Use Chrome’s URLBlocklist and URLAllowlist policies to control where automated browsers may go. For a deny-by-default design, set URLBlocklist to *, then add only approved origins or paths to URLAllowlist. Chrome treats the allowlist as the exception list and gives it precedence over the blocklist. Apply the policy at the correct device, browser, user, or profile scope, verify it at chrome://policy, and run Playwright with a dedicated profile rather than your everyday Chrome profile.
Choose the policy scope before writing rules
Chrome can receive policy from several control planes. The scope determines which automation runs are affected.
| Scope | Use it when | Typical deployment |
|---|---|---|
| Device or platform | Every user and browser on a machine must follow the same restriction. | Operating-system management, Windows Group Policy, macOS managed preferences, Linux enterprise tooling, or an MDM system. |
| Enrolled browser or machine-cloud | A managed browser installation, regardless of the signed-in user, needs a central rule. | Chrome Enterprise enrollment and its administrative control plane. |
| OS user | The restriction should follow a managed operating-system account. | System policy management. |
| Cloud user or Chrome profile | The rule should follow a managed Chrome account or profile across devices. | Chrome Enterprise Admin console for managed users. |
For unattended runners, device or enrolled-browser scope is usually easier to reason about because a new job cannot silently switch to an unrestricted account. A profile-level rule is useful when one machine serves multiple teams, but you must ensure the runner starts the intended managed profile every time.
Build a default-deny policy
Block everything first
Set URLBlocklist to a single entry, *. This establishes the default-deny posture: a navigation is blocked unless a more specific policy entry allows it.
#1 Best Overall
- Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
- Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
- Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
- Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
- 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.
Add narrow exceptions
Put approved destinations in URLAllowlist. Chrome’s documented URL-filter syntax can express schemes, subdomains, ports, and paths. Do not assume that allowing a bare domain automatically covers every scheme, subdomain, port, or URL path.
For example, an automation job that needs only a production API and its login host should permit those exact origins rather than an entire top-level domain. Keep the combined policy within Chrome’s documented limit of 1,000 URL entries.
Understand matching and precedence
Chrome evaluates matching filters by specificity. A rule containing a scheme, host, port, or path can be more specific than a broad host rule. Avoid contradictory entries unless you have tested the exact result. For the URLAllowlist and URLBlocklist pair, Chrome documents that “The URLAllowlist policy takes precedence over URLBlocklist.” Treat that as an exception mechanism, not as a reason to make the allowlist broad.
URLAllowlist support in headless mode is documented from Chrome 92. Because policy behavior and supported syntax are release-sensitive, check the current Chrome policy reference when upgrading the browser image.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsDeploy the rules through your management system
Managed users or enrolled browsers
In the Chrome Enterprise Admin console, select the organizational unit or group that owns the automation account or enrolled browser. Add the URLBlocklist and URLAllowlist values under the URL/content settings, save, and allow policy propagation before testing.
Rank #2
- 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
- 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
- Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
- 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
- What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.
Windows
Use the Chrome enterprise administrative templates in Group Policy. Assign URLBlocklist and URLAllowlist at the computer level for machine-wide enforcement or at the user level when the policy should follow a Windows account. Confirm that the runner’s service account receives the same policy as an interactive test account.
macOS and Linux
Use managed preferences or your organization’s supported device-management tooling on macOS. On Linux, deploy the Chrome enterprise policy files through the distribution’s enterprise-management mechanism. The exact file location and packaging method vary by distribution; the important operational check is the policy page inside the same Chrome build used by automation.
Verify that Chrome received the intended values
- Start the exact Chrome channel and profile used by the runner.
- Open
chrome://policy. - Click Reload policies. Restart Chrome first if your management system requires a process restart.
- Confirm that
URLBlocklistandURLAllowlistdisplay Status: OK and the expected entries. - Navigate to at least one approved URL, one URL that should be blocked, and one near miss such as the wrong scheme, subdomain, port, or path.
Test in the same profile, executable channel, operating-system account, and container or VM image that the automation job uses. A successful check in a personal Chrome profile does not prove that a service account is constrained.
Free tools Windows power users keep installed
One-click scans. No signup required.
Use Playwright without fighting enterprise policy
Playwright can launch branded Chrome and Edge channels, but enterprise policy can change whether the browser launches or accepts automation control. Recent Chrome policy changes also make automating the default Chrome profile unsupported in Playwright’s BrowserType guidance.
Create a dedicated automation profile
- Create a directory owned by the automation service, such as
/var/lib/automation/chrome-profileor a per-job temporary directory. - Launch the branded channel with that directory as its user-data directory.
- Apply and validate the domain policies against that profile.
- Run smoke tests before production jobs and destroy temporary profiles after the job if they contain credentials or session data.
