Chrome Bridge
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| CHROME_BRIDGE_CAPS | No | Comma-separated list of tool groups to load (e.g., core,audits,visual,network,storage,dom,files,all) | core |
| CHROME_BRIDGE_HOST | No | Bind address for the server | 127.0.0.1 |
| CHROME_BRIDGE_PORT | No | WebSocket port for the Chrome Bridge server | 8765 |
| CHROME_BRIDGE_TOKEN | No | Shared secret for extension and relay authentication |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| get_statusA | Check bridge status: extension connection, server mode (primary/relay), port, version |
| get_tabsA | List every open tab with id, url, title, active flag and mine (created by this session). Read-only. Find a tab_id when the implicit target is not the one you mean. include_windows adds position, size, state and type of each window — needed before moving or tiling. |
| navigateA | Navigate a Chrome tab to a URL. Returns a preview of interactive elements with refs usable in click/type_text/hover. |
| screenshotA | Screenshot of the visible viewport only (PNG), at the current scroll position, or one per viewport preset with presets. Read-only. Activates the tab in the background without stealing window focus, then restores the previous tab. Downscaled to ≤1568px: for fine print, element_screenshot with scale. |
| execute_jsA | Run JavaScript in the page (MAIN world). Requires the extension's "Allow user scripts" toggle; errors explain setup if disabled. |
| clickA | Click an element by CSS selector or by a ref (n1, n2…) from get_interactives or navigate. A real pointer sequence: it can submit, open a dialog or navigate — use wait_after. Not idempotent; a native confirm() blocks the bridge: handle_dialogs first. |
| type_textA | Put text into an input, textarea or contenteditable, by selector or ref. Replaces the whole value through the native setter (React/Vue controlled inputs register it) and fires input and change. mode=keys emits keydown/input/keyup per character for autocomplete and masked fields: slower, use it only when mode=set leaves the field empty. |
| read_pageA | Read the page as text (default), markdown, raw HTML, or accessibility tree. Read-only. markdown keeps headings, links and tables at a fraction of the HTML cost. Expensive on big pages: HTML on a large table costs tens of thousands of tokens for data you filter anyway — prefer extract_table/extract for repeated content, get_interactives for click targets. |
| get_page_infoA | Get page metadata: meta tags, scripts, stylesheets, links, and forms |
| get_storageA | Read localStorage, sessionStorage or cookies of the current origin (type=all for every one). Read-only. Cookies come with domain, path, expiry and the httpOnly/secure flags, so this also answers whether a session cookie is present — write them back with set_storage, or snapshot a logged-in state with session_fixture. |
| query_domA | Query DOM elements by CSS selector, returning structure, attributes, bounding rect, and computed styles. |
| modify_domA | Change an element in the live DOM: setAttribute, removeAttribute, addClass, removeClass, setStyle, setTextContent. Nothing is persisted — the next reload restores the page as the server sends it. For styling many elements at once inject_css is one call instead of N. |
| inject_cssA | Inject a CSS rule into the page. Stays until the next navigation or reload, and re-injecting the same id replaces it rather than stacking. Affects only what is rendered — the stylesheet of the site is untouched. |
| read_consoleA | Read console messages captured since page load, incl. uncaught errors and unhandled rejections. |
| monitor_networkA | Monitor network requests. source=page: XHR/fetch hook (installed on first call); source=browser: all requests incl. static assets; source=websocket: connections and messages. format=har exports HAR 1.2. |
| create_tabA | Open a new tab, optionally at a URL, and make it the implicit target of later commands in this session. Each call creates another tab: reuse a tab_id or navigate() to move an existing one instead of piling up tabs. |
| wait_forA | Block until a condition holds: element, text, function (JS expression; needs the "Allow user scripts" toggle), navigation (mode=spa for client-side routes), network_idle. Polls until timeout (10s element/function, 15s the rest) then returns |
| scrollA | Scroll. action=to: once to element/coordinates; action=until: repeatedly until element visible, network idle, or no new content (infinite scroll). |
| set_storageA | Write, delete or clear a localStorage/sessionStorage key, or a cookie with its path, domain and expiry. action=clear wipes every entry of that type for the origin and cannot be undone — on a site the user is logged into, clearing cookies logs them out. Read the current values first with get_storage. |
| fill_formA | Batch fill form fields with React-compatible events. Handles input, select, checkbox, radio, and textarea. With submit_selector it also submits, so a repeated call submits twice — not safe to retry blindly. |
| viewport_resizeA | Resize the Chrome window to a preset (mobile 375x812, tablet 768x1024, desktop 1440x900) or explicit dimensions; the viewport is smaller by the browser chrome, action=get reports the real one. width/height override half a preset. A maximized window on ChromeOS ignores the request. |
| element_screenshotA | Screenshot cropped to one element or to a viewport region (PNG), optionally enlarged. Read-only. The cheapest image in the set, because it carries only the box you asked for — and with scale the way to read fine print: crop the box, zoom it, verify. |
| full_page_screenshotA | Full-page capture by scrolling: stitched segments of ~2 viewports (≤1568px), or one image per viewport with stitch=false. Expensive: ~2.7k image tokens per segment, only max_segments returned, the rest via segment_offset. Reading the text you need is cheaper by an order of magnitude — prefer read_page, extract or find_text unless layout is the question. |
| measure_spacingA | Measure the gap, overlap and distance in CSS pixels between two elements, with their margins and paddings. Read-only. Values come from the current layout, so zoom and viewport size change them: viewport_resize({zoom:1}) and a fixed viewport_resize make results comparable across runs. |
| watch_domA | Watch DOM mutations (MutationObserver). First call installs the watcher; later calls read accumulated mutations. |
| emulate_mediaