Frequently asked questions
What Rindler is, how it keeps your sign-ins secure, how to wire it into your own agent, and what it costs.
What Rindler is & how it's different
What is Rindler?
Rindler signs into the websites your team already uses and does the work there: downloading statements and invoices, pulling records, checking statuses, and submitting forms. It maps the site, proves the mapping works by testing it against the real site, and keeps it working when the site's design changes, so your team never hits a broken login or a stale form. No scraping, no API key required. Founded in 2025 and backed by Y Combinator.
What can AI agents do with Rindler?
With Rindler, AI agents can search sites, pull structured data like listings and prices, fill out forms, complete multi-step flows, and add items to a cart for checkout, across almost any website, not just stores. Rindler turns each supported site into a typed, reliable tool your agent calls, so one agent can research, pull data, and take actions across the web. Shopping is just one of them.
Can an AI agent shop online and buy things for me?
Yes, an AI agent can shop online for you by searching real sites, comparing prices, and building a cart you check out yourself. With Rindler, you ask an AI agent at chat.rindler.ai to run the task and it replies with structured cards like a shopping list or cart handoff. For carts on third-party sites, the cart hands off and you check out directly on that site. Rindler does not collect your card details or process the merchant's payment.
Can I connect ChatGPT or Claude to Rindler to take actions on websites?
Yes. Connect any MCP-capable agent (ChatGPT, Claude, Claude Code, Cursor, Devin Desktop, or Codex) to Rindler and it can take real actions on live websites: search, pull data, fill forms, and check out. Rindler turns each site into a structured, typed tool your agent calls, returning verified structured records instead of raw HTML. No API key required.
How is Rindler different from web scraping?
Rindler returns structured, deterministic data instead of raw scraped HTML. Where DOM scrapers break instantly when a site's UI changes, Rindler's site configs are self-healing and adapt automatically. Each supported site becomes a typed API, so your agent gets compact structured JSON (a few hundred tokens) rather than a roughly 50k-token raw DOM dump.
What does an AI agent get back from Rindler?
Structured JSON, not raw HTML. Every Rindler call returns a compact record set your agent reads directly by field, never a DOM to parse. A response carries a screen identifier, persistent context (cart contents, delivery address), screen-specific data (products, listings, transactions), and an available_actions array with typed params. It is typically a few hundred tokens, versus the roughly 50,000 tokens of nav, footer, sidebar, and tracking markup a raw page fetch returns.
Is Rindler only for shopping, or does it work on any website?
Any website, not just stores. Rindler is horizontal infrastructure for sites that were never given a usable API. That includes legacy portals, private SaaS dashboards, government registries, supplier and payer portals, applicant tracking systems, and multi-step forms. Shopping is one category among many. Each supported site becomes the same kind of typed, structured tool your agent calls, whether it sells sneakers or files documents.
Can Rindler operate internal or private dashboards that have no API?
Yes. If you can reach it in a browser, Rindler can drive it, including legacy portals and private SaaS dashboards with no API. Your agent opens a session on the target portal, authenticates the way your team does, dispatches the mapped action, and gets structured records back instead of a screen to parse. Each site is mapped individually and ships only after an automated verifier passes it against the real site.
How is Rindler different from Browser Use, Firecrawl, or raw Playwright?
Those tools drive or scrape a page live on every run; Rindler calls a pre-mapped, verified config that returns structured records. Instead of an LLM re-reading the DOM each time, or a script chasing CSS selectors that break on redesign, Rindler exposes each site as deterministic typed actions, with an automated verifier gating every mapping and self-healing configs that adapt when a layout changes. On one illustrative grocery task, the mapped path finished in 98 seconds instead of 407 and cost $0.26 instead of $1.54.
Security & privacy
Does Rindler store my passwords?
For most sites, no. You sign in yourself, and Rindler never sees your password. You log in inside a Rindler-managed browser on the real site, and Rindler keeps only the resulting session cookies, encrypted with AES-256-GCM under a per-user key. For a limited set of sites, you can optionally let Rindler securely store your credentials so it can sign in for you. That option is opt-in, per site, and encrypted.
How do I sign in to a gated site through Rindler without giving it my password?
Most sign-ins are a one-time, hands-off step. Rindler opens a single-use link (it expires in 15 minutes) to a Rindler-managed browser on the site's login page, you sign in yourself including MFA, then click "I'm logged in." Rindler keeps only an AES-256-GCM-encrypted session scoped to you and that one site, reused on later runs until that stored session expires. On some sites a login is tied to a single live browser, and there you sign in per task. For sites you use often, you can instead opt in to let Rindler securely store your credentials and sign in for you.
