Gaddi
Provides a browser_signin capability that signs agents into websites by filling credentials from 1Password using its CLI and desktop-app integration. The user authorizes the target site and Login item, Gaddi fills them and returns an outcome to the agent; credentials are excluded from sign-in results and audit entries, and exact matches are redacted from text tool output for ten minutes after use.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@GaddiOpen my Gmail in a background tab and summarize unread emails."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Gaddi
Gaddi is a local MCP server that lets AI agents work in your existing Chrome tabs.
It uses the browser and logins you already have. Agents open background task groups, read pages and interact with controls. Claude Code, Codex and other MCP clients share the same connection and approval rules.
I built it because the browser tools I tried were slow, heavy and kept taking focus from my other apps. I wanted one browser connection I could use with any agent.

You authorize the action
A held action needs a signed decision from the Mac's owner. Telling the agent "yes" does not create that signature.
A local broker checks each request before it reaches Chrome. The default policy holds recognized payments, purchases, deletion, security changes and sends, plus every file upload. Gmail Send actions and direct password-field access are refused. Ordinary reading and navigation continue without a prompt unless an address matches a held rule.
The shipping approval card with its request expiry annotated, using a disposable local page.
The panel names the action and can show its target on the page. Approve or Deny starts macOS owner authentication: Touch ID or the Mac password. A key held in the Secure Enclave signs the decision. The broker binds approval to the pending action and rejects changed requests or reused proofs. There is no software-key fallback.
For sign-ins and eligible sends, Always allow on this site remembers the exact origin, including scheme and port. Send buttons and Enter have separate permissions. Remembering and revoking both require a signed owner decision. The shipped lists are empty; payments, deletion, security actions and uploads never offer this choice.
Where that protection ends
Gaddi guards calls made through Gaddi. It is not a sandbox for an agent that also has your shell access. Its policy matches control names and URLs, mainly in English and Italian; it cannot identify every harmful action or prevent requests a page sends on its own. JavaScript checks can miss obfuscated code.
Pages read through Gaddi go to your agent, including private information visible in logged-in tabs. The extension needs broad site, debugger, bookmark and extension-management access. Review the default policy and Chrome bridge limits before connecting it to sensitive accounts.
Related MCP server: agent-browser-ga MCP
Install
Requires macOS 26+, a Mac with Secure Enclave, Chrome, Node.js 22.18+ on the 22.x line or 23.6+, and Xcode to build the approval app. This is a source installation with an ad-hoc-signed Mac app.
git clone https://github.com/ABCastor/gaddi.git
cd gaddi
npm ci
bash install/register/daemon.sh
bash install/register/app.sh
bash install/register/chrome-bridge.shIn chrome://extensions, enable Developer mode, click Load unpacked and select extension/. Add ~/.local/bin to your PATH. Keep the checkout in place: the installed components reference it.
Register the clients you use, then restart them. Quit apps that own their configuration before registration.
Client | Command |
| |
| |
| |
| |
Antigravity |
|
Another MCP client can launch node /absolute/path/to/gaddi/mcp/server.mjs over stdio. Every installer accepts --dry-run. See configuration and removal.
Work in a tab
gaddi status
gaddi open https://example.com --group "Research"
gaddi look <tab-id>
gaddi click <tab-id> '<element-ref>'
gaddi close <tab-id>open returns the tab ID; look returns text and control references. Keep that ID through the task. MCP tools use the same names with a browser_ prefix. Agents can also type, scroll, select, wait and take screenshots. Input works in the background; browser_show brings a tab to you.
Pass the version from look to reject stale input. When a session ends, its background tabs are cleaned up; tabs shown to you are preserved.
Sign in with 1Password
browser_signin uses the 1Password CLI and its desktop-app integration. You authorize the site and Login item; Gaddi fills it and returns an outcome to the agent. Captchas, passkeys and extra verification can still need you.
Credentials are excluded from sign-in results and audit entries. Exact matches are redacted from text tool output for ten minutes after use; screenshot pixels are outside that redaction. See sign-in and approval details.
Uploads are limited to 20 MB and wait for approval. Protected credential paths and key files are refused, though these checks cannot detect secrets inside arbitrary files. Extension controls cover restart, enable, held disable/removal and optional local installation. The bridge recovers failed connections without replaying page actions.
Development
npm run typecheck
npm run build:extension
bash tests/run-all.shTests use isolated state. Gate tests must fail with their protection removed. Browser tests need Chrome for Testing; Secure Enclave checks need a desktop session. Missing prerequisites are reported as skipped. Commit regenerated extension output after source changes. Visual sources are included.
There is no console or network inspection, download handling, browser-dialog handling or video recording. CSS and Web Animations can be slowed; JavaScript timers, canvas and video cannot. Licensed under MIT.
This server cannot be deployed
Maintenance
Related MCP Connectors
Lets AI agents use a real human as a tool: visual checks, taste, phone calls, unblocking, approvals
AI-powered browser automation — navigate, click, fill forms, and extract data from any website.
AI-powered web automation. Navigate websites using AI agents for one page or a thousand
AI-powered web automation. Navigate websites using AI agents for one page or a thousand
Related MCP Servers
- AlicenseNot gradedqualityBmaintenanceLets AI assistants control your real Chrome browser to perform web tasks like reading pages, taking screenshots, clicking, and typing, using your existing logged-in sessions.133MIT
- FlicenseNot gradedqualityDmaintenanceEnables AI agents to interact with a user's real Chrome browser tabs, executing JavaScript, reading cookies, and making fetch requests within authenticated sessions.-
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to securely control a user's existing signed-in Chrome browser through isolated tab groups, with strict per-session ownership and no cookie or token exposure.3 npmISC
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to securely control a user's existing Chrome profile locally, providing typed browser actions, form and editor support, WordPress workflows, terminal automation, and Figma inspection with policy-based authorization and redacted auditing.MIT