> ## Documentation Index
> Fetch the complete documentation index at: https://docs.crossmint.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create Browser Profile

> Create a subject-scoped browser profile: a durable browser identity that lets a user's merchant login be reused across checkout runs instead of signing in on every run.

A user has at most one browser profile, and it accumulates saved state across merchants.

**API scope required**: `agent-checkouts.browser-profiles.create`



## OpenAPI

````yaml post /unstable/agent-checkouts/browser-profiles
openapi: 3.0.3
info:
  title: Crossmint Agent Checkouts API
  version: unstable
  description: >-
    Drive a real, automated browser session through any merchant's checkout on
    behalf of a signed-in user.


    You hand the API a product URL, an optional natural-language instruction,
    and a hard maximum cost. Crossmint runs a browser through the merchant's
    checkout pages, pausing for *user actions* (shipping, payment, anything only
    a human can answer) which you respond to with values that satisfy a supplied
    JSON Schema. There are no webhooks in v1 — poll the checkout until it
    reaches a terminal state.


    ## Base URL


    `https://www.crossmint.com/api` (production) ·
    `https://staging.crossmint.com/api` (staging)


    ## Authentication


    Every request requires **two** credentials:


    - `X-API-KEY` — a client-side API key (`ck_...`) with the
    `agent-checkouts.*` scopes.

    - `Authorization: Bearer <jwt>` — a JWT identifying the end user, issued by
    an external auth provider your project trusts. Without it the API returns
    `401`.


    <Note>This API lives under the `unstable` namespace. The schema may change —
    pin and re-test on upgrades.</Note>
servers:
  - url: https://www.crossmint.com/api
    description: Production
  - url: https://staging.crossmint.com/api
    description: Staging
security:
  - ApiKeyAuth: []
    BearerAuth: []
tags:
  - name: Agent Checkouts
    description: Create, poll, respond to, and cancel browser-driven checkouts.
  - name: Buyer Profiles
    description: >-
      Subject-scoped buyer identity and shipping address the agent can prefill
      during a checkout run. Payment data is never stored.
  - name: Browser Profiles
    description: >-
      Subject-scoped browser identity that lets a user's merchant login be
      reused across checkout runs. Crossmint stores metadata only: the saved
      browser state is held by our browser infrastructure and never returned.
paths:
  /unstable/agent-checkouts/browser-profiles:
    post:
      tags:
        - Browser Profiles
      summary: Create Browser Profile
      description: >-
        Creates a subject-scoped browser profile: a durable browser identity
        that lets a user's merchant login be reused across checkout runs instead
        of signing in on every run. A user holds at most one profile, and it
        accumulates saved state across merchants. Returns the created profile.


        **API scope required**: `agent-checkouts.browser-profiles.create`
      operationId: createBrowserProfile
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateBrowserProfileRequest'
            examples:
              Labelled profile:
                summary: Create a profile with a label
                value:
                  label: Shopify Stores
      responses:
        '201':
          description: The browser profile was created.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/BrowserProfile'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '409':
          $ref: '#/components/responses/BrowserProfileConflict'
components:
  schemas:
    CreateBrowserProfileRequest:
      type: object
      properties:
        label:
          type: string
          minLength: 1
          maxLength: 120
          description: Optional human-readable label for the profile.
    BrowserProfile:
      type: object
      description: >-
        The browser profile, returned by create, get, list items, and update.
        Metadata only — no cookies, tokens, or local storage.
      required:
        - id
        - createdAt
        - updatedAt
      properties:
        id:
          type: string
          format: uuid
          description: >-
            The browser profile id. Pass it as `browserProfileId` when creating
            a checkout.
        label:
          type: string
          minLength: 1
          maxLength: 120
          description: Optional human-readable label for the profile.
        createdAt:
          type: string
          format: date-time
        updatedAt:
          type: string
          format: date-time
          description: When the label was last changed. Checkout runs do not update it.
    Error:
      type: object
      properties:
        statusCode:
          type: integer
        error:
          type: string
        message:
          type: string
  responses:
    BadRequest:
      description: The request body or parameters were invalid.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    Unauthorized:
      description: >-
        Missing or invalid authentication. A valid `X-API-KEY` and
        `Authorization: Bearer <jwt>` are both required.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    Forbidden:
      description: >-
        The API key lacks the required scope, or Agent Checkouts is not enabled
        for this project.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    BrowserProfileConflict:
      description: The user already has a browser profile.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: X-API-KEY
      description: Client-side API key (`ck_...`) with the `agent-checkouts.*` scopes.
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        JWT identifying the end user, issued by an external auth provider your
        project trusts.

````