Manus is a hosted general-purpose AI agent designed to carry out multi-step work rather than only answer in chat. Depending on the task, it can plan, browse websites, operate authenticated sessions, create and process files, run code in a cloud virtual machine and call third-party data services. The useful output may be a report, spreadsheet, website, analysis or completed web workflow.
The word “agent” should be read as delegated authority, not guaranteed autonomy. Manus can take actions in environments connected to personal or business accounts. Users must decide which data it may see, which actions require confirmation, how credits and failures are bounded, and what external system proves completion.

How a Manus task can cross systems
user request + files
|
v
Manus planner
|
.------+-----------+----------------.
v v v
cloud VM Cloud Browser Browser Operator
files/code cloud session your local browser
| | |
'------+-----------+----------------'
v
third-party APIs / logged-in services / exported artifact
|
human verification + approval
The execution path determines the risk. A cloud VM holds task files and runtime state. Cloud Browser runs remotely and can maintain logins there. Browser Operator asks permission to control the browser on the user’s computer, potentially using already authenticated sessions. These are not interchangeable privacy boundaries.
Cloud Browser versus Browser Operator
| Capability | Cloud Browser | Browser Operator |
|---|---|---|
| Where it runs | Manus cloud environment | User’s primary computer/browser |
| Authentication | User logs into accounts in cloud browser | Can use local authenticated sessions after permission |
| Availability | Can continue while local browser is closed, subject to service | Primary computer must remain online |
| Data exposure | Credentials/session and pages processed in hosted environment | Agent can interact with locally visible account content |
| Best initial use | Public research or a dedicated low-privilege account | Supervised task requiring an existing session |
| Main danger | Persistent cloud login and broad connected account | Accidental action in high-authority personal/work account |
Create dedicated accounts or least-privilege roles where possible. Never use a browser profile that is simultaneously logged into email, finance, admin consoles and social accounts for an experimental agent task. Review sessions and revoke access after temporary work.
Current plans and model access
Official help updated March 2026 describes Free, Pro and Team plans. Free users receive Chat Mode and Manus 1.6 Lite in Agent Mode, with 300 daily-refresh credits and an initial registration allocation described in desktop guidance. Pro starts at $20/month, with annual billing discount, and adds Manus 1.6 and Manus 1.6 Max alongside Lite; the live pricing page should be checked for exact credit allotments. Team is positioned for collaboration, privacy and administrative controls.
Do not compare plans only by credits. Confirm concurrent tasks, model access, storage, browser/VM features, team controls, export, retention, support, renewal and regional availability. “Starting at” means higher tiers or credit bundles can cost more.
| Plan question | Why it changes value | Evidence |
|---|---|---|
| Which agent model? | Lite, standard and Max may differ in capability/cost | Live task selector and plan page |
| Monthly credits? | Defines sustainable task volume | Account dashboard and billing terms |
| Daily credits? | Official help says they apply only to 1.6 Lite | Credit balance before/after test |
| Team governance? | Shared agents and data need roles/audit | Admin documentation and contract |
| Cancellation/refund? | Protects against unused credits or renewal | Checkout and current help article |
Credits are a blended compute meter
Official help says credits are consumed by LLM tokens used for planning/decisions/output, virtual machines used for browser, files and code, and third-party APIs such as professional or financial data. Complexity and duration affect use. Credits are charged during active processing; storing/deploying completed outputs is described as not consuming credits.
Technical failures attributed to Manus are documented as eligible for a full refund of consumed credits. An unsatisfactory but technically completed result may not be the same as a platform failure. Capture the task ID, start/end balance, error, trace and support case.
| Task behavior | Likely credit driver | Cost control |
|---|---|---|
| Long research | Many model/search/browser steps | Limit sources, fields and iteration count |
| Large file processing | VM time plus tokens | Pre-clean files and define output schema |
| Website building | Code, preview, revisions and deployment | Specify acceptance tests before generation |
| Authenticated extraction | Browser time and page count | Set exact records/date range and stop condition |
| Repeated vague prompt | Exploration and rework | Provide constraints and examples upfront |
Measure credits per accepted artifact and human correction minutes. A cheap task that creates unusable output has infinite practical unit cost.
Design a bounded task contract
Replace “analyze competitors” with a contract: target companies, allowed sources, fields, freshness date, output format, maximum pages/iterations, missing-data policy and prohibited actions. State whether the agent may log in, download, upload, submit, message or purchase.
- Goal: one observable outcome.
- Inputs: authorized files, accounts and source list.
- Constraints: time, geography, budget, privacy and exclusions.
- Authority: read, draft, preview or execute for each system.
- Evidence: citations, files, screenshots, logs or receipts.
- Stop: maximum credits/time and escalation conditions.
- Acceptance: deterministic checks plus named reviewer.
The action confirmation ladder
| Level | Example | Required control |
|---|---|---|
| Read public | Visit official product documentation | Source/date validation |
| Read private | Open CRM or email | Scoped account, purpose and data minimization |
| Draft | Prepare email or form | Keep unsent; human reviews full content |
| Reversible write | Create draft record/event | Preview arguments and provide undo |
| External communication | Send email/post/comment | Fresh approval bound to recipient/content |
| Financial/legal/admin | Purchase, contract or permissions | Keep outside autonomous path or require strong accountable gate |
If the recipient, amount, date, data disclosure or scope changes after approval, ask again. A general instruction such as “handle whatever comes up” should never authorize consequential writes.
