Retrieved article excerpt
Open article · Retrieved 2026-10-02T16:26:25.461723+00:00
Back
# Lightpanda 1.0: Out of Beta and Ready for Production
Francis Bouvier
### Francis Bouvier
#### Cofounder & CEO
[IconX](https://x.com/bouvierfrancis)[IconLinkedin](https://www.linkedin.com/in/francisbouvier/)
[announcement](https://lightpanda.io/blog/tags/announcement) [security](https://lightpanda.io/blog/tags/security) [wpt](https://lightpanda.io/blog/tags/wpt)
Friday, October 2, 2026
Lightpanda 1.0: Out of Beta and Ready for Production
## TL;DR
After two years of hard work and 10,000 commits, Lightpanda is no longer in beta. It passes more than 1.7 million Web Platform Tests (WPT) subtests and now enforces CORS (Cross-Origin Resource Sharing) by default. It’s used in production by AI agents, search APIs, indexing and data extraction companies to retrieve billions of web pages every day.
The full changelog is in the [1.0.0 release notes](https://github.com/lightpanda-io/browser/releases/tag/1.0.0).
## Why we built Lightpanda
Lightpanda started with a problem we lived with for years. At our previous company, we gathered data from over 20 million pages a day on a fleet of headless Chrome instances, and keeping it running was expensive and painful. So [we built the browser we wished we’d had](https://lightpanda.io/blog/posts/why-build-a-new-browser).
Today you can drive it the way your stack already works: through Puppeteer, Playwright, Selenium, or ChromeDP. You can also install it straight into your project with `pip install lightpanda` or `npm install @lightpanda/browser`. For agents, we ship a native MCP server. You can also call it from the CLI to dump HTML, markdown or a semantic tree, or hand it a plain-English task in agent mode.
## Why Lightpanda is ready for production
Our browser engine is built from scratch from first principles: written in Zig, no graphical rendering, running the modern web’s JavaScript at a fraction of Chrome’s memory and CPU.
When we published the beta in November 2024, many sites wouldn’t load due to incomplete web API coverage. This is a continuous process (even for Chrome). But today, we are confident that you can depend on Lightpanda in production.
Two things had to be true before we dropped the beta label. Lightpanda had to run enough of the web platform that real sites work. It also had to enforce the security rules other browsers enforce, because it runs code you didn’t write.
## 1.7 million passing WPT subtests
Lightpanda passes 1,739,845 subtests of the [Web Platform Tests](https://web-platform-tests.org/), the shared conformance suite browser vendors use to check that they implement web standards the same way. In November 2024, it passed 2,645. Every run is public on our [WPT dashboard](https://perf.lightpanda.io/wpt).
Lightpanda passing WPT subtests over time
### Where the growth came from
1. **November 2024 to March 2026:** API work on the [DOM](https://lightpanda.io/blog/posts/migrating-our-dom-to-zig), HTML, Fetch, URL, cookies and events took Lightpanda from 2,645 to roughly 290,000 passing subtests.
2. **April 2026:** the encoding/ suite started passing. It holds about 1.15 million subtests, mostly large generated tables of character mappings, so the count jumped in a few days.
3. **April to September 2026:** about 340,000 more from workers, Shadow DOM, IndexedDB, XPath, WebSockets and forms.
### How Lightpanda compares with Chrome and Firefox
For context, Chrome passes 2,184,491 subtests and Firefox passes 2,137,997, according to their [September 2026 runs on wpt.fyi](https://wpt.fyi/results/). Lightpanda sits at about 80% of Chrome’s count.
Most of that gap comes from the choice we made on day one not to do graphical rendering. More than half of the subtests Chrome passes and Lightpanda doesn’t are in the CSS, editing and SVG suites, which test layout and painting.
## CORS is one part of a wider security push
### What CORS does
Starting with [Lightpanda 1.0](https://github.com/lightpanda-io/browser/releases/tag/1.0.0), the browser enforces CORS on every `fetch()` and `XMLHttpRequest` a page makes. If a server hasn’t said a cross-origin page may read its response, the page can’t read it.
Every browser applies the **same-origin policy**: a script loaded from one origin (scheme, host and port) can’t read responses from another. [CORS](https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/CORS) is how a server relaxes that rule. It opts in with response headers such as `Access-Control-Allow-Origin`.
For requests that could change state, like a `PUT` or a request carrying custom headers, the browser first sends an `OPTIONS` request called a **preflight**. It only sends the real request if the server’s answer allows it. The rules are defined in the [Fetch standard](https://fetch.spec.whatwg.org/#http-cors-protocol).
For a headless browser running inside your cloud network, often driven by an AI agent visiting pages nobody vetted, skipping these checks is an important security concern. A malicious page could call an internal service or an API the session is logged into, and read what comes back.
A dedicated headless browser already limits security risks, because it doesn’t carry the logged-in sessions of your everyday browser. We wrote more about [browser security in the age of AI agents](https://lightpanda.io/blog/posts/browser-security-in-the-age-of-ai-agents) and why we think every agent deserves its own browser.
Lightpanda passes 371 of the 463 subtests in the cors/ suite, or 80%. We’re working through the remaining 92, and you can follow progress on the [dashboard](https://perf.lightpanda.io/wpt).
### Other security fixes
In the past six months, we also shipped:
- **Opt-in resource loading (0.4.0):** iframes, workers and external stylesheets only load when you ask for them with `--load-resources`. Less of a page’s code runs unless your job needs it.
- **Authorization stripped on cross-origin redirects (0.4.0):** credentials you set for one host don’t follow a redirect to another.