Does Rindler handle or store my credit card?
No. Rindler does not receive or store payment-card numbers. Stripe collects and processes card details and billing contact data for Rindler subscriptions. Rindler stores only the payer email and the identifiers, amount, currency, and status needed to reconcile billing. For carts built on third-party sites, the cart hands off so you check out directly with that merchant.
Does Rindler send my chat data to AI providers, and is it used to train their models?
Yes, Rindler sends your messages, system prompt, and tool results to Anthropic (Claude), and to OpenAI (GPT) when you select it, but it opts out of training and default retention. Anthropic's default API tier does not train on inputs, and OpenAI requests are sent with store:false to opt out of default retention. Your name, email, and Clerk ID are never sent as request metadata.
What third-party services does Rindler use, and who does it share my data with?
Rindler's published sub-processors are Clerk, Anthropic, OpenAI, Amazon Web Services (AWS), Porter, Sentry, PostHog, Cloudflare, Kernel, Browserbase, BrightData, Capsolver, Resend, Stripe, Slack, and Infisical. Rindler does not sell or share your personal information with advertisers or data brokers, and it uses no ad trackers, fingerprinting, or session-replay. See Rindler's published privacy policy or email founders@rindler.ai for the full list.
Can I delete my data from Rindler?
Yes, Rindler lets you delete your data. Rindler honors access, correction, and deletion requests within 30 days, and you can revoke any authenticated session, which deletes the encrypted cookie record. GDPR and CCPA rights are honored, and you can set chat history to auto-delete after 7, 30, or 90 days. Email founders@rindler.ai to exercise these rights.
Is Rindler SOC 2 certified?
Rindler is actively working toward SOC 2 certification. It isn't certified yet, but the process is underway. Rindler doesn't claim certifications it hasn't earned, and is happy to walk enterprise procurement through its current security posture and progress. Reach the team at founders@rindler.ai.
Is it allowed to use Rindler on websites I don't own?
Yes. Rindler acts on sites you already have access to, signing in with your own account when a site requires it, the same way you would in your own browser. It only reaches what you could reach yourself. You are responsible for using it in line with the terms of the sites you access, the same as when you use them directly.
How does Rindler handle two-factor authentication (2FA)?
On most sites you complete 2FA yourself once, in a Rindler-managed browser, and Rindler never sees the codes. It opens a single-use link (it expires in 15 minutes) to the real login page where you sign in and finish any verification the site asks for, including MFA. After you click "I'm logged in," Rindler keeps only the resulting session, scoped to that one site. On some sites the login mandates a fresh one-time code each time; there Rindler collects the code for the current task only and never saves it.
Do I have to sign in every time, or does Rindler stay logged in?
On most sites, no. You sign in once and Rindler reuses that session on later runs instead of asking you again. Some sites tie a login to a single live browser, and there you sign in per task. Rindler stores the session encrypted with AES-256-GCM under a per-user key and replays it on later runs. Sessions do not last indefinitely: when one stops working, the next call returns an expiry signal and you re-authenticate through the same one-time flow. You can also revoke any saved login yourself, which deletes the encrypted cookie record.
Is it legal for an AI agent to log into websites and act on my behalf?
Rindler acts only on sites you already have access to, signing in with your own account the same way you would in your own browser. It reaches only what you could reach yourself, and it does not create accounts or defeat access you do not have. You are responsible for using it in line with the terms of the sites you access, the same as when you use them directly. Third-party carts hand off to that site for checkout; Stripe separately processes Rindler subscription billing.
Can Rindler download files like bank statements or CSV exports?
Yes. When an action captures a file (a statement, a transaction export, a CSV), the result includes a download object with a direct URL, served with no login required. The link expires in about 30 minutes, so agents present it immediately as a download link. If capture fails, the result carries a download_capture_failed code instead of a false success, so the agent never tells you to check a downloads folder for a file that is not there.
For developers: MCP, tools & setup
What is an MCP server?
An MCP server is a service that exposes tools an AI agent can call over the Model Context Protocol, so the agent can take actions instead of only chatting. Rindler runs a hosted MCP server at mcp.rindler.ai that gives your agent four tools: start_session, dispatch_action, extract_content, and close_session. It is a server, not an SDK, so there is no API key and no client library.
How does a Rindler session work?
A Rindler session runs through four tools your agent calls: start_session opens the site, dispatch_action runs an action (search, filter, submit, or add-to-cart), extract_content re-reads the screen as structured records, and close_session ends it. Authentication, navigation, retries, and error recovery run server-side. If a site is unsupported, start_session returns an 'unsupported_site' signal so your agent can fall back to native browsing.
