Scraping via the Preview Panel: The Session Is the Credential
The preview panel session is the scraping credential: rotating URL tokens, cosmetic click failures, CDP left dead.
TL;DR
When scraping Jakarta's court portal, external fetches only hit captcha walls because the browser session inside the panel carries the real credentials. Rotating tokens force click-driven navigation, and automation success flags lie, so verify via URL and DOM instead of auto-retrying. This approach harvested 4,828 bankruptcy cases across 242 pages, keeping sessions in-panel with checkpoints instead of URL replays.
Panel Session Is the Credential, Not a Helper Tool
I was waiting for the automated click result in the desktop AI workbench preview panel, and all that appeared was a single line of error: The pointer input never reached the page. The crucial detail: the click still executed, and the page still navigated. At that moment, I was pulling case data from the Central Jakarta court portal for the DemandScope project. I had already solved the captcha manually inside the panel, but the moment I fetched the same URL from the outside, all I got back was a 769-byte captcha interstitial.
My first guess: the anti-bot gateway was just about external identity. Clean IP, normal User-Agent, human-like click speed, done. My previous article on ExampleBlog started exactly there: stealth proxies dying at captchas that measure the browser. But this addendum hits deeper. After reading the installed runtime source code, specifically preview.ts and use-preview-routing.ts along with two surrounding Python tools, I realized the panel's character is more unique than just a captcha. The session inside the panel is the only ticket. The case list and details are bound to a PHP session, and a robot fetch to the same URL still returns that same 769-byte interstitial. The panel is not a helper tool; the panel is the credential.
Rotating Tokens: Navigation Must Be Driven by Clicks
The second characteristic that makes URLs unshareable is the path pattern: /list_perkara/page/{N}/{token}, and that token rotates on every page. Deep URLs I constructed myself were bounced right back to the previous page. Navigation must be driven by clicks, period. Furthermore, drive_preview often reports failure even when navigation succeeds. The success flag from the automation tool is not the truth; the returned delta URL is the fact. If I set up automatic retries on top of that flag, the result is double-clicking and skipping pages.
The tab model is also not what I imagined. There is no API to switch tabs. Every action reading or moving the page always targets the active tab. Opening a URL reuses the last used browser tab; the URL has no identity, the tab is the container being navigated. This means the chat link I send functions as a remote control for the panel tab: open the same URL, the intended tab moves forward, without duplication.
No CDP: Remote Debugging Is Intentionally Left Dead
So why not just use the DevTools Protocol to save effort? Because it is simply not available. This desktop application never enabled remote debugging; several ports I suspected were CDP listeners turned out not to be. Architecturally, this is how it is: Google supports CDP for its own official products, and direct third-party use is unsupported [1]. In Electron, the remote debugging endpoint only opens if the developer intentionally adds the switch before the application is ready [2]. An open debug port in a profile carrying a session is like handing over the full key to that session; leaving it dead is the correct decision.
Dual Gateways and Working Habits
Regarding sessions, standard web mechanisms work correctly. The session ID in the cookie is how the server knows two requests come from the same browser [3]. Checkbox-type captchas will let a real user through immediately or issue a challenge, while score variants calculate interactions silently without any input [4]. This case demonstrates that there are two gateways working simultaneously with different properties. The session cookie sticks to the browser, while the rotation token sticks to the navigation flow. A URL saved as-is breaks on both layers simultaneously; that is why crawl results cannot be replayed from a URL list, only from the correct click flow.
The final result: 4,828 bankruptcy and PKPU cases from the Central Jakarta portal, 242 pages times 20 rows, fresh as of October 06, 2026, recorded in the DemandScope project log. Inside are Unilever versus CV Cipta Usaha Nagari, and Ascot Group versus PT MNC Sky Vision Tbk. This is not a lucky result; it is the result of three correct decisions: maintain the session in the panel, drive navigation with clicks, and verify via page state rather than tool flags.
If you want to replicate this pattern, here are four habits I hold. Never automatically retry on top of a click failure that proves to be cosmetic; check the URL and DOM first. Session cookies die with the browser session, so place checkpoints in the middle of the crawl, do not rely on resuming from a URL. Keep the debug port away from profiles carrying real sessions. And when captcha challenges suddenly surge, stop for a moment; the gateway measuring the browser is not beaten by tools, and it does not need to be fought.
## Sources