Zendoric
← Back to the day · September 4, 2026

A Show HN pitches AI agents that run entirely in the browser, with no server or containers

🕒 Published on Zendoric: September 4, 2026 · 09:12

✨ AI-generated · how it's made

An independent developer has launched buttercup.sh, a free weekly course for building AI agents in pure JavaScript that run inside the browser, with no backend. The promise of near-zero-cost infrastructure runs into a familiar problem: the API keys live on the client.

By Zendoric · September 4, 2026.

An anonymous developer has posted "Show HN: Building AI agents client-side JavaScript" on Hacker News, introducing buttercup.sh: a free, weekly course that teaches how to build artificial intelligence agents that run entirely inside the browser, in vanilla JavaScript, with no intermediary server. As the author himself describes it, the project starts in mid-September 2026 and will cover, week by week, the function calling loop (the mechanism by which a model requests the execution of an external tool and receives the result) in the browser runtime, screen capture of the viewport itself to give the agent vision, connection with remote agents, and coordination of several subagents without blocking the interface thread. All the code is open and requires no installation: it runs by pasting an API key into the page itself.

The architecture is the central argument. The vast majority of current agent systems —from chaining frameworks to homegrown implementations running in production— place the agent loop on a Python server inside containers, with an intermediate layer that handles calls to the model and to the tools. Buttercup.sh inverts that logic: the loop lives in the user's tab. Traffic to the model goes straight from the browser to the chosen provider —Anthropic, OpenAI, xAI, Google, OpenRouter or any OpenAI-compatible endpoint— with no proxy of its own in between. For anyone who wants to do without external providers, the system supports Ollama or vLLM locally, and WebLLM to run embedded models directly in the browser itself.

The appeal is obvious: no server to maintain, no infrastructure bill for every intermediate call, and the possibility of operating completely offline if the model runs on the user's machine. It is the same logic that has driven projects such as transformers.js or MLC in recent years: moving compute and inference from the data center to the user's device drastically lowers the marginal cost of experimenting with AI and reduces dependence on whoever operates the server. For an individual developer or a small team, removing that orchestration layer removes much of the friction of getting started.

But the design itself acknowledges, in the fine print, the price of that convenience: the API key is stored in the browser's local storage (localStorage), and that storage is readable by any script that manages to run on that same origin. The site itself warns of it: it is advisable to use a key with limited permissions that can be revoked painlessly. It is no minor detail. An agent that can also photograph and operate a preview in an iframe —click, type, scroll— and send screenshots back to the model widens the surface of what can go wrong if that browser is compromised: it is no longer just a leaked key, but an agent with the ability to act on what it sees.

It is a pattern we have seen repeated in this year's agentic ecosystem: every layer of autonomy granted to an agent —browsing, executing tools, coordinating subagents— is only as secure as the weakest point in the chain of permissions that sustains it. When that weak point is the storage of a browser shared with any script that manages to slip in, control stops being a conscious design decision and comes to depend on each user's hygiene. It is not a flaw exclusive to this project —it is the trade-off inherent in moving orchestration outside a controlled backend— but it is worth naming with the same clarity with which the infrastructure savings are announced.

It is also worth putting the story's real scope in perspective: this is an individual, open-source project, presented on Hacker News to a modest reception —one point and one comment at the time of writing. It is not a platform with traction or an announcement from an established company; it is the proposal of a developer who wants to document, in public and week by week, how far an agent can be taken without a backend. Its value lies not in its immediate impact, but in the fact that it illustrates —with real code, runnable in any tab— an underlying trend: building agents is getting cheaper and more decentralized at the same pace as the models that power them. That is, ultimately, the same democratizing force that drives free software and open models: the fewer pieces of closed infrastructure needed to build something useful with AI, the more people can try. The challenge, here as in the rest of the agentic ecosystem, will be making sure that openness is not paid for up front in security.

🔗 Related on Zendoric

Sources & references