🛡️ 100% Local Manifest V3 • Zero Cloud Backend

Automate Web Workflows & Export Code Right from Your Browser

A zero-backend, privacy-first Selenium & Playwright recorder built into Google Chrome. Record multi-page workflows, mask passwords with AES-256, and export clean code for free.

FlowMacro IDE • Standalone Controller (960 × 750px)
TAB #1024 ATTACHED
BASE_URL:
REC
#
Command
Target Selector
Value
open
https://app.supabase.com/login
-
2
type
data-testid="email-input"
lead.engineer@acme.dev
3
type
id=password
{{SECRET_PASSWORD}}
4
click
aria/Sign in button
5
click
shadow=auth-box >>> #mfa-btn
6
waitFor
#prod-analytics-cluster
visible
5-Tier Waterfall: data-testid → id → ARIA → CSS → XPath6 / 6 Commands Ready
LIVE EXECUTION LOGS[STREAMING]
[14:02:11.104] [INFO] Target tab #1024 connected via Chrome Runtime & Scripting APIs
[14:02:11.240] [OK] Navigated to https://app.supabase.com/login (200 OK, 124ms)
[14:02:11.750] [DOM] Resolved selector 'data-testid=email-input' in 2.1ms (Waterfall Tier 1)
[14:02:12.180] [SHIELD] 🛡️ Sensitive input detected: value masked with {{SECRET_PASSWORD}}. WebCrypto AES-256-GCM armed.
[14:02:12.620] [PIERCE] Pierced open Shadow DOM host '<auth-box>' -> '#mfa-btn'
[14:02:13.110] [SUCCESS] Replay executed on tab #1024 across frames with 0 DOM errors.
>
[SUCCESS] Replay executed on tab #10240 Leaks
System Specification

Six Core Architectural Pillars

Built for automation engineers, QA specialists, and developers who require deterministic browser replay, zero-trust credential security, and zero cloud dependencies.

100% Local Execution

Operates entirely within Chrome using Manifest V3 and chrome.storage.local/session. Zero cloud execution sandboxes, no external backend servers, and zero telemetry. Your automation data never leaves your device.

01 / ZERO CLOUD DEPENDENCIES

5-Tier Selector Waterfall

Records redundant fallback locators: data-testid → id → aria-label → optimal CSS path → XPath. If an element's styling or markup changes, playback falls back down the chain seamlessly.

02 / DETERMINISTIC LOCATORS

Multi-Page & SPA Routing

Auto-reattaches across full-page redirects, OAuth logins, and SPA transitions (pushState/replaceState/popstate). Flushes debounced inputs instantly upon route changes to guarantee zero dropped keystrokes.

03 / REDIRECT & ROUTE RESILIENT

AES-256 Secret Vault

Auto-detects input[type="password"] and sensitive credentials. In-RAM encryption via native Web Crypto API (AES-256-GCM) with 96-bit random IVs, exporting clean process.env variables with zero leakage.

04 / ZERO-LEAK LOCAL ENCRYPTION

Shadow DOM & Iframe Support

Recursively traverses open shadow roots using shadow-piercing locators (>>>) and routes automation commands to specific frame IDs. Automates embedded payment forms, Stripe elements, and Web Components with ease.

05 / SHADOW ROOTS & FRAMES

Standalone IDE & Exporters

Dedicated controller window (960 × 750px) with Record, Pause, Stop, Step Editing, and Undo/Redo history. 1-click export to clean Playwright (TS), Puppeteer (JS), Python Selenium, or native Selenium .side JSON.

06 / PLAYWRIGHT • PUPPETEER • SELENIUM
Code Generation Sandbox

Clean, Zero-Leak Code Exporters

Observe how sensitive password inputs automatically render as process.env.AUTO_MACRO_PASSWORD across all target frameworks.

Target Framework:
// Generated by FlowMacro IDE • Playwright (TypeScript)
import { test, expect } from '@playwright/test';

test('Automated Supabase Login Workflow', async ({ page }) => {
  // 🛡️ Zero-Trust Vault: Credentials loaded strictly via environment
  // Plain-text password is NEVER committed to repository or CI logs
  const AUTO_MACRO_PASSWORD = process.env.AUTO_MACRO_PASSWORD || '';

  await page.goto('https://app.supabase.com/login');
  await page.locator('css=[data-testid="email-input"]').fill('lead.engineer@acme.dev');

  // Injected securely into DOM without plain-text leakage
  await page.locator('input[type="password"]').fill(AUTO_MACRO_PASSWORD);
  await page.locator('button#login-submit').click();

  await expect(page.locator('#prod-analytics-cluster')).toBeVisible();
});
Tested & Verified: 0 plain-text password leaks in generated code exports.PASSED (100% SECURE)
🟢 100% FREE DURING BETA — $29 ONE-TIME DEAL COMING SOON

Full Automation Suite. Free in Beta.