A minimal Playwright launch in JavaScript looks like this:
Rank #3
- Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
- Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
- Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
- Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
- What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.
import { chromium } from 'playwright';
const browser = await chromium.launch({
channel: 'chrome',
headless: true
});
const context = await browser.newContext({
// Keep state isolated from a user's normal Chrome profile.
});
const page = await context.newPage();
await page.goto('https://approved.example', { waitUntil: 'domcontentloaded' });
console.log(await page.title());
await browser.close();
Use your deployment’s supported persistent-context method when you need a specific user-data directory. Never point a production runner at an employee’s default profile; it can contain extensions, cookies, certificates, or settings that both weaken isolation and make policy failures difficult to reproduce.
Test policy behavior as an automation contract
- Allowed origin: navigation completes and the expected page marker is present.
- Blocked origin: navigation fails with the browser’s policy-blocked result rather than silently reaching the site.
- Scheme variation: test HTTP and HTTPS separately if only one is approved.
- Subdomain variation: test the exact host and an unapproved sibling host.
- Port variation: test the approved port and a different port.
- Path variation: test an approved path and a sensitive path that should remain unavailable.
- Redirect: follow an allowed URL that redirects to an unapproved host and confirm the destination is blocked.
- Headless mode: repeat the suite in the same headless configuration used in production.
Log the browser version, policy status, profile path, and target URL for each failure. This makes a policy regression distinguishable from DNS, TLS, authentication, or application errors.
Common failures and fixes
The policy page shows no values
The browser may not be enrolled, the account may be outside the assigned organizational unit, or the management service has not propagated the change. Confirm scope and identity, click Reload policies, then restart Chrome and check again.
Status is not OK
An invalid value, unsupported pattern, or conflicting management source is likely. Remove the newest entry, reload policies, and reintroduce rules one at a time using Chrome’s documented filter syntax.
An approved URL is blocked
Check scheme, host, port, path, and redirects. A host-only exception may not match the actual destination. Also verify that the automation process uses the profile in which you inspected chrome://policy.
Rank #4
- Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
- Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
- Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
- Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
- Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft
An unapproved URL loads
Look for a broader allowlist entry, a different Chrome executable, or a profile that did not receive the blocklist. Recheck the effective values and test from a clean dedicated profile.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Playwright cannot launch or control Chrome
Enterprise policy or recent Chrome changes may be affecting the default profile or the selected channel. Use a dedicated user-data directory, launch the branded channel explicitly, and validate policy state before creating the Playwright context.
Headless and headed results differ
Confirm the browser version and policy support. URLAllowlist headless support is documented from Chrome 92, but release changes can alter behavior. Run the same smoke test in both modes during browser upgrades.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Performance, reliability, and security considerations
- Keep the allowlist small. Fewer patterns reduce review effort and make unexpected access easier to detect.
- Prefer path- and host-specific exceptions over wildcard domains when a job needs only one service.
- Version policy files or Admin console changes alongside the automation code, and require review for new destinations.
- Cache policy validation results only as a diagnostic; always enforce the policy in the browser because network-level checks do not replace browser navigation controls.
- Use short-lived profiles for jobs handling credentials, and avoid copying a profile between unrelated runners.
- After Chrome or Playwright upgrades, rerun tests for redirects, ports, paths, and headless operation.
Or skip the browser setup
If your goal is simply to obtain a clean image or PDF of a permitted page, ScreenshotNeo provides a single-request alternative. Its service accepts consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each cleanup step can be disabled. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and the response identifies the page verdict and billing result in headers.
For a direct capture, see the ScreenshotNeo API documentation:
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python:
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
ScreenshotNeo also offers an MCP server with take_screenshot, get_page_info, and capture_pdf tools so Claude, Cursor, or another MCP client can capture pages. Every feature is included on every plan. The Free plan includes 1,000 screenshots per month without a card; paid plans start at $5 for 3,000 screenshots. Create a free ScreenshotNeo account.
Best Value
- 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
- Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
- Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
- HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
- What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
FAQ
Can I use only URLAllowlist without URLBlocklist?
That creates an exception list, not a default-deny policy. To deny every destination except approved entries, pair URLBlocklist * with narrowly scoped URLAllowlist values.
Does a policy applied to one Chrome profile affect every profile?
No. User and cloud-profile policies follow their managed scope. Device or enrolled-browser policies are the appropriate choice when every user on a machine must be restricted.
How many URL policy entries can Chrome store?
The Chrome Enterprise policy reference documents a limit of 1,000 URL entries.
Should automation reuse a developer’s Chrome profile?
No. Use a dedicated profile directory so enterprise policy, cookies, extensions, and credentials are isolated and reproducible.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

