Browser Provisioners
Browser provisioners automate or guide a web UI flow and return secret values.
Use them when a service lacks a stable API for credential creation or you want a repeatable “click path” for OAuth setup.
Notes:
- Browser flows are brittle. UI changes can break them.
- Provisioners often output multiple keys (client id + client secret).
- Engines:
stagehand(AI-assisted) orplaywright(recorded JSONL).
Schema shape
Section titled “Schema shape”{ "kind": "browser", "name": "github-oauth", "label": "GitHub OAuth", "engine": "stagehand", "browser": { "startUrl": "https://github.com/settings/developers", "userDataDir": "$XDG_STATE_HOME/lazyenv/chrome-profile", "headless": false, "loginCheck": { "urlMustContain": "github.com" } }, "steps": { "type": "stagehand", "items": [] }, "provides": ["GITHUB_CLIENT_ID", "GITHUB_CLIENT_SECRET"]}For Playwright, set engine: "playwright" and steps.type: "playwright-jsonl" with a JSONL file.
Stagehand model
Section titled “Stagehand model”For engine=stagehand, select LLM provider/model via LAZYENV_STAGEHAND_MODEL (default: openai/gpt-4.1-mini).
Built-ins: see Built-in Provisioners.