Auto-Browser
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| APP_ENV | No | Set to 'production' to enable stricter security requirements. | |
| GEMINI_API_KEY | No | API key for Google Gemini provider. | |
| OPENAI_API_KEY | No | API key for OpenAI provider. | |
| API_BEARER_TOKEN | No | The bearer token used to protect the controller API. | |
| CLAUDE_AUTH_MODE | No | Set to 'cli' to use subscription-backed CLI auth for Anthropic. | |
| GEMINI_AUTH_MODE | No | Set to 'cli' to use subscription-backed CLI auth for Gemini. | |
| MCP_TOOL_PROFILE | No | The tool surface to expose. Set to 'full' for the entire legacy/internal tool surface. Default is curated. | |
| OPENAI_AUTH_MODE | No | Set to 'cli' to use subscription-backed CLI auth instead of API keys. | |
| ANTHROPIC_API_KEY | No | API key for Anthropic/Claude provider. | |
| MCP_ALLOWED_ORIGINS | No | Comma-separated list of exact allowed origins for MCP browser clients. | |
| REQUIRE_OPERATOR_ID | No | Set to 'true' if every non-health request must carry an operator ID header. | |
| AUTO_BROWSER_BASE_URL | Yes | The base URL where the Auto Browser FastAPI server is running (e.g., http://127.0.0.1:8000/mcp). | |
| AUTH_STATE_ENCRYPTION_KEY | No | A 44-char Fernet key used for encrypting auth-state storage at rest. | |
| AUTO_BROWSER_BEARER_TOKEN | No | Bearer token for authenticating the bridge with the Auto Browser API. | |
| REQUIRE_AUTH_STATE_ENCRYPTION | No | Whether to force encryption for auth state files. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {} |
| resources | {
"subscribe": true
} |
| experimental | {
"autoBrowser": {
"workflowProfiles": [
"fast",
"governed"
],
"resumableAgentJobs": true,
"cancellableAgentJobs": true,
"discardableAgentJobs": true
}
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| browser.create_sessionA | Create a new browser session and optionally navigate to a start URL. |
| browser.list_sessionsA | List live and persisted browser sessions, one reference each (id, name, status, live, current page, takeover URL). browser.get_session returns a full record. |
| browser.get_sessionA | Get the full record for one browser session by ID: the live session summary (status, current page, tabs) when the session is active, or the persisted session record when it has been closed. Use browser.list_sessions to discover session IDs. |
| browser.observeA | Capture the current browser observation: interactables, tabs, console, and a perception summary. Presets: 'text' — no screenshot or OCR: interactables, accessibility tree and the first 2,000 characters of page text; for text-only models. 'fast' — screenshot only, returned as an image, no text/accessibility extraction; for vision models. 'normal' (default) — text plus a screenshot URL and OCR. 'rich' — normal with twice the interactables and 4,000 characters of text. To read a whole page, use browser.get_html with text_only=true. |
| browser.screenshotA | Capture the current viewport and return it as an image (plus its artifact URL), without the full observe payload. |
| browser.list_auth_profilesA | List reusable saved auth profiles that can be loaded into a new session. |
| browser.list_downloadsA | List files captured from browser downloads for one session. |
| browser.read_downloadA | Read a downloaded file as text (CSV, JSON, TXT, HTML, ...), by download_id from browser.list_downloads or, if omitted, the latest completed download. Paged like browser.get_html. Binary files (PDF, XLSX, images) are refused with their artifact URL. |
| browser.list_tabsA | List currently open tabs/pages for one session. |
| browser.activate_tabA | Bring one tab to the foreground so subsequent observations and actions target it. Tab indexes come from browser.list_tabs. Returns the activated index, the updated session summary, and the current tab list. |
| browser.close_tabA | Close one tab index if more than one tab is open. |
| browser.execute_actionA | Execute one browser action (navigate, click, hover, type, press, select_option, scroll, …) in a session, using the same action schema the agent planner emits. Actions are policy-checked and audited, and governed actions may require a granted approval_id. Call browser.observe first to get targetable element IDs and selectors. Returns the action's verification (what changed) and an observation of the page after it (up to 20 interactables). |
| browser.save_auth_profileA | Save the current session storage state into a reusable named auth profile. |
| browser.request_human_takeoverB | Ask for a human to take over the shared browser desktop. |
| browser.close_sessionB | Close a session and finalize its trace/artifacts. |
| browser.fork_sessionA | Fork a session: snapshot its cookies, storage state, and current URL, then create a new independent session with that state. Useful for branching workflows or running parallel variants. |
| browser.eval_jsA | Execute a JavaScript expression in the current page context and return the result. Every call needs operator approval for that exact expression: the first call returns status approval_required with an approval_id; retry with approval_id once it is approved. Prefer find_elements, get_html or observe for reading the page — they need no approval. |
| browser.wait_for_selectorA | Wait for a CSS selector to reach a specific state (visible, hidden, attached, detached). Returns when the condition is met or raises on timeout. |
| browser.get_htmlA | Read the current page: its serialized DOM (the whole document, not just the viewport), or with text_only=true its visible text — the cheapest way to read a page's content. Returns up to max_chars (default 20,000) from offset; when truncated is true, call again with offset=next_offset for the rest. |
| browser.find_elementsA | Find elements either by CSS selector or by a text/regex query across the page's text content. selector mode returns matching elements' text, href, value, bounding box, and visibility -- useful before clicking or scraping multiple items. query mode (set query, optionally regex and context) returns the matched text plus surrounding context for each hit -- a cheap way to locate a specific string on the page without a full observe. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| Active Sessions | List of all active browser sessions |
| Recent Audit Events | Recent browser audit events across sessions |
TDQS
Scored across 20 tools
Every tool targets a distinct resource or action: sessions, tabs, downloads, auth profiles, observation, reading content, and execution. Even similar tools like observe, screenshot, get_html, and find_elements have clearly different purposes and output formats, eliminating ambiguity.
All tools follow a consistent browser. prefix with verb_noun snake_case naming (list_sessions, create_session, activate_tab, save_auth_profile). Even single-word verbs like observe and screenshot are acceptable and maintain predictability.
With 20 tools, the set is on the heavier side but justified by the breadth of browser automation: session management, tab control, page reading, actions, downloads, auth profiles, and advanced features like forking and JS evaluation. Each tool serves a distinct purpose, so the count feels appropriate for a full-featured server.
The surface covers the full lifecycle: session CRUD (create, list, get, close), observation (multiple modes), navigation and interaction (execute_action), tab management, downloads, auth profiles, and even human takeover and forking. There are no obvious dead ends; every action has a complementary read or verification tool.