Purroxy
Purroxy is an MCP server that gives Claude secure access to websites behind your login by replaying recorded browser automation actions. Credentials never leave your local machine, and sensitive data is redacted before being exposed to AI.
purroxy_status: Verify whether the Purroxy desktop app is running and reachable, and see how many automation capabilities are available.purroxy_list_capabilities: Discover all recorded browser automations, including each capability's name, description, target website, and required input parameters.purroxy_run_capability: Execute a recorded browser automation by name — Purroxy replays the saved steps in a headless browser using stored session credentials, accepts dynamic input parameters, and returns structured data extracted from the resulting page.
Deploys backend functionality to Cloudflare Workers, enabling serverless execution of Purroxy's automation capabilities in a distributed edge computing environment.
Purroxy
Record what you do on any website. Securely automate it forever.
Pre-release software. Purroxy is under active development. Functionality may be incomplete or break between updates — no guarantees are provided. If you run into issues or have feedback, please open an issue on GitHub.
Purroxy gives Claude secure access to websites behind your login. You walk through a site in Purroxy's built-in browser, and every action you take is recorded as a capability. At runtime, Purroxy replays those exact steps on your behalf. Your credentials never leave your machine.
Download
Latest release — macOS, Windows, Linux.
Related MCP server: browser-gateway
How it works
Log in once — Enter a URL and log in through the secure embedded browser. Credentials never touch any AI.
Record what you want done — Walk through the site. Every click, search, and navigation is recorded as a reusable capability with parameters.
Ask Claude — Claude replays the recorded steps, fills in variable inputs, and extracts results. Your password is never stored or shared.
Security
Zero-knowledge login — Purroxy never sees your password, only session cookies
Encrypted vault — Sensitive data stored in your OS keychain, typed into forms by Purroxy, never sent to Claude
Data scrubbing — Vault values removed from page content before Claude sees it
Local extraction — Data extracted on your machine, sensitive results redacted
Claude Desktop integration
Purroxy connects to Claude Desktop via MCP. One-click setup in Settings. Your capabilities become tools Claude can call.
Pricing
Free during pre-release. Early accounts will be grandfathered when paid plans launch ($3.89/month). Or contribute a capability to the community library and use Purroxy free forever.
Development
npm install
npm run dev # Vite dev server + Electron
npm test # Run tests
npm run package # Build distributableBackend (Cloudflare Worker):
cd backend
npm install
npm test # Run backend tests
npm run dev # Local dev server
npm run deploy # Deploy to CloudflareLicense
Apache 2.0
Available Tools
3 toolspurroxy_list_capabilitiesA
List all browser automation capabilities recorded in Purroxy. Returns each capability's name, description, target website, and required parameters. Call this first to discover what automations are available before executing one with purroxy_run_capability. Requires the Purroxy desktop app to be running.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It effectively describes key behaviors: it's a read operation (implied by 'List'), specifies the return format (capability details), and states a prerequisite (Purroxy app must be running). However, it doesn't mention potential limitations like rate limits, error handling, or data freshness, leaving some behavioral aspects uncovered.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is appropriately sized and front-loaded: it starts with the core purpose, then details the return data, usage context, and prerequisite in three concise sentences. Every sentence adds essential information without redundancy, making it highly efficient and well-structured for quick comprehension.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's low complexity (0 parameters, no output schema, no annotations), the description is largely complete: it covers purpose, usage, return data, and prerequisites. However, without an output schema, it could benefit from more detail on the return structure (e.g., format, pagination), but the mention of specific fields mitigates this gap adequately for this simple tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has 0 parameters with 100% coverage, so the baseline is 4 as per the rules for zero parameters. The description doesn't need to add parameter semantics, but it does mention 'required parameters' as part of the return data, which aligns with the schema's lack of inputs. No additional value is needed or provided beyond the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose with specific verbs ('List all browser automation capabilities') and resources ('recorded in Purroxy'), and distinguishes it from sibling tools by mentioning its role in discovery before using purroxy_run_capability. It explicitly names the returned fields (name, description, target website, required parameters), making the purpose highly specific and differentiated.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides explicit usage guidelines: it states when to use this tool ('Call this first to discover what automations are available before executing one with purroxy_run_capability'), names the alternative tool (purroxy_run_capability), and includes prerequisites ('Requires the Purroxy desktop app to be running'). This gives clear context and exclusions for effective tool selection.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
purroxy_run_capabilityA
Execute a recorded browser automation capability by name. Purroxy replays the recorded actions in a headless browser with saved session credentials, then extracts and returns structured data from the resulting page. Call purroxy_list_capabilities first to discover available capability names and their parameters. Requires the Purroxy desktop app to be running.
