Extensions have entered the AI age.Install the extension

Control belongs inside the work.

Moxby keeps browser capabilities scoped, makes connected services explicit, and puts review beside the place where an agent acts.

Local browser layerMods, working state
Explicit routesPermissions, review, scoped context
Connected servicesChosen websites, model services, Desktop Bridge

Four principles shape the boundary.

Security is strongest when a person can see what the system knows, where it can act, and what still requires a decision.

01

Keep browser software local by default.

Mods and their working state are designed to run locally through the Moxby extension. You choose the websites and connected services a capability needs to reach.

02

Make permission boundaries legible.

A Mod is scoped to matching sites and approved behavior. Mods and Missions disclose the browser or Bridge capabilities they need. Controls should be understandable before the work runs.

03

Keep consequential actions reviewable.

Missions stage consequential external actions for review by default. Run history, evidence, errors, and KPI readings stay attached to the outcome.

04

Separate product access from model usage.

API model calls route through OpenRouter. Supported ChatGPT and Claude authentication uses the Desktop Bridge. Moxby keeps these paths visible in usage reporting.

Controls follow the surface.

There is no single permission switch that can explain every kind of work. Moxby puts the relevant boundary beside the website, Mod, Mission, model connection, or Bridge capability that needs it.

Extension and Mods

Choose the sites a Mod can match, review the proposed behavior, and keep the added capability inside your browser rather than publishing changes to the original application.

Mods and local applications

Install focused browser apps with a clear purpose and permission surface. Mods that use connected services should disclose those connections before you rely on them.

Missions and external actions

Define the KPI, source of truth, cadence, and operating bounds. External messages are staged for review by default so autonomous work does not require invisible outbound behavior.

Moxby Chat and model access

Use supported ChatGPT and Claude authentication through the Desktop Bridge or explicit OpenRouter API access. Model requests contain the context required for the active call.

Desktop Bridge capabilities

The Bridge extends Moxby to approved local files, applications, authentication, and operating-system capabilities that a browser extension cannot safely provide alone.

Website free tools

Planning tools send approved requests through OpenRouter without exposing provider credentials in browser code. Tool inputs should still exclude credentials and sensitive records.

Autonomy with a visible evidence trail.

Moxby is designed to let agents do real work while keeping the inputs, changes, evidence, and handoff close enough for a person to inspect.

1

Define the scope

Choose the project, site, room, KPI, or source of truth that frames the job.

2

Run inside the boundary

The agent uses the attached work, approved tools, and current context to move the job forward.

3

Keep the evidence

Mission runs, browser actions, local changes, screenshots, KPI readings, and linked evidence show what changed.

4

Review the consequence

Inspect consequential changes and stage outbound communication before it leaves the approved boundary.

Security, plainly stated.

What stays local, what connects, and where review belongs.

Does Moxby keep everything only on my computer?

Mods are designed around local browser execution, but connected work can still reach websites, OpenRouter, supported model services, and Desktop Bridge capabilities you approve. These boundaries should be explicit.

How are model calls handled?

API model calls use OpenRouter. The model request contains the context needed for that call, including any eligible rasterized context. Model usage is separate from the Moxby subscription.

Can an agent send messages without review?

Missions stage external messages for review by default. A team can define the operating loop and work cadence while keeping outbound communication in a visible approval step.

Where should credentials be stored?

Use the supported secure authentication or secret surfaces provided by Moxby and the Desktop Bridge. Do not place credentials or production secrets in ordinary prompts or public tool inputs.

Does this page claim a security certification?

No. This page explains current product boundaries and operating controls. It does not claim a certification, compliance attestation, or audit that has not been explicitly published by Moxby.

Keep control close to the work.

Install Moxby and evaluate its Mods, Missions, Chat, and connected Desktop Bridge capabilities inside one visible browser workflow.

Install Moxby Extension

Four connected ways to work in your browser.

Chat on any page, build Mods, run Missions, and add ready-made products from the Marketplace.