- **Stricter cookies (0.2.9 to 0.4.1):** page JavaScript can’t modify HttpOnly cookies, SameSite=Strict holds on cross-site navigation, the SameSite=Lax exception only covers safe methods, and Set-Cookie domains that are public suffixes get rejected.
- **Network filtering (0.2.9 onward):** `--block-cidrs` and `--block-private-networks` keep the browser away from address ranges you choose, such as private subnets or cloud metadata endpoints.
- **Parser and protocol hardening:** fixes for CR/LF injection through the URL authority (0.3.1) and integer overflow in WebSocket message-length parsing (0.4.1), plus dozens of use-after-free and double-free fixes across releases.
We publish a [security policy](https://github.com/lightpanda-io/browser/blob/main/SECURITY.md) for reporting vulnerabilities.
### Running the latest V8
Lightpanda 1.0 ships with V8 15.5.35.13, the latest stable release of the JavaScript engine behind Chrome and Node.js ([browser#3676](https://github.com/lightpanda-io/browser/pull/3676), [zig-v8-fork#215](https://github.com/lightpanda-io/zig-v8-fork/pull/215)). The upgrade means the security fixes that land in V8 also apply to Lightpanda.
V8 runs every line of JavaScript a page sends you, so keeping it current matters as much as CORS.
## Lightpanda in production
Companies use Lightpanda in production for AI agents, indexing, search and data extraction, some at more than 30 million pages a day each.
[Keenable](https://keenable.ai/blog/keenable-raised-26m-to-beat-google-in-the-agentic-search-market), which builds web search for AI agents, runs Lightpanda for search and indexing. [Ilya Bogin](https://www.linkedin.com/in/ilya-bogin/), Member of Technical Staff at Keenable, explains why:
> When agents retrieve information from the web, they can often read it directly from HTML. But most of the valuable sites render content dynamically. More than 35% of our answers depend on them.
>
> Rendering these pages is up to 400x more expensive than reading static HTML.
>
> Lightpanda makes this scalable: 4x faster and 6x more cost-efficient than Chromium.
[DeveloperHub.io](https://developerhub.io) moved its prerender service from headless Chrome to Lightpanda. Pages now serve 4x faster and load average dropped 10x. The scheduled restarts and CPU alarms went away with Chrome. Zaid Daba’een, their CEO, put it this way:
> I’ve now completely switched to using Lightpanda, rewriting prerender entirely. This change serves pages 4x faster (a conservative estimate, it’s often closer to 6x) and lowering load average by 10x. Instances no longer require a restart, and I’m not receiving CPU alarms anymore.
The full story is in [How DeveloperHub.io cut prerender load by 10x](https://lightpanda.io/blog/posts/how-developerhub-io-cut-prerender-load-by-10x).
## Built into agent frameworks
### Hermes Agent
[Hermes Agent](https://hermes-agent.nousresearch.com/docs/user-guide/features/browser#lightpanda-local-engine), from Nous Research, lists Lightpanda as a local browser engine alongside cloud providers. Its docs explain why:
> It starts instantly, runs 9x faster and uses 16x less memory than Chrome, which matters for agents that live on small VMs for long stretches.
Switching Hermes to Lightpanda takes three lines in `~/.hermes/config.yaml`:
```
browser:
cloud_provider: local
engine: lightpanda
```
Hermes then starts `lightpanda serve` itself, one process per session, so you don’t need Chromium or Node.js installed. For actions Lightpanda doesn’t support yet, such as screenshots, Hermes falls back to Chrome automatically.
### agent-browser
[agent-browser](https://github.com/vercel-labs/agent-browser), the browser automation CLI for AI agents from Vercel, [runs on Lightpanda](https://agent-browser.dev/engines/lightpanda) with one flag: `--engine lightpanda`. Pair it with its `batch` command and a separate `--session` per site, and you get several Lightpanda sessions working in parallel:
```
agent-browser --session rust-wiki --engine lightpanda batch "open https://en.wikipedia.org/wiki/Rust_(programming_language)" "get text body" &
agent-browser --session rust-home --engine lightpanda batch "open https://www.rust-lang.org" "get text body" &
wait
```
[Chris Tate](https://x.com/ctatedev/status/2041928222766399805) from Vercel on the integration:
> agent-browser + Lightpanda + batch + multi-session is a dangerous combo. Completed this benchmark task in 5.85s
## Try Lightpanda 1.0
Install it with the command below, or pick another method in the [installation guide](https://lightpanda.io/docs/run-locally/installation/one-liner):
```
curl -fsSL https://pkg.lightpanda.io/install.sh | bash -s "1.0.0"
```
Pick a page your pipeline navigates today and fetch it:
```
lightpanda fetch --dump markdown https://your-site.example
```
If a page breaks, [open an issue with the URL](https://github.com/lightpanda-io/browser/issues). DeveloperHub.io filed two before switching, and both were fixed before they moved production over.
Already running Lightpanda? We recommend you keep CORS enabled. If you have trouble with CORS, you can open an issue and use `--disable-features cors` in the meantime.
## What’s next?
Going out of beta does not mean our work is done. We’re working hard every day to increase Web API coverage and pass more WPT subtests.
Our DNA hasn’t changed: speed and memory will always be the priority. And now it matters more than ever. We want Lightpanda to be the default web browser in the era of AI agents and robots.
## FAQ
### What does it mean that Lightpanda is out of beta?
[Lightpanda 1.0](https://github.com/lightpanda-io/browser/releases/tag/1.0.0) is the first release we consider stable enough to build production systems on. It passes 1,739,845 Web Platform Tests subtests and enforces CORS by default.
### What is CORS and why does a headless browser need it?
CORS (Cross-Origin Resource Sharing) is the mechanism servers use to tell browsers which other origins may read their responses.