browser-relay
Officialbrowser-relay
Drives the user's real, logged-in Chrome from AI agent sessions without ever handing another browser client the user's cookies (which gets sessions invalidated). An MV3 extension lives inside real Chrome and executes commands sent over a WebSocket from a local relay daemon.
Architecture
Claude session -> MCP (HTTP :9277/mcp) -> relay daemon -> WebSocket -> MV3 extension -> real Chrome tabsextension/- the Chrome MV3 extension.server/relay.js- the relay daemon: MCP streamable-HTTP server + WebSocket server. Node >= 18, single dependency (ws).deploy/ai.wecko.browser-relay.plist- launchd LaunchAgent template (macOS);install.shfills in your node and repo paths.install.sh- installs deps + the LaunchAgent and prints the two remaining manual steps.test/- MCP smoke test (e2e.sh), a direct tool-call helper (call.js), and a mock extension for testing the relay without Chrome.
The extension connects out to ws://127.0.0.1:9277/ws as a client (it does
not run a server itself), sends a hello on open, and answers every command
the relay sends with exactly one ok:true/ok:false reply.
Install
/bin/bash install.shThis copies the LaunchAgent, (re)starts it, and waits for
http://127.0.0.1:9277/health to answer. It then prints two steps you do by
hand:
Register the MCP server:
claude mcp add --transport http browserx http://127.0.0.1:9277/mcp -s userLoad the extension:
chrome://extensions-> enable Developer mode -> Load unpacked -> selectextension/.
Tools (relay commands)
command | args | result |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
tab_id is optional everywhere it appears - it falls back to the active tab
of the last focused normal window.
snapshot is the main way an agent finds things to act on: it walks every
frame of the page (iframes included) for interactive elements, tags each one
with a stable data-bx-id="fN:eM" ref (per-frame prefix), and returns a
compact list plus frame metadata. click, type_text and wait_for search
all frames, so admin apps rendered in iframes (OVH, Shopify) work directly
without evaluate fallbacks.
Cost guardrails (v1.1.0)
snapshotdefaults to 150 elements per frame (hard cap 250) and thetext_excerptis opt-in viainclude_text.evaluateoutput is capped at ~6KB (strings truncated, arrays/objects limited) and prefers compact JSON.screenshotis downscaled to max 1280px, jpeg quality 75 by default.clickfires exactly one nativeel.click()(v1 fired 2 click events).wait_forpolls every 1.5s across all frames.
The relay enforces a backstop cap on every tool result, so no single call can inflate the model context.
Known limitations
Synthetic input is not trusted input.
clickandtype_textdispatch real DOM events, but they are not OS-level input, so some sites (payment iframes, bot-detection-heavy forms) may reject or flag them.Screenshots require the tab to be active.
chrome.tabs.captureVisibleTabonly captures the active tab of a window;screenshotbriefly activates the target tab if it isn't already, then restores the previous one.evaluatecan be blocked by a page's CSP. Strictscript-srcpolicies can reject the injected eval; when that happens the error is surfaced verbatim rather than swallowed. A future version should switch tochrome.userScripts.executein theUSER_SCRIPTworld, which is exempt from page CSP.
Changelog
v1.1.0 - cost/token optimizations: smaller snapshots, capped
evaluateoutput, downscaled jpeg screenshots, single-click fix, iframe support for snapshot/click/type/wait.v1.0.0 - initial release.
The MV3 service worker gets killed by Chrome. It is normal for
background.jsto be torn down and revived repeatedly; thebx-keepalivealarm (every ~24s) and the reconnect-on-close logic are what keep the WebSocket connection coming back. A short gap in connectivity right after Chrome starts or the SW is revived is expected.Google (and similar) may challenge with reCAPTCHA or a security check. If that happens, the agent must stop and ask the human to clear it in the real browser window rather than trying to script around it.
Same-origin iframes are not walked by
snapshotin v1.
Troubleshooting
curl 127.0.0.1:9277/health- confirms the relay daemon is up.tail -f relay.log- relay daemon stdout/stderr (from the LaunchAgent).Reload the extension from
chrome://extensionsif it stops responding.Inspect the service worker console:
chrome://extensions-> browserx relay -> "service worker" link, to see WebSocket connect/reconnect logs and any errors from injected scripts.