Skip to content

Set Navigation Policy Node

Automation/Browser/Navigation

Restricts where Go To and Execute Browser Action Plan may navigate in this session: URL schemes, domain allow and block lists, and private network addresses. The final URL after redirects is checked too; a blocked landing page is left for about:blank and the node fails. Requests the page makes on its own are not filtered.

browser_set_navigation_policyautomationLocal only
Inputs7
Outputs3
Security exposure9/10
Packageautomation

Ratings

Scores range from 0 to 10. Higher values mean more impact, exposure, or operational weight.

SecurityAttack surface and exposure impact.
9/10High
PrivacyPotential sensitivity of processed data.
7/10High
PerformanceRuntime or resource pressure.
9/10High
GovernancePolicy, audit, or compliance impact.
9/10High
ReliabilityOperational stability considerations.
8/10High
CostExternal or compute cost impact.
10/10High

Input Pins

7

▶

Execution
exec_in

Trigger

Session

Struct
session

Automation session

AutomationSessionAutomationSession11 fields
session_refstringrequired
platformPlatformrequired
enum "Windows", "MacOS", "Linux"
default_delay_msinteger:uint64required
format uint64min 0
click_delay_msinteger:uint64required
format uint64min 0
debug_modebooleanrequired
browser_typeanyOf (2)

Browser context info if browser is attached

variant 1BrowserTypevariant
enum "Chrome", "Firefox", "Edge", "Safari"
variant 2nullvariant
browser_headlessboolean | null
browser_user_data_dirstring | null
current_page_refstring | null

Current page info if a page is open

current_window_handlestring | null
browser_frame_selectorsArray<Selector>
default []
itemsSelectorarray item
kindSelectorKindrequired
variant 1enumvariant
enum "Css", "Xpath", "TextExact", "TestId"...
variant 2constvariant

Visible text contained in the element; script, style and head content is ignored.

const "Text"
variant 3constvariant

ARIA role, optionally filtered by accessible name: `button`, `button|Sign in` (case-insensitive substring), `button|=Sign in` (exact) or `button|/^sign/i` (regex).

const "Role"
variant 4constvariant

Element ref from the latest Browser Snapshot, such as `e12`.

const "Ref"
valuestringrequired
confidencenumber | null
format double
scopestring | null

Enabled

Boolean
enabled

Disable to remove the policy and restore the default rules (privileged schemes such as file: and javascript: stay blocked)

Default true

Allowed Schemes

String Array
allowed_schemes

URL schemes that may be opened; empty allows all except file, javascript, chrome, edge, devtools and view-source

Default ["http","https"]

Allowed Domains

String Array
allowed_domains

Host globs such as example.com or *.example.com; empty allows any host

Default []

Blocked Domains

String Array
blocked_domains

Host globs that are always blocked

Default []

Block Private Networks

Boolean
block_private_networks

Block loopback, private, link-local and cloud metadata addresses (hosts are resolved; unresolvable hosts are blocked)

Default true

Output Pins

3

▶

Execution
exec_out

Continue

Session

Struct
session_out

Updated automation session

AutomationSessionAutomationSession11 fields
session_refstringrequired
platformPlatformrequired
enum "Windows", "MacOS", "Linux"
default_delay_msinteger:uint64required
format uint64min 0
click_delay_msinteger:uint64required
format uint64min 0
debug_modebooleanrequired
browser_typeanyOf (2)

Browser context info if browser is attached

variant 1BrowserTypevariant
enum "Chrome", "Firefox", "Edge", "Safari"
variant 2nullvariant
browser_headlessboolean | null
browser_user_data_dirstring | null
current_page_refstring | null

Current page info if a page is open

current_window_handlestring | null
browser_frame_selectorsArray<Selector>
default []
itemsSelectorarray item
kindSelectorKindrequired
variant 1enumvariant
enum "Css", "Xpath", "TextExact", "TestId"...
variant 2constvariant

Visible text contained in the element; script, style and head content is ignored.

const "Text"
variant 3constvariant

ARIA role, optionally filtered by accessible name: `button`, `button|Sign in` (case-insensitive substring), `button|=Sign in` (exact) or `button|/^sign/i` (regex).

const "Role"
variant 4constvariant

Element ref from the latest Browser Snapshot, such as `e12`.

const "Ref"
valuestringrequired
confidencenumber | null
format double
scopestring | null

Policy

Struct
policy

The policy now in effect

NavigationPolicyNavigationPolicy4 fields
allowed_schemesArray<string>

Allowed URL schemes such as `http` and `https`. When empty, every scheme except the privileged ones (file, javascript, chrome, chrome-untrusted, edge, devtools, view-source) is allowed; privileged schemes are only allowed when listed.

default []
itemsstringarray item
allowed_domainsArray<string>

Host globs such as `example.com` (that host only) or `*.example.com` (its subdomains). Empty allows any host. URLs without a host (about:, data:) are governed by schemes only.

default []
itemsstringarray item
blocked_domainsArray<string>

Host globs that are always blocked; checked before the allowlist.

default []
itemsstringarray item
block_private_networksboolean

Blocks hosts that are, or resolve to, loopback, private, link-local, CGNAT, multicast or cloud metadata addresses. Hosts that cannot be resolved are blocked too.

default false

Node Info

Internal name
browser_set_navigation_policy
Category
Automation/Browser/Navigation
Version
1