browser-mcp-bridge
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@browser-mcp-bridgeOpen my Gmail and summarize unread emails from today"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
browser-mcp-bridge
A desktop tray application that bridges the Browser MCP stdio server to Streamable HTTP, so HTTP-based MCP clients — like Open WebUI or anything else on your network — can drive your actual, logged-in browser.
┌──────────────┐ HTTP + Bearer ┌──────────────────────────────┐
│ Open WebUI │ ─────────────────► │ browser-mcp-bridge (tray) │
│ (homelab) │ :8020/mcp │ ├─ stdio ─► @browsermcp/mcp│
└──────────────┘ │ └────────► Browser ext. │
│ └─► your Chrome│
└─────────────────────────────┘Why?
Browser MCP is a stdio MCP server that pairs with a Chrome extension and automates your real browser — with your cookies, your sessions, your login state. Great idea, but stdio means the MCP client has to run on the same machine. If your LLM frontend lives on a homelab server (Open WebUI, etc.), it can't reach it.
browser-mcp-bridge closes that gap:
🌉 stdio ⇄ HTTP — exposes
@browsermcp/mcpas a Streamable HTTP endpoint🔐 Bearer token auth — every
/mcprequest must carry your token🌐 CIDR allowlist — restrict which source IPs may connect (defaults to localhost only)
🖥️ System tray app — live status icon, settings GUI, log viewer
🩺 Honest status light — 3-state tray icon: green (browser connected), orange (bridge up, browser extension disconnected), red (subprocess down)
💓 Heartbeat — polls the browser with a read-only
browser_snapshotevery 10s (configurable) so the status light reflects reality, not stale state🛟 Crash-resilient — auto-restarts the npx subprocess with backoff; survives browser restarts
🩹 Health endpoint —
GET /health(no auth) for monitoring from anywhere on the LAN
Related MCP server: agent-browser-mcp
Security model
This tool gives an LLM full control of your real browser session. Please read this.
Layer | What it protects against |
Bearer token | Anyone without the token (e.g. passing bots, LAN scanners) |
CIDR allowlist | Anyone outside your allowed IP ranges (e.g. WAN exposure) |
Plaintext HTTP | ⚠️ Nothing — token and traffic are unencrypted on the wire |
Recommended setup: LAN-only deployment (homelab), token in Open WebUI, CIDR limited to your subnet. Do not expose this to the internet without putting a TLS-terminating reverse proxy in front of it.
The token is stored in ~/.config/browser-mcp-bridge/config.json (chmod 600).
Requirements
Python 3.10+
Node.js (for
npx, which fetches@browsermcp/mcp)Qt6/PySide6 (tray + GUI; headless mode works without it)
Install
git clone https://github.com/NopeNix/browser-mcp-bridge.git
cd browser-mcp-bridge
python3 -m venv venv
venv/bin/pip install -r requirements.txtUsage
GUI (tray) mode
venv/bin/python bridge.pyTray icon appears in your system tray (green → orange → red depending on state). Right-click for: Show window · Restart subprocess · Quit. The settings dialog lets you set port, bearer token (show/hide), CIDR allowlist, and heartbeat interval.
Headless mode
venv/bin/python bridge.py --headlessDesktop integration (KDE/Plasma)
mkdir -p ~/.local/share/applications ~/.config/autostart
cp packaging/browser-mcp-bridge.desktop ~/.local/share/applications/
cp packaging/browser-mcp-bridge.desktop ~/.config/autostart/systemd user service (optional, headless servers)
cp packaging/browser-mcp-bridge.service ~/.config/systemd/user/
systemctl --user daemon-reload
systemctl --user enable --now browser-mcp-bridge⚠️ Run either the GUI or the headless service — they both bind the same port and spawn their own subprocess, so running both will conflict.
Connecting Open WebUI
Admin Panel → Settings → Tools → add MCP server:
http://<bridge-host>:8020/mcpAuth: header
Authorization=Bearer <your-token>(find it in the tray settings dialog)In Chrome, click the Browser MCP extension icon → Connect
Tools (
browser_navigate,browser_click, …) appear in the model's toolset
Configuration
~/.config/browser-mcp-bridge/config.json:
{
"port": 8020,
"token": "auto-generated-on-first-run",
"allowed_cidrs": ["127.0.0.1/32", "::1/128"],
"heartbeat_interval": 10
}allowed_cidrs— list of IPv4/IPv6 CIDRs permitted to call/mcpheartbeat_interval— seconds between read-only browser probes (status light refresh)
Endpoints
Route | Auth | Purpose |
| none |
|
| Bearer + CIDR | MCP Streamable HTTP endpoint |
| Bearer + CIDR | session termination |
Troubleshooting
Symptom | Likely cause |
Tray green, tools fail with "No connection to browser extension" | Extension not connected — click its icon → Connect |
Tray orange | Bridge up, browser extension disconnected (checked every heartbeat) |
Tray red | npx subprocess crashed — restart from tray menu |
| Your IP is not in |
| Missing or wrong bearer token |
Port taken at startup | Another instance or service on that port — change |
Architecture
bridge.py single-file app: HTTP server, subprocess manager, tray GUI
packaging/ .desktop launcher, systemd unitThe HTTP server is stdlib http.server (no aiohttp/flask dep for the server path);
PySide6 is only needed for the tray/GUI. Each HTTP request is translated 1:1 into a
JSON-RPC message over the subprocess's stdio, and responses are matched back by
request id.
License
MIT — see LICENSE.
This server cannot be deployed
Maintenance
Related MCP Connectors
Browser MCP for logged-in tasks. Uses your Chrome — credentials stay local. Zero-token replay.
Zero-setup MCP gateway securely connecting AI to your tools with authentication and workflows
Access Kernel's cloud-based browsers and app actions via MCP (remote HTTP + OAuth).
Remote streamable-HTTP MCP server running on a single Cloudflare Worker. Your assistant gets live Airbnb, Amazon, Booking.com, Google Flights, Maps and Reddit data, social search on X, Instagram and TikTok, the Meta Ad Library, and image/video generation without any keys. Connect your own accounts to let it send WhatsApp or Telegram messages, work an IMAP inbox, manage Meta Ads campaigns and publish to X and LinkedIn. OAuth 2.1 with PKCE; stored credentials are AES-256-GCM encrypted.
Related MCP Servers
- AlicenseNot gradedqualityAmaintenanceMCP server for local browser control via Chrome/Edge extension, enabling agents to open isolated tabs, observe pages, take screenshots, and interact with accessible controls using an existing browser profile. It is agent-agnostic, local-only, and supports safe session scoping with origin grants and sensitive-data blocking.MIT
- AlicenseAqualityAmaintenanceMCP server that drives your real Chrome/Edge/Opera browser through a Chrome extension and DevTools Protocol, preserving logins and session state, and can also perform OS-level mouse and keyboard input behind approval.5146 PyPI1MIT
- AlicenseNot gradedqualityAmaintenanceLocal browser MCP server that lets AI assistants control a real desktop browser via tools like navigate, snapshot, and search_web.MIT
- AlicenseBqualityCmaintenanceEnables AI assistants to remotely drive a hosted headless browser over HTTP, supporting navigation, clicking, typing, and structured page reading through the Model Context Protocol. It also provides bearer-token authentication for secure remote MCP access.237,739,093 npmApache 2.0