pilot-browser-mcp
Allows AI agents to attach to and drive the user's existing Brave browser sessions, navigating pages, reading accessibility snapshots, and performing actions like clicks, typing, uploads, and form submissions with visible cursor, human takeover, and approval controls.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@pilot-browser-mcpOpen github.com/notifications and summarize my unread ones"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
pilot-browser
Let AI agents drive your real, logged-in browser, with a visible cursor, human takeover, and approvals for anything consequential. MCP-native.

Real recording: Claude-style agent → pilot-browser MCP server → real Chrome, on a fictional job form (supervised mode). Re-record with npm run demo:record.
Most browser agents run a fresh headless browser with none of your logins, or ship a forked browser. pilot-browser attaches to the Chrome, Brave or Edge you already use, through the browser's own consent prompt (Chromium 144+). The agent works in a tab of its own; you watch its cursor move and can step in at any moment.
Your browser, your sessions: no fork, no profile copying, no cookie export.
You stay in control: clicking in the agent's tab pauses it. The agent can't see the page while you drive, so passwords and 2FA codes you type never reach the model.
Approvals, at the level you choose: four modes from ask before everything to never ask. The default asks before submitting, paying, sending, deleting and uploading.
Injection-resistant by construction: an origin allowlist, destination checks from the live DOM, cross-site copy checks and tamper-proof controls hold even when the model is fooled. They're tested against a fully compromised agent on every CI run (security model).
MCP-native: works from Claude Code, Cursor, or any MCP client.
Status: 0.1, early. Tested on Linux with Chrome 154; CI covers Linux, macOS and Windows. Expect rough edges and breaking changes before 1.0.
Quick start (Claude Code)
Open Chrome (or Brave / Edge) and visit
chrome://inspect/#remote-debugging(brave://…,edge://…). Tick Allow remote debugging for this browser instance. This is a one-time step.Add the server:
claude mcp add pilot-browser -- npx -y @pilot-browser/mcpStart a new session and ask, e.g.: "Use pilot-browser to open github.com/notifications and summarize my unread notifications."
Your browser asks Allow once per session. Click it, then watch the agent work in its own tab.
Other MCP clients: run npx -y @pilot-browser/mcp as a stdio server. On native Windows use "command": "cmd", "args": ["/c", "npx", "-y", "@pilot-browser/mcp"]. Requires Node 22+.
Related MCP server: byob
You stay in control
The pill at the top of the agent's tab shows what it's doing.
| Working. Press Pause, or just click or type in the tab, to take over. Press Hand back when done. Stop ends the session. |
| Approval. Depending on your mode, consequential steps wait for Approve. The approval covers that exact action on that exact page, once. |
| Handoff. For logins, 2FA and CAPTCHAs the agent asks you to do it. It can't see the page until you press Done. |
The agent can't press these buttons and the page can't fake them; see SECURITY.md.
Tools
Tool | What it does |
| Attach to your running browser, or launch a managed one with its own profile. Takes |
| Go to a URL within the allowed origins. |
| Accessibility snapshot with refs, clipped to the viewport by default ( |
| Act on refs from the latest page, with real (trusted) input. |
| Attach files from your configured |
| Answer alert/confirm/prompt dialogs. |
| Viewport PNG, optionally labelled with refs. |
| Ask you to do something in the tab, and wait for you. |
| Close the agent's tab and detach; your browser stays open. |
Every action quotes the observationId of the page it was planned on, so the agent never clicks based on a stale page.
Modes and settings
Pick how much the agent may do without asking:
Mode | Asks you before… | Good for |
| every click, typing, upload and submit | First runs, sensitive sites |
| submits, uploads, sends, deletes, payments, typing data copied from another site | Everyday use |
| only payments/purchases, deletes, destructive dialogs, and cross-site copies | Repetitive work you trust, e.g. job applications |
| nothing | Unattended runs in a managed profile |
Hard rails stay on in every mode: the origin allowlist, the upload folder, checks before clicks that would leave the allowed sites, and your Pause / Stop.
npx @pilot-browser/mcp config # show current settings
npx @pilot-browser/mcp config set mode auto
npx @pilot-browser/mcp config set uploadDir ~/Documents/resumes # enables uploads from this folder only
npx @pilot-browser/mcp config set approvalTimeoutSeconds 300
npx @pilot-browser/mcp config set identity 'Alex Rivera;alex@example.com;+1 555 0100' # your own details
npx @pilot-browser/mcp config set unattended true # nobody at the browser (overnight runs)Settings live in ~/.pilot-browser/config.json and are re-read on every browser_connect, so changes apply to the next session without restarting your MCP client. No MCP tool can change them, so the model can't loosen its own leash. Env vars override the file: PILOT_MODE, PILOT_UPLOAD_DIR, PILOT_APPROVAL_TIMEOUT, PILOT_PROFILE_DIR, PILOT_BROWSER_UNATTENDED, PILOT_IDENTITY, plus PILOT_CHROME for the managed-mode browser binary.
identity: your own name, email, phone and profile links, as ;-separated values or a JSON array. Typing text the agent read on another site normally needs your approval (it could be a one-time code copied out of your inbox). Your own details are exempt, so filling in your name after reading your LinkedIn profile doesn't stop and ask.
unattended: for runs with nobody at the browser, such as a batch left running overnight. Use it with a managed profile (mode: "managed" at connect), which needs no Allow click. In an unattended session:
browser_handoffandbrowser_wait_for_userfail at once withunattendedinstead of waiting;an action that needs approval in your mode fails with
approval_unavailableinstead of asking, so it is skipped, not done;input in the tab doesn't pause the agent (a page moving focus can't stall the run), but Pause and Stop still work;
page results start with
captcha: …when a CAPTCHA or bot check is visible, so the agent can skip that task. pilot-browser never solves CAPTCHAs.
Supported
Chrome / Brave / Edge | Firefox | |
Linux / macOS / Windows | attach + managed | planned (WebDriver BiDi, managed first) |
On WSL with a Windows browser you need mirrored networking.
How it works
pilot-browser is a TypeScript MCP server built on vercel-labs/agent-browser. That project is a Rust engine that drives Chromium over the DevTools Protocol.
Attach mode uses Chromium's approval-mode endpoint. Managed mode launches a browser on a dedicated profile.
The overlay (cursor, pill, controls) is injected into the agent's tab only.
Policy, approvals, the interaction lease and verification all run outside the model.
Details: ARCHITECTURE.md · SECURITY.md.
Package | |
The MCP server ( | |
Chromium driver built on agent-browser | |
Engine-neutral contract, lease, overlay, policy, risk and taint checks |
Development
git clone https://github.com/ajstars1/pilot-browser && cd pilot-browser
npm install && npm run build
npm run typecheck && npm test # unit tests
npm run test:e2e # real headless Chrome: driver, MCP over stdio, injection suiteTo use your checkout from Claude Code: claude mcp add pilot-browser -- node "$PWD/packages/mcp/dist/bin.js". See CONTRIBUTING.md.
License
Apache-2.0. Built on agent-browser (Apache-2.0).
This server cannot be deployed
Maintenance
Related MCP Connectors
AI-powered browser automation — navigate, click, fill forms, and extract data from any website.
AI-powered web automation. Navigate websites using AI agents for one page or a thousand
AI-powered web automation. Navigate websites using AI agents for one page or a thousand
Stealth web automation for AI agents. Login, signup, navigate, screenshot.
Related MCP Servers
- AlicenseBqualityFmaintenanceEnables AI agents to directly control your real Chrome browser with full context including login sessions, cookies, and open tabs. It provides tools for page scanning, JavaScript execution, CDP control, screenshots, and physical mouse/keyboard input for authentic browser automation.20245MIT
- AlicenseNot gradedqualityBmaintenanceLets AI assistants control your real Chrome browser to perform web tasks like reading pages, taking screenshots, clicking, and typing, using your existing logged-in sessions.132MIT
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to securely control a user's existing Chrome profile locally, providing typed browser actions, form and editor support, WordPress workflows, terminal automation, and Figma inspection with policy-based authorization and redacted auditing.MIT
- AlicenseNot gradedqualityCmaintenanceConnects AI agents to your existing daily-driver Chrome so they can inspect, extract from, record, and replay workflows across background tabs without stealing cursor focus, breaking 2FA/SSO sessions, or leaking secrets. A deterministic R0–R4 risk firewall gates state-changing and destructive actions behind human approval.2Apache 2.0


