Network Access
Restrict a stealth session to a fixed list of hosts. Requests to anything outside the list are refused before they reach the destination.
How to turn it on
Pass allowedDomains to sessions.create(). It requires stealth: true — the same precondition as proxies and captcha solving.
await client.sessions.create({
stealth: true,
allowedDomains: ["example.com", "api.example.com"],
})A domain on the list also covers its subdomains: example.com matches example.com and any *.example.com, but not otherexample.com. The match is case-insensitive.
What a refusal looks like
A request to a host that isn't on the list is refused at the point the browser tries to connect — the navigation or subresource fetch fails, the same way it would against a network that's simply unreachable. Driving the browser yourself (rather than just calling page.goto), you'll see a tunnel failure such as Chromium's ERR_TUNNEL_CONNECTION_FAILED.
Creating a session with allowedDomains but without stealth: true is refused up front:
{ "error": "allowedDomains requires stealth: true" }With a managed proxy
Allowlist enforcement runs on the host your browser is trying to reach, checked before any connection is made — it works the same way whether or not you've also turned on a managed proxy. With a proxy, that check is the only thing standing between your browser and the open internet; without one, there's a second, independent layer behind it. Either way, a host outside your list is refused.
allowedDomains stops the browser from connecting to a host outside your list. It does not stop a DNS lookup for that host's name from resolving — a lookup can succeed and return an address without the browser ever being allowed to use it. If your own threat model depends on third parties being unable to tell whether a given hostname exists, treat that as outside what this feature covers.