browser-mcp
Automatically handles Okta/Entra WebAuthn passkey challenges during agent-driven browsing by arming a CDP virtual authenticator before clicks/navigations, preventing native OS dialogs from blocking sign-in flows.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@browser-mcpTake a snapshot of the current page"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Browser MCP
Chrome/Edge extension (Manifest V3) that turns the browser into an MCP server for AI agents — 68 browser tools, direct code-mcp-gateway mode, screen recording, TTS narration, page annotations.
How it works
flowchart LR
A["AI agent"] -->|"MCP JSON-RPC"| G["code-mcp-gateway"]
G -->|"wss /ws/{deviceId}?token=…"| E["Extension (MV3)"]
E -->|"CDP / tabs"| P["Pages"]Mode | Connection | When to use |
Direct gateway (default) | Popup: Device ID + Token → | Remote agents over the internet; extension serves MCP itself, no local server |
Local bridge |
| File store ( |
Toolbar icon: gray = disconnected, green = connected.
Related MCP server: BrowserPilot
Install
Requires Chrome or Edge ≥ 111.
Open
chrome://extensions, enable Developer mode, click Load unpacked, selectpackages/browser-extension(or install the zip above).Click the toolbar icon, enter the gateway Device ID and Token, click Connect — the popup shows Connected (gateway).
The token must match the device's token configured on the code-mcp-gateway. Leave it empty only if you accept that anyone reaching the gateway can control the browser.
Tools (68)
Element discovery uses the @ref system: snapshot returns an interactive element tree with [ref=eN] markers; every interaction tool accepts a ref or a CSS selector.
Group | Tools |
Discovery |
|
Interaction |
|
Navigation |
|
Page reads |
|
Network & DevTools |
|
State & debugging |
|
Emulation & control |
|
Media & narration |
|
Vault |
|
Media & narration
Tool | Behavior |
| Narrates each step via native speech synthesis ( |
| Caption bar for narrated text ( |
| Draws arrows, boxes, circles, highlights and text labels on a fixed overlay ( |
Vault
Encrypted in-browser credential store: master password → PBKDF2 → AES-256-GCM, stored in chrome.storage.local, never sent to the gateway.
Action | Purpose |
| Vault lifecycle |
| Credential CRUD |
| Fill a login form from the vault — secrets never leave the extension |
| Supply HTTP Basic/Digest credentials from the unlocked vault instead of tool arguments |
OS-dialog prevention (automatic)
While the extension is connected and an agent is driving a tab, native prompts that no extension can read or click are suppressed automatically — the agent never has to call a tool for this:
Suppressed | How |
WebAuthn / passkey dialog (Windows Hello, security key, Okta/WAM) | A CDP virtual authenticator is armed before every agent click/navigation and survives the redirect, so a click that bounces into an Okta/Entra page which fires WebAuthn on load is answered inside the renderer |
HTTP Basic/Digest prompt | Auth-challenge interception is enabled on the tab, so Chrome never renders its own prompt (auto-cancelled after 60 s instead of hanging) |
Download Keep/Discard bubble + downloads shelf |
|
The guard runs on connect (active tab), on every agent command, and on tabs the agent opens while it is driving; it is skipped under stealth. Turn it off with webauthn {action:"auto", enabled:false}.
webauthn also exposes explicit control when the agent wants it:
Action | Purpose |
| Install / remove / inspect the virtual authenticator for a tab |
| Toggle the automatic guard above |
| Manage credentials (resident passkeys). |
An OS dialog that is already on screen cannot be read or clicked by any extension. A get() that needs a credential held only by the platform authenticator (your real Windows Hello passkey) still reaches the OS — enroll a passkey into the virtual authenticator, or preload its key with add.
Local server
bun browser-mcp.ts # http://127.0.0.1:7777/mcp
bun browser-mcp.ts --token <s> # require auth on /mcp + /filesLocal clients use http://127.0.0.1:7777/mcp — see mcp-client.example.json. Verify: curl -s http://127.0.0.1:7777/health.
CLI
bun browser-mcp.ts --gateway <domain> --token <s> --id <device-id>Flag | Description | Default |
| Listen port |
|
| Bind address |
|
| Require auth on | none |
| Require this token from the extension | none |
| Link the MCP endpoint through a code-mcp-gateway | none |
| Gateway device id (overridden by the popup ID) | random |
| Where downloaded/uploaded files are stored |
|
| DEV ONLY: skip the extension Origin check | off |
Security
/browser/wsaccepts onlychrome-extension://origins;/mcpand/files/*reject browser origins other than localhost (CSRF).--tokengates/mcpand/files/*(?token=or Bearer);--extension-tokengates the extension bridge.In gateway mode the extension verifies the device token forwarded with each request before answering.
File IDs are 12-char random hex, validated and sanitized; uploads capped at 500 MiB, screenshots 8 MiB inline.
Binds to
127.0.0.1by default; binding to0.0.0.0without--tokenprints a warning.
Development
bun run check # syntax check
bun run test # test suite
bun run build # build dist/browser-extension.zip
bun browser-mcp.ts # run the serverThis server cannot be deployed
Maintenance
Related MCP Connectors
Hyperbrowser MCP — wraps the Hyperbrowser AI-agent browsing API
Live browser debugging for AI assistants — DOM, console, network via MCP.
AI-powered web automation. Navigate websites using AI agents for one page or a thousand
AI-powered web automation. Navigate websites using AI agents for one page or a thousand
Related MCP Servers
- AlicenseNot gradedqualityNot gradedmaintenanceAn extension-based MCP server that enables AI assistants to control your existing Chrome browser, leveraging your active login states and settings for automation. It provides over 20 tools for tasks like semantic tab search, screen capture, network monitoring, and direct element interaction.-
- FlicenseBqualityDmaintenanceEnables AI to control browsers via natural language for web automation, testing, and data scraping. Supports Chrome-based browsers and integrates with any MCP-compatible AI tool.172-
- AlicenseNot gradedqualityAmaintenanceEnables AI assistants to control your webpage via MCP, allowing navigation, screenshots, clicks, content reading, and more through a Chrome extension.21MIT
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to control your existing Chrome browser via MCP, using your logged-in sessions for automation on authenticated sites. Provides high-level browser tools plus raw CDP and Chrome API access.MIT