Four chase emails drafted, in your own outbox
A Strawberry companion drives the browser on your own machine, scoped to one profile, with no credential copied anywhere else and a card before anything sends.
Ask for the four quotes nobody has signed, one nudge each, in the sender’s own voice, and four drafts appear in your own outbox, on the machine that already holds the logins. Nothing sends until you have read them.
Strawberry is an agentic browser for macOS and Windows with 93 native integrations carrying 1,257 hand-written operations, 1,975 further apps connectable as accounts, and your own logged-in session for whatever has neither. Routines fire on a daily time, an interval, a cron expression or an app trigger, each with its own run history. Keep Awake holds the Mac or PC awake, so a scheduled run finishes with the lid closed. Ask Always mode in Settings → AI permissions puts a card in front of every action.
xAI documents Bots as AI teammates that “can sign in and use apps and websites just like you do on a persistent cloud computer”, with a browser, filesystem and terminal, connectors and MCP where available, computer use for anything without a clean API, skills, routines that fire on a schedule or after an event where supported, and an approval flow with allow-once, deny and always-allow.
The same docs name the trade. Cloud work continues after you close the app, and every Bot on your account shares one computer, so browser cookies, signed-in sessions, files and command-line credentials are shared between them. xAI notes the per-Bot screens as separate work surfaces rather than separate security boundaries. The broader version of this argument is at cloud browser agents vs local agentic browsers.
| Strawberry | ||
|---|---|---|
| Where the browser runs | A persistent cloud computer xAI operates | The browser on your Mac or Windows machine |
| Whose sessions | Signed in inside that computer, shared across your Bots | Yours, already open, on your hardware |
| Laptop closed | Work continues in xAI’s cloud | Keep Awake holds your machine awake so routines finish |
| MFA and CAPTCHA | You take over the remote computer for that step | Usually already satisfied on the trusted device |
| Approvals | Allow once, deny, always allow | Approval card per consequential action, or Ask Always for all |
| Connected accounts | Connectors and MCP where available | About a hundred you authorise, reads and staged writes |
Which computer ends up holding your logins?
Yours.
The sessions are the ones already in your browser, on your hardware, scoped to one profile. Nothing is re-authenticated elsewhere and nothing persists in a datacenter, and Keep Awake holds the machine up so a routine still finishes with the lid closed.
With a cloud agent you sign into your accounts inside the vendor’s environment once, and the sessions persist there. xAI is upfront about the consequence: because the computer is shared across your Bots, a credential or file placed on it is reachable by any of them.
Approvals, side by side
Strawberry’s card sits in front of the consequential action and names it, and Ask Always mode in Settings → AI permissions turns every step into a stop. An action approved here happens in the session already on your machine, so there is no second copy of your logged-in state anywhere to think about. The full model is at /security.
xAI documents allow-once, deny and always-allow controls, tells you to set explicit boundaries in the request, and notes that an approval controls the proposed action and does not reverse work already completed.
What happens when a site asks for a code?
Usually nothing, because the device the site trusts is the device the work is happening on. Your MFA already happened this morning, the cookie is in the browser, and the tab opens. It shows up ten times a week. The mechanics are at how do AI agents log into websites.
xAI's docs describe taking over the shared computer to complete a password, passkey, two-factor prompt, CAPTCHA or payment step, then telling the Bot to continue, and advise against pasting one-time codes into chat.
What to hand over first
Start with the runs that end inside an account you already own:
- The 50 accounts in your book, checked against every company site this month, with the six worth a call named.
- Anything that ends in a change inside a tool you are signed into, with the approval card in front of it.
- Anything involving a credential you would not paste anywhere, kept on the machine that already holds the session.
- The recurring pass nobody remembers: save it as a routine and turn on Keep Awake so it finishes overnight.
- The sorted-by-role version of the same list is the agentic work index.
Experience Strawberry for free
DownloadTrusted by fast-growing companies worldwide
Frequently asked questions
Strawberry is free to download and includes AI credits to start. Paid plans begin at $20/month. See pricing. · Reviewed · Canonical facts for AI agents