How the integration works
The integration has four boundaries:- Collect. Use Evervault’s Card component or another Evervault collection method. Store an encrypted PAN only under your reviewed retention policy; treat CVC as transaction-specific and do not retain it after authorization, even encrypted.
- Tokenize. Immediately before a browser task, call Evervault’s Browser Tokens API with the encrypted values, a short time-to-live (TTL), and the exact destination hostnames that may receive plaintext.
- Launch. Create a Browserbase session with the proxy configuration returned by Evervault. If the proxy intercepts TLS, add the Evervault CA certificate to the Browserbase project and reference it when creating the session.
- Automate. Give the agent or automation only the token values. Evervault replaces those values with plaintext when an allowed request leaves the browser through its proxy.

When to use this integration
Use Browserbase and Evervault when:- an agent must complete an existing website checkout or login flow;
- the workflow needs a payment card, password, API key, recovery code, or another secret;
- your browser provider should not receive plaintext sensitive data; or
- you need to preserve the format expected by a merchant form, such as a Luhn-valid card number.
PCI DSS considerations
Browserbase and Evervault split the browser workflow so that the systems driving the browser can work with tokens instead of plaintext cardholder data:- Evervault hosts the Card component, encrypts the card fields, and reveals the underlying values only through its proxy to an allowed merchant or payment-provider hostname.
- Your backend creates short-lived Browser Tokens from encrypted PAN and transaction-specific encrypted CVC. It should not decrypt or log these values, and must not retain CVC after authorization, even encrypted. Any encrypted PAN storage must follow your reviewed retention policy.
- Your agent, automation code, and Browserbase receive format-preserving tokens and proxy credentials, not the original card number or security code.
- The merchant or payment service provider receives the original values over the network when the browser submits the checkout request.
Next steps
Browser Tokens quickstart
Collect a card, create short-lived tokens, and launch Browserbase with the
Evervault proxy.
Evervault Card Collection
Collect encrypted card data inside an Evervault-hosted iframe.