No paywall, no recurring subscriptions, no credit card required. Experience complete local automation with 0 plain-text leaks.

Community Edition100% Free Forever
$0

For individual developers recording and replaying local macros in browser tabs.

  • Unlimited macro recordings
  • Single-tab browser replay
  • Standard Playwright & Selenium export
  • Local AES-256 password auto-masking
Add to Chrome — Free
Pro Lifetime TierBETA ACCESS
$29$79One-time deal coming soon
🟢 100% FREE DURING BETA — $29 ONE-TIME DEAL COMING SOON

For engineering teams running automated batch fills, shadow DOM traversal, and exporting to CI/CD test pipelines.

  • Everything in Community
  • AES-256 Local Secret Vault (zero-leak RAM)
  • 5-Tier Selector Waterfall & Shadow DOM traversal
  • Cross-Origin Iframe Routing & frameId dispatch
  • SPA Route Interception with instant input flush
  • Multi-Format Exporters (Playwright, Puppeteer, Python, .side)
  • MV3 Keep-Alive Alarms for long automation replays
Install Free Chrome Extension

✨ Checkout disabled during Beta • Instant free install from Chrome Web Store

DOCUMENTATION & TROUBLESHOOTING

Quick Start & Common Help Topics

Pragmatic guides for everyday browser automation, multi-step logins, credential protection, and exporting tests.

01

Start Recording

Click the FlowMacro icon in your Chrome toolbar, type your target Base URL, and hit Record. A standalone IDE window opens and synchronizes with your active browser tab.

Tip: Works smoothly across modern SPAs (React, Next.js, Vue, Clerk).
02

Interact Naturally

Click buttons, type searches, and navigate pages. FlowMacro generates resilient 5-tier locators (data-testid → ID → ARIA → CSS → XPath) and penetrates open Shadow DOMs in real time.

Passwords are auto-encrypted with local AES-256 in memory.
03

Replay & Export

Hit Stop when done. Replay directly in your browser with adjustable speed (0.5x, 1x, 2x), or export to Playwright (TS), Puppeteer (JS), Python Selenium, or .side JSON.

Zero telemetry • Zero remote servers • 100% Client-Side.

Common Issues & Quick Fixes

AUTH

Multi-step login flows (Clerk, Supabase, NextAuth)

On sites with multi-screen authentication (e.g. enter username → click Continue → enter password screen), duplicate submit clicks or transient elements can be recorded during the transition.

Quick Fix: In the FlowMacro IDE table, simply delete any extra ghost submit steps between entering your username and typing your password. FlowMacro will cleanly execute Step 1 (Username) → Click Continue → Step 2 (Password) → Click Sign In.
SECURITY

Are my passwords or API keys safe?

You never need to worry about credentials leaking into plain-text JSON files or git commits.

How It Works: Sensitive fields are encrypted with AES-256-GCM in memory and masked with {{SECRET_PASSWORD}}. When exported to Playwright or Python, FlowMacro generates clean process.env.AUTO_MACRO_PASSWORD references so credentials stay secure.
TIMING

Replay says "Target not found within 5000ms"

Occurs if a slow network request or complex animation delays the element from rendering in the DOM.

Quick Fix: FlowMacro automatically attempts 5 fallback selectors (data-testid → ID → ARIA → CSS → XPath). If a site takes several seconds to load, insert a brief wait step (e.g. 1500ms) or click the step in the IDE to pick an alternate locator.
EDITING

Made a mistake while recording?

You don't have to throw away your recording and start over if you accidentally clicked something.

Quick Fix: In the IDE table, use the ↑ and ↓ arrows to reorder steps, click the Trash icon to remove unwanted steps, or click any row to edit its selector, command, or value directly in the Command Inspector.

Need Help, Found a Bug, or Have Questions?

Have an automation challenge, feedback, or need help with a specific website? Reach out directly to our team!