Flower Control
Allows automated control of webpages through the Brave browser via the Web channel. It uses Playwright to read page text, links, buttons, and form fields, then perform actions such as filling forms, clicking elements, managing tabs, and uploading or downloading files. Brave is currently the only supported browser for this Web integration.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Flower ControlFill out the contact form on the current webpage and submit it."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Flower Control
Download the source preview · Install · Browser login
Give Codex tools to operate websites and Windows apps: fill forms, read documents, use menus, upload files, click, type, and drag.
Install Flower as a Codex plugin, then tell Codex what you want done and which window or browser environment to use. It adds three tool channels: Web for webpage elements, App for desktop controls, and Computer for actions based on screenshots.

What it does
Channel | How it operates | Useful for |
Web | Reads page text, links, buttons, and form fields, then acts on those elements through Playwright | Research, web forms, online code editors, tabs, uploads, and downloads |
App | Reads the controls a Windows app exposes, including names, values, lists, and menus, then operates them through FlaUI / Windows UI Automation | Desktop forms, settings, long lists, menus, and dialogs belonging to the selected app |
Computer | Takes a screenshot of the selected window and sends mouse and keyboard input at the chosen position | Drawing, dragging, canvases, shortcuts, and interfaces with few readable controls |
For example, Web can read a page and fill its form without locating every field by screenshot. App can select an item in a desktop list or change a checkbox by its name. Computer can drag an object on a canvas or use an existing browser window you select. An app must expose its controls for App to read them; Computer provides a way to operate the visible interface when it does not.
Codex can combine the channels in one task, such as editing a webpage through Web and operating a related desktop dialog through App. The model plans the task; Flower supplies the local controls and checks the selected target and action state.
Related MCP server: OpenSky
Control and optional Jev
Known mechanical steps can run in a batch, reducing separate model/tool round trips. Jev is an optional target selector: it receives a short goal and a few candidate labels, chooses a target, and Flower can execute that choice within the same tool call. It is disabled on a new installation and is not required to use any of the three channels.
Press Ctrl+Alt+9 to stop writes. Computer control shows a moving border, an elapsed-time label, and a Stop button. Resuming requires a fresh look at the target; an interrupted action is not silently repeated.
Start here
Source adapters are included for native Windows Claude Code and Antigravity, with a shared local entry and configuration generator for native Cursor, VS Code, and OpenCode. The shared entry has protocol checks and a helper build; individual clients have not completed real task acceptance or installation. Connection mode excludes private profiles and same-target cross-channel handoff. The Codex runtime evidence below does not validate these clients.
This is a Windows source preview. Start with installation, then read browser profiles and login. The setup uses a current Codex desktop installation, Windows 11 x64, CPython 3.14 x64, and .NET 10 SDK. The Web channel also needs a Chromium-family browser at its standard system installation path (Brave is verified; Chrome and Edge are pending verification). Windows 10 and other hosts have not received the same acceptance coverage.
Installation prepares a package for your Windows account and your source directory. It is not a portable copy of the developer's administrator helper. Keep the source directory, Python runtime, and virtual environment in place after installation.
You can ask Codex in ordinary language; you do not need to name every tool call. For an initial trial, use a test window or a public page:
Use Flower App to fill the fields in the window I select. Save and verify the result.
Open this public page in a temporary Flower browser, find the information I asked for, and close the session when finished.
Use Flower Computer to drag the orange object into the blue area in the window I select.
Profiles and privacy
Temporary browsers start separately. The AI profile keeps its own logins and is available for normal agent work. The personal profile, named Luohua in the tool API, needs your permission once per chat. None of these profiles imports cookies from your everyday browser. To use a saved login through Web, log in once in the chosen Flower profile; the login guide walks through the handoff.
Flower has no usage telemetry, crash uploads, remote configuration, or automatic updates. Its control state and browser data are stored locally. Codex still uses its configured model service, and browsing reaches the websites you request. Jev is an optional external AI service, disabled on a new installation; it receives approved short target labels and goals, not raw screenshots or a full page tree. See privacy for the exact boundary.
Browser compatibility
The Web channel accepts the Chromium-family browsers Brave, Chrome, and Edge. Brave is the verified configuration; Chrome and Edge share the same engine and request path, but their real-foreground use is pending verification in this preview. Other engines are not supported.
App and Computer are general Windows window tools. You can select a window from another browser and operate its visible interface through Computer. App can use whatever accessible controls that browser exposes. This does not create a managed Web session or import that browser's cookies into Flower.
Current limits and testing
Login may expire normally. UAC secure-desktop prompts need a person. Custom input methods with English candidate windows need further adaptation. The helper's current tray menu is Chinese; the tool descriptions and this documentation are available in English.
Practical tests cover spreadsheets, documents, drawing, browser editing and file transfer, desktop lists and dialogs, stop/resume, and Jev in all three channels. One document-color task missed the required color precision. These results support the workflows tested; they are not a 95% success claim or a published OSWorld score. Read validation.
License and dependencies
Flower's own code is available under the MIT license. MCP, Playwright, FlaUI, Pillow, and the other pinned dependencies keep their own licenses and are credited in third-party notices.
For fixes, see contributing. For a security issue, see security.
This server cannot be deployed
Maintenance
Related MCP Connectors
AI-powered browser automation — navigate, click, fill forms, and extract data from any website.
AI-powered web automation. Navigate websites using AI agents for one page or a thousand
AI-powered web automation. Navigate websites using AI agents for one page or a thousand
- openhelmOAuthai.openhelm
Autonomous cloud agent tasks: real browser + your tools, structured evidence-backed results.
Related MCP Servers
- AlicenseNot gradedqualityAmaintenanceEnables Windows agents to control desktop applications and isolated Chromium sessions through a unified computer tool, supporting discovery, observation, input, window management, browser automation, and sequencing actions.398 npmMIT
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to automate desktop operating systems and applications through UI automation, screenshots, and input simulation.1MIT
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to automate both web browsers and native desktop applications through a unified interface, supporting tasks like browsing, clicking, typing, and file clipboard operations via exposed MCP tools.1Apache 2.0
- AlicenseAqualityBmaintenanceEnables MCP-speaking AI agents to operate a desktop and browser through structured UI inspection, mouse/keyboard gestures, tab-scoped browsing, and approved local screen recording with editing.31MIT