Do I need an API key to use Rindler?
No, Rindler needs no API key and no client library. The Rindler MCP server at mcp.rindler.ai is a hosted server, not an SDK: you install it with curl https://rindler.ai/install | sh, then authenticate over OAuth 2.0 PKCE in your browser and tokens refresh automatically. Point any MCP-capable agent at it and start calling tools.
Which AI agents and MCP clients work with Rindler?
Rindler works with any MCP-capable agent, including Claude Code, Cursor, Devin Desktop, Claude Desktop, Codex, ChatGPT, and any other MCP client. Rindler runs a hosted MCP server at mcp.rindler.ai that your agent connects to over OAuth with no API key, so it plugs into whatever MCP client you already use. No custom SDK per client is required.
Does Rindler have rate limits?
Yes, there is a per-domain burst limit on starting sessions. Open too many sessions on the same domain too quickly and start_session returns a "Too many start_session calls" error naming the limit and a retry-after window. This protects the site rather than hammering it, and normal task pacing stays well under the limit. Retries after a timeout or a transient failure are fine; a timeout is neither a rate-limit nor an unsupported site.
How do I add Rindler to an agent that loads MCP servers from a config file?
Add one HTTP MCP entry and restart the agent. For runtimes that read a local MCP config, the entry is {"mcpServers": {"rindler": {"type": "http", "url": "https://mcp.rindler.ai"}}}. In Claude Code that file is .mcp.json at the project root, and the one-command installer curl https://rindler.ai/install | sh writes it for you. Restart the session to load the tools, then authenticate over OAuth 2.0 PKCE in your browser. No API key.
Sites, mapping & reliability
What websites does Rindler support?
Rindler supports a public catalog of sites you can browse at chat.rindler.ai/configs, and you can map any new site yourself for free by pasting its URL into the mapper and picking a Fast or Deep crawl. A freshly mapped site becomes a private, typed API scoped to your account, with an automated verifier confirming reliability. Rindler works even on sites that were never built for agents, including sites with no API.
Can I map my own website with Rindler?
Yes. You can map any website with Rindler for free. Paste its URL into the mapper at chat.rindler.ai and Rindler learns the site's structure automatically, with a Fast or Deep crawl option. An automated verifier confirms reliability, and the freshly mapped site becomes a private, deterministic typed API scoped to your account that you can try right away in chat.
How reliable is Rindler?
Rindler is built for reliability. Every mapped site is confirmed by an automated verifier, and persistent sessions with server-side authentication, retries, and error recovery keep tasks running. In Rindler's own benchmarks against open-source agents, it delivered roughly 3x fewer failed tasks, 4x faster completions, and 6x cheaper execution. Self-healing configs also adapt when a site's design changes.
If a website changes its design, does Rindler still work?
Yes. When a website changes its layout or updates its design, Rindler's mappings adapt automatically, so your agent keeps working without anyone rewriting code. Rindler calls these self-healing configs, and an automated verifier continuously confirms each mapping still returns reliable, structured data. It's included on every Rindler plan, including the free $0 tier.
Does Rindler work on sites that block automated traffic?
Sites that block ordinary automated traffic are exactly where Rindler is used. Sign-in and access are handled for you as part of the session, so your agents never have to manage any of it. Many Rindler-connected sites answer a direct fetch with a 403 or a blocked page, and Rindler is the supported way to reach them. If a sign-in step needs anything extra, you clear it yourself in the managed browser during the one-time sign-in handoff.
Does Rindler work on JavaScript-heavy sites where a plain fetch returns an empty page?
Yes, that is a core case. Sites that return an empty JavaScript-only shell to a direct HTTP fetch still work, because Rindler drives a real server-side browser that reads the fully rendered page. It returns structured records regardless of client-side rendering, A/B-tested layouts, or popups. The same call against the same site returns the same shape of response across runs, independent of DOM changes.
Can Rindler read PDFs and documents from a site?
Yes, via a dedicated extract_document tool. Point it at a PDF's URL and it returns the text per page with 1-based page numbers plus page_count, the document's true length even when you request a subset. For long files, pass query to get only pages containing a substring, or pages for a range like "1-3,7". It fetches anonymously and sends no cookies, so it reads only what a signed-out visitor could; a PDF behind a login is not yet supported. A scanned image with no text layer returns pdf_no_text_layer.
