Test personas for people and AI agents
Give your agentsa real inbox.
Test signups, read verification emails, and pick up where the last run left off. Each reusable persona keeps an identity, inbox, and activity history together. Connect through API or MCP.
3 personas free · no card · 7-day inbox history
Dana Whitfield
d.whitfield417
Saved activity
Monday · agent note
Signup completed. Welcome email received.
Wednesday · agent note
Password reset tested. Account accessible.
Next agent session
“Use Dana to test the new sign-in flow. Check her previous runs first.”
Read Dana’s identity and saved activity
Find this run’s sign-in email in her inbox
Save a note for the next run
Your agent changes. The test user stays.
A throwaway address handles one email. A persona gives your agent a test identity it can return to, with a record of what happened before.
Start with the same person
Create a persona in the app, then let your agent read its identity and reuse its email address across signup, onboarding, and returning-user tests.
Read the email your app sent
Find messages by sender, subject, and arrival time. Read verification links, sign-in codes, and password reset emails from the actual inbox.
Leave the next run a record
Save outcomes and observations to the persona's activity. The next session can read those notes before it decides what to test again.
Use the local MCP bridge with your AI tool, or call the REST API from a script or test runner. Your agent handles the browser and assertions; Persona Kit supplies the inbox and saved context.
Scoped, revocable API keys. No browser or proxy setup needed for inbox access. Your plan’s email limits and retention apply.
Seven things every persona keeps to itself
Most tools isolate the browser and stop there. The leak is rarely the browser — it is the inbox you reused, or the password you stored somewhere shared.
Everything a persona needs to stand on its own
An inbox is the beginning. Keep the identity, credentials, and browser state with the persona they belong to.
Complete identities
Pick a country, a region, and optionally a city. The address, postal code, phone, timezone, and language are generated together so they agree with each other.
A real inbox per persona
Each persona can hold its own address that genuinely receives mail, so verification codes never land in your own inbox. Forward it on if you want to watch it.
Credential vault
The logins a persona creates live with the persona. Passwords and TOTP seeds are encrypted with AES-256-GCM, and codes are generated on demand.
Isolated browser sessions
Launch a persona into a live session and drive it from the dashboard. Its cookies and storage are saved on release and restored on the next launch.
Scheduled automations
Give a search-and-visit task to a set of personas on a cron schedule. Runs are staggered and offset at random, with a screenshot kept for every participant.
API and agent tools
Read personas and real email, then save activity notes through REST or the local MCP bridge. Use scoped keys you can issue and revoke yourself.

Runs on your own Steel Browser deployment and your own proxy account
Your browser. Your exit IPs.
Persona Kit does not resell a proxy network or run a shared browser pool. You connect a Steel Browser deployment and a residential proxy account you already pay for, and personas run through them.
- Browser
- Steel Cloud with an API key, or self-hosted Steel Browser
- Proxy
- Bright Data, IPRoyal, Smartproxy, or any custom gateway
- Stored as
- AES-256-GCM encrypted before it reaches the database
- Result
- Traffic on infrastructure you control, with no markup from us
What we don't do
Not aspirations. These are things we have decided against, and they do not change quietly.
- We do not sell your personal information
- We do not use your persona content to train machine learning models
- We do not inject ads or trackers into your sessions
- We do not share persona data between organizations
- We do not read your persona email except when you ask us to help with a fault
One limit worth stating plainly: a persona’s fingerprint and proxy make it distinct, but we make no claim to defeat WebRTC, DNS, or IPv6 disclosure in every configuration, nor to beat any specific fingerprinting technique. Treat persona isolation as strong compartmentalisation, not anonymity. The Privacy Policy lists every field we store, every sub-processor that receives it, and how long each category is kept.