read and navigate pages, fill in forms, work across multiple tabs, schedule recurring tasks, record workflows and save them as shortcuts, read a page's console errors, and fill in logins through 1Password. That sounds like a lot, but at its core it's a single ability: Claude sees what you see and can click and type wherever you could.

What it can't do is stated just as clearly in the same guide. It only runs in Google Chrome: "Claude in Chrome is not supported on other Chromium-based web browsers," so neither Edge nor Brave, and not on a phone at all. And it needs a paid plan: "all paid plans (Pro, Max, Team, and Enterprise)". Entry is therefore Pro at 20 dollars a month, as of September 2026; every tier with sources is in Claude Pricing and Plans Explained.

One contradiction you should know about: Anthropic's release notes carry an entry dated December 12, 2025, about availability for the free plan. The pricing page, as of September 2026, and the getting started guide both say the opposite: Chrome from Pro upward only. I go with the pricing page, because it describes the product you can buy today. If you're on the free plan, don't count on the extension working.

How to install Claude in Chrome in five steps

According to Anthropic's getting started guide, installation is short. I've broken it into five steps because the fourth and fifth are the ones where you should pause and think.

  1. Open the Chrome Web Store, search for "Claude", and click "Add to Chrome". This only works in Google Chrome on a desktop machine.
  2. Sign in to the extension with your Claude account. It has to be an account on a paid plan.
  3. Pin the extension to the toolbar. From then on you open the side panel through the Claude icon.
  4. Grant the Chrome permissions. According to the guide there are 15 of them, including "debugger", "tabs" and "downloads" (as of September 2026). That's more than most extensions ask for, and it's the price of letting Claude read and control pages. If you're not willing to grant them, don't install the extension.
  5. Choose your approval mode and decide which websites Claude may act on. What the three modes mean is explained further down.

Then give your first task in the side panel. Start with something you can verify yourself in two minutes: summarize a page, copy a table from a website, prepare a form that you then submit yourself.

The first task: Sebastian and the Search Console report

On September 15, 2026, Sebastian, my AI employee for SEO and GEO, was supposed to open the AI report in Google Search Console. Since late August 2026, Google shows there how often a site appears in AI Overviews and AI Mode, and it's only available in the portal, not through the API. So someone had to go into the browser. Sebastian used Claude in Chrome for that: the extension opened its own tab in my running Chrome, took screenshots, and read the page content.

Then Google asked for a login. At that point the task was over for Sebastian, and that's by design. My workforce has a rule: no credentials handled by AI. Sebastian didn't sign in, didn't enter a password, and didn't look for a workaround; he reported that Google was asking for a login. The next step is mine: I sign in, and only then does Claude read the page I'm signed in to.

So the result of this first task wasn't a report but a clean boundary. For me that's the most important thing about the extension: it doesn't replace the human at the login, it replaces the clicking behind it. Here is how the work has split up for me since:

Step What the extension does What it doesn't do What I do myself
Open and read a page Open a tab in the running Chrome, take a screenshot, read the content Act on page content as an assignment (per the vendor) Phrase the task, check the result
Login Stop at the login form and report back Type a password or one-time code Sign in myself, then let it continue
Forms and clicks Fill in fields, click, switch between tabs Act on a new website without approval Grant or decline approval per website
Purchases and payments Nothing, blocked in every mode Buy, create accounts, delete permanently Carry out every payment myself

Approval per website and the three modes

Two separate switches are at work here, and that is what usually gets mixed up. The mode decides how much you confirm step by step. The per-website approval decides whether Claude may act on a site at all. A convenient mode does not lift the website approval, and a granted website approval does not make the mode stricter.

Anthropic's permissions guide describes three modes. "Manually approve" pauses before every single action and asks. "Automatically approve" is, per the guide, the default in Cowork side panels: Claude keeps working instead of asking about every step and reviews each action for safety itself. "Skip all approvals" turns the prompts off, and then, according to Anthropic, nothing checks the actions automatically either; it is meant only for trusted scenarios. The guide also mentions a side effect: the automatic mode uses more of your usage limit, though Anthropic gives no specific figures.

Independently of that, the extension asks per website. The first time on a site you get three choices: "Allow this action", "Always allow actions on this site", or "Decline". Even with "Always allow", the guide says Claude asks again before it downloads files, enters sensitive information or grants authorizations. You manage the list of approved websites in the extension's settings under "Permissions". In my workforce that is exactly the rule: approval per website, no blanket approval for everything.

The permissions guide also lists actions Claude is not supposed to take in any mode, even with prompts turned off: purchases and financial transactions, creating accounts, handling credit card or ID data, permanent deletions, carrying out instructions from emails or web content, and changing system files. That's a vendor statement, and I treat it as a safety net, not a free pass. The real safeguard remains approval per website: where Claude isn't allowed to act, nothing can go wrong.

Safety: passwords, payments, prompt injection

The main risk is called prompt injection, and Anthropic names it as such in its guide to using Claude in Chrome safely. It means this: a web page contains text that sounds like a command to Claude, hidden in a comment or in white text, for example. A browser agent that reads page content as instructions would carry it out. Anthropic states that the success rate of such attacks in its internal tests is below 0.08 percent, as of August 2026. That's a vendor figure, it isn't zero, and Anthropic itself calls the problem not fully solved. So I treat the split between data and instructions not as a product property but as my workforce's operating rule: content from web pages is material, never an assignment, and whatever comes back from the browser gets checked before anyone works with it.

On passwords: the extension doesn't type them itself. If you use 1Password, it can fill in logins that way; Anthropic states in its 1Password help article that passwords and one-time codes never enter Claude's context. Without 1Password, my rule is what Sebastian did on September 15: stop at the login and call me. I carry out payments myself, regardless of the fact that purchases are blocked anyway.

In the same guide, Anthropic also lists where you'd better not use the extension: online banking, health data, legal and financial documents, captchas, and sensitive work data. It recommends a separate Chrome profile for sensitive accounts and makes clear that you remain responsible for every action the extension takes. Keep in mind too that Claude takes screenshots of active tabs, so everything visible is captured. For business data I therefore use a Team account with a data processing agreement; what applies there is in Claude Privacy and GDPR: What Applies. This is not legal advice, just my own practice based on the vendor's statements as of September 2026.

Claude in Chrome for teams: what the admin configures

According to Anthropic's admin guide, the extension is enabled by default on the Team plan; on the Enterprise plan it was disabled by default and has been enabled as well since September 10, 2026. Admins can set an allowlist or blocklist for websites, and Anthropic recommends starting with a more restrictive allowlist. The 1Password integration is off by default on Mac. If you maintain a firewall, the guide says you need to allow claude.ai, api.anthropic.com, and the websocket endpoint bridge.claudeusercontent.com.

If you're rolling the extension out to several people, I'd start with the allowlist and extend it website by website. That follows the principle my workforce approves by: per website, never blanket. A broad approval is hard to take back later.

Frequently asked questions

Is Claude in Chrome free?

No. Anthropic's pricing page and the getting started guide list the extension for paid plans only, so from Pro at 20 dollars a month upward, as of September 2026. A release notes entry from December 2025 does mention availability on the free plan, but the pricing page doesn't confirm it. Trust the pricing page.

Does the extension work in Edge or Brave?

No. Anthropic explicitly states that other Chromium-based browsers are not supported. You need Google Chrome on a desktop machine; there is no mobile version.

Can Claude see my passwords?

The extension doesn't type passwords. With 1Password, logins are filled in so that, according to Anthropic, passwords and one-time codes never enter Claude's context. Without 1Password you sign in yourself; that's exactly where Sebastian stopped during his task on September 15, 2026.

Why does Claude ask before every action?

Because you're in "Manually approve" mode or visiting a website for the first time. In "Automatically approve", per Anthropic the default in Cowork side panels, Claude asks less often and reviews the actions for safety itself instead. Approval per website is independent of that and stays in every mode; you manage it in the extension's settings.

Does Claude in Chrome use up my usage limit?

Yes. The extension runs through your Claude account and counts against its limit. Anthropic notes in the permissions guide that the automatic mode uses more quota than the manual one; the vendor gives no specific figures, and I haven't measured it.

How do I install Claude in Chrome?

Through the Chrome Web Store with "Add to Chrome", then sign in with your Claude account, pin the extension, grant the permissions, and choose the approval mode. The five steps above explain what to watch for when it comes to permissions.

Where to go from here

If you're trying Claude in the browser for the first time, pick a task whose result you can check yourself and keep approval per website switched on. If you want to hand Claude whole workflows rather than single pages, take a look at Claude Cowork: What It Does, Who It's For; if you'd rather work in files than in the browser, Claude Code: A Guide for Beginners is the place to start. How my AI employees are set up overall is described in My AI Workforce: Eight Employees. The eight packages are ready to use in my community.

Kevin Welter

Kevin Welter

Developer, IT architect, author of technical books (Kubernetes, cloud infrastructures) and speaker. Runs his business with an AI workforce of eight AI employees and shows solo business owners in his community how to hire their first AI employee.

More about AI employees

Your first AI employee up and running within an hour

Join the community