What happens when an AI agent hits a site Rindler hasn't mapped yet?
start_session returns an unsupported_site screen and the agent falls back to its own browsing. The signal is explicit ("Rindler does not have a mapping for <domain>. Use your native browsing or web search tools instead. Do not retry start_session on this domain."), so the agent does not stall or loop. You can also map most sites yourself for free by pasting the URL into the mapper at chat.rindler.ai. A transient timeout is not an unsupported site and should simply be retried.
What happens when a Rindler action fails or times out?
Authentication, navigation, retries, and error recovery run server-side, so many transient failures are handled before your agent sees them, and a timeout is never treated as an unsupported site. The agent retries or re-reads the current screen. If a modal blocks the page, the error is blocked_by_dialog carrying the dialog's title and its dismiss_candidates; the agent clears it by calling the global dismiss_dialog action with button_text set to one of them, then retries the same action instead of losing progress.
Does a Rindler agent remember anything between sessions?
Yes, through a durable memory tool. An agent can remember a fact or reusable how-to, recall relevant memories before acting, and forget anything wrong or stale. Each memory is tagged semantic or procedural with a self-scored importance, and recall runs hybrid semantic and keyword search. Memory is scoped per user and never returns another user's data, so an agent carries site quirks and learned workflows across runs instead of relearning them each time.
Does Rindler handle a site's search filters, and what if they change?
Yes, and it reads them live rather than hardcoding them. On a faceted screen, extract_content returns the page's actual filter and facet controls as a filters array alongside the structured records. Because filters are contextual (a marketplace's Vehicles category adds Make, Model, and Year), Rindler re-reads them from the current page each time instead of assuming a fixed set, so your agent applies whatever the site currently offers.
Can Rindler take actions on a site, or does it only read data?
Both. dispatch_action executes the real actions a site exposes (searching, filtering, submitting forms, moving through multi-step flows, adding items to a cart), using the same session as reads. The boundary is deliberate: nothing books, pays, reorders, or changes a record without your explicit instruction, and third-party carts hand off so you check out on that site yourself. Stripe separately processes Rindler subscription billing. Rindler does not move money on your site accounts on its own.
Pricing, getting started & company
How much does Rindler cost?
Rindler has four plans: Free at $0, Starter at $100 a month, Teams at $1,000 a month, and Enterprise with custom pricing. The Free plan, for developers and individuals, is a demo of the product: chat with a curated set of the sites we support best, plus the complete Rindler MCP server and agent tools and the chat.rindler.ai app. Starter adds access to every supported site (not just the demo set), one site of your own mapped and maintained by us, and 100 credits every month. Teams raises that to up to 20 sites of your own mapped and maintained by us, 1,000 credits every month, and saved tasks you can put on a schedule. Enterprise, for teams running agents in production, adds priority support with an SLA and volume credit pricing.
Does Rindler have an enterprise plan?
Yes, Rindler offers an Enterprise plan with custom pricing for teams running agents in production. It adds higher usage limits, dedicated site mappings that are more thorough and tailored to exactly the sites and workflows your team needs, authenticated sessions at scale, and priority support with an SLA. Contact founders@rindler.ai or schedule a call from rindler.ai/pricing to discuss.
How do I use Rindler?
You use Rindler two ways: sign in to chat.rindler.ai and ask an AI agent to run tasks on real sites for you, or connect your own MCP-capable agent (Claude Code, Cursor, Devin Desktop, Codex, or any MCP client) to Rindler's hosted server at mcp.rindler.ai. chat.rindler.ai also works as a live demo, so you can try Rindler there before wiring it into anything. Developers install with one command, curl https://rindler.ai/install | sh, then authenticate over OAuth. No API key.
Who founded Rindler and is it a real company?
Rindler was founded in 2025 by Michael Serrano and Arthur De Los Santos, who met at MIT in 2022 and did research at MIT CSAIL. Rindler is backed by Y Combinator and builds the infrastructure that lets AI agents reliably use any website, turning sites into structured, typed APIs. You can reach the founders directly at founders@rindler.ai.
Does Rindler charge per request, per site, or a flat fee?
Neither per request nor per site. The Free plan is $0 with no per-call or per-site fee. Free is a demo of the product: chat with a curated set of the sites we support best, plus the complete Rindler MCP server and agent tools and the chat.rindler.ai app. Starter adds access to every supported site (not just the demo set), one site of your own mapped and maintained by us, and 100 credits every month. Teams raises that to up to 20 sites of your own mapped and maintained by us, 1,000 credits every month, and higher usage limits. Enterprise is custom-priced for teams running agents in production and adds priority support with an SLA and volume credit pricing.
Automate the sites your work depends on.
Talk to us and we'll scope your sites, volume, access, and terms, then tell you exactly what we would deploy.