Never use API keys for main agents (Claude, Codex). Always use built-in, pre-configured subscription auth.
Firefox is excluded from scope for now — not worth pursuing given Cloudflare blocks it on login.
Do NOT modify the Oracle Chrome profile (~/.oracle/chrome) — no deleting lock files, no removing caches, no "cleaning up" anything. Hands off.
When doing production verification against real ChatGPT:
- Use
--allow-visibleso the human can observe browser behavior and give fast feedback - Do NOT spam the ChatGPT website — minimize queries to avoid trouble with OpenAI/Cloudflare