| Name | Required | Description | Default |
|---|---|---|---|
| capability_name | Yes | The name of the capability to execute, exactly as returned by purroxy_list_capabilities. | |
| parameters | No | Input parameters for the capability as key-value string pairs. Check purroxy_list_capabilities to see which parameters each capability accepts and which are required. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It effectively describes key behaviors: it's a mutation tool (executes actions), requires external dependencies (Purroxy desktop app), involves automation (replays recorded actions in headless browser), uses saved credentials, and returns structured data. However, it doesn't mention potential side effects, error handling, or performance characteristics like timeouts.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is front-loaded with the core purpose in the first sentence, followed by essential context in subsequent sentences. Every sentence earns its place: the first defines the action, the second explains the mechanism, the third provides usage guidance, and the fourth states prerequisites. No wasted words, and the structure flows logically from what to how to when.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity (automation execution with dependencies), no annotations, and no output schema, the description does well by covering purpose, usage, and prerequisites. However, it lacks details on return values (only mentions 'structured data' vaguely) and doesn't address potential failures or limitations. For a tool with no output schema, more clarity on results would improve completeness.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents both parameters thoroughly. The description adds value by explaining that capability_name must match exactly from purroxy_list_capabilities and that parameters are key-value string pairs, reinforcing the schema. It doesn't provide additional syntax or format details beyond the schema, but the context is helpful.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the specific action ('Execute a recorded browser automation capability by name'), the resource ('recorded browser automation capability'), and the mechanism ('Purroxy replays the recorded actions in a headless browser with saved session credentials, then extracts and returns structured data'). It distinguishes from sibling tools by specifying this is for execution, while purroxy_list_capabilities is for discovery and purroxy_status likely for monitoring.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly states when to use this tool ('Call purroxy_list_capabilities first to discover available capability names and their parameters') and provides prerequisites ('Requires the Purroxy desktop app to be running'). It clearly differentiates from alternatives by indicating the discovery tool must be called first, establishing a clear workflow.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
purroxy_statusA
Check whether the Purroxy desktop app is running and reachable. Returns the connection status and the number of available capabilities. Use this to verify Purroxy is ready before attempting to run automations.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden. It discloses that the tool returns 'connection status and the number of available capabilities,' which adds useful behavioral context. However, it lacks details on error handling, latency, or authentication needs, leaving some gaps in transparency for a status-checking tool.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences that are front-loaded with the core purpose and followed by usage guidance. Every sentence adds value without redundancy, making it efficient and well-structured for quick understanding.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's low complexity (0 parameters, no output schema, no annotations), the description is complete enough for a status-checking tool. It explains what the tool does, when to use it, and what it returns. However, without an output schema, it could benefit from more detail on return values (e.g., specific status codes), but this is a minor gap.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has 0 parameters with 100% coverage, so no parameter documentation is needed. The description appropriately does not discuss parameters, focusing instead on the tool's purpose and usage. This meets the baseline for tools with no parameters.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the specific action ('Check whether the Purroxy desktop app is running and reachable') and the resource (Purroxy desktop app). It distinguishes from siblings by focusing on status verification rather than listing or running capabilities, making the purpose explicit and differentiated.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides explicit guidance on when to use this tool ('Use this to verify Purroxy is ready before attempting to run automations'), which directly contrasts with the sibling tools (purroxy_list_capabilities, purroxy_run_capability) that are for listing and executing capabilities. This gives clear context and alternatives.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
3 tool updates
- Added
purroxy_list_capabilities - Added
purroxy_run_capability - Added
purroxy_status
TDQS
Scored across 3 tools
Each tool has a clearly distinct purpose: list_capabilities for discovery, run_capability for execution, and status for health checking. There is no overlap in functionality, making it easy for an agent to select the right tool for each task without confusion.
All tools follow a consistent verb_noun pattern with the prefix 'purroxy_' (e.g., purroxy_list_capabilities, purroxy_run_capability, purroxy_status). This predictable naming scheme enhances readability and usability across the tool set.
With only 3 tools, the set feels thin for a browser automation server, potentially lacking operations like managing capabilities (e.g., create, update, delete) or handling errors. However, it covers basic discovery, execution, and status checks, which is borderline but functional for its stated purpose.
The tools provide core functionality for listing and running capabilities, with a status check, but there are notable gaps: no tools for creating, updating, or deleting capabilities, and no error handling or session management tools. This limits the server's ability to fully manage browser automations, though basic workflows are supported.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
- platform7nOAuthtech.p7n
Connect Claude to your Platform7n workspaces — chat, links, and tasks. One-click OAuth.
GA4, Google Ads and Search Console in Claude. Read-only OAuth, multi-account for agencies.
Give Claude only the Google Drive files you choose. Every action logged.
Multiple Google accounts (Gmail, Calendar, Drive, Contacts, Tasks) in one Claude connector.
Related MCP Servers
- FlicenseNot gradedqualityDmaintenanceConnects Claude Desktop to Google Drive, allowing Claude to access and interact with your Drive files and folders securely through OAuth authentication.1-
- AlicenseNot gradedqualityAmaintenanceReliable, scalable browser infrastructure for AI agents. Route, pool, and failover across any browser provider. 8 built-in browser tools using raw Chrome CDP - navigate, screenshot, snapshot, interact, evaluate. Zero-config with auto Chrome detection & concurrent sessions support51810MIT
- AlicenseNot gradedqualityCmaintenanceGive Claude direct access to your AWS account, SSH into your servers, run shell commands on your laptop, query your databases, and manage PM2 processes — all from a Claude chat. No Claude Code subscription needed. Your keys never leave your machine.2MIT
- AlicenseNot gradedqualityBmaintenanceEnables Claude to access your Fathom meetings, transcripts, and AI summaries.1016MIT