Browser automation failure modes
Websites change, lazy-load data, contain advertisements and may display instructions hostile to the agent. A page can tell the model to ignore the user, reveal information or click a dangerous link. Treat web content as untrusted evidence, not authority over tools.
- Restrict allowed domains and block internal/metadata addresses.
- Check terms, robots/access policy and rate limits before extraction.
- Never bypass CAPTCHA, access controls or contractual limits.
- Use unique action IDs to prevent duplicate form submissions.
- Confirm success in the external system, not from the agent’s narration.
Cloud VM, files and code execution
A disposable VM limits direct impact on the user’s machine, but output can still contain malicious documents, scripts or dependencies. Do not upload secrets unless necessary. Scan downloaded files and open them in a protected viewer. Do not run generated code in production or with cloud credentials.
Keep source files immutable and hash important inputs/outputs. Record package versions and commands for reproducibility. For data analysis, independently verify row counts, joins, formulas and sample results. A polished spreadsheet can contain a silent denominator or date-filter error.
Account, privacy and team governance
Before connecting a work account, review Manus privacy terms, subprocessors, retention, training choices, processing location and deletion. Browser sessions can expose more than the requested page through cookies and navigation. Use SSO/RBAC/audit controls where offered, but validate their exact plan availability.
| Asset | Minimum policy | Exit procedure |
|---|---|---|
| Cloud browser login | Dedicated least-privilege account | Log out, revoke sessions/tokens |
| Local Browser Operator | Separate browser profile | Remove permission/extension and close profile |
| Uploaded files | Classification and approved purpose | Delete task/files and verify retention terms |
| Team project | Owner, members and audit review | Export evidence, transfer/delete ownership |
| Generated deployment | Secrets, domain and maintenance owner | Shut down hosting and revoke credentials |
Verify artifacts by type
| Output | Independent acceptance checks |
|---|---|
| Research report | Open every source; verify dates, quotes, facts and inference labels |
| Spreadsheet | Schema, row count, duplicates, formulas, units and sampled source rows |
| Website | Build, routes, mobile/accessibility, forms, security headers and ownership |
| Code repository | Diff scope, tests, dependency/security scans and human review |
| Browser action | Authoritative receipt/history and rollback |
| Presentation | Source accuracy, visual legibility, rights and speaker narrative |
Ownership context and why current terms matter
Meta announced an acquisition of Manus in December 2025, and major reporting stated Manus subscriptions would continue. Subsequent 2026 reporting described regulatory complications and separation steps. Because corporate status can change quickly, do not rely on a static directory statement to determine current controller, data-sharing relationship or roadmap. Read the live Manus legal entity, privacy notice and official announcements at signup.
The product itself remains live and its official help content was updated in June 2026. That is stronger evidence for current features than acquisition speculation. Corporate news is relevant to vendor risk, not a substitute for testing the service.
A practical two-week pilot
Days 1–3: public research only, no logins; measure citations and credits. Days 4–7: upload synthetic files and test spreadsheet/code outputs. Week 2: connect one dedicated low-privilege account, allow reads and drafts, and test approval/undo. Do not start with payments, customer messaging or production administration.
Track accepted outcome rate, credits, elapsed time, human correction, factual errors, duplicate actions, privacy exceptions and unrecoverable failures. Compare with a supervised chatbot and a deterministic automation for the same task.
Alternatives
| Option | Best fit | Tradeoff versus Manus |
|---|---|---|
| Manus | Hosted general-purpose artifact and browser tasks | Credit variability and high account/data authority |
| ChatGPT/Claude/Gemini | Supervised research, files and coding | Different agent/action depth and ecosystem |
| Perplexity | Source-forward research | Less general artifact/browser automation |
| n8n/Make/Zapier | Repeatable business integrations | More explicit deterministic workflow setup |
| Browser automation framework | Testable fixed web workflow | Engineering and maintenance, stronger reproducibility |
| Human specialist | High-stakes judgment and accountable execution | Higher direct cost, clearer responsibility |
Frequently asked questions
Is Manus a chatbot?
It includes chat, but Agent Mode can use cloud compute, browsers, files, code and integrations to complete tasks.
What does the free plan include?
Official March 2026 help describes Chat Mode, Manus 1.6 Lite in Agent Mode and daily-refresh credits. Verify the live pricing page.
How are credits consumed?
By LLM tokens, active cloud VM work and third-party APIs, based on task duration/complexity.
Are failed tasks refunded?
Official help says tasks failing for Manus-side technical reasons receive consumed-credit refunds. Document the task and confirm the account balance.
What is the difference between Cloud Browser and Browser Operator?
Cloud Browser runs remotely; Browser Operator can control the local browser after permission and requires the primary computer online.
Can Manus safely send messages or buy things?
Only with explicit argument-bound human approval and a rollback/receipt path. Keep high-consequence actions outside initial pilots.
Who owns Manus?
The corporate situation changed during 2025–2026 and received conflicting/regulatory reporting. Use current official legal/privacy pages for the controlling entity and data terms.
Primary sources
- Official Manus product
- Live pricing page
- Official plan guidance
- Official credit rules
- Official Cloud Browser documentation
- Official Browser Operator documentation
- Current Manus privacy policy
- AP reporting on the December 2025 Meta transaction
- OWASP prompt-injection guidance
Last reviewed July 26, 2026. Plans, credits, models, browser behavior and corporate/legal status can change. Confirm the live product, controller and terms before payment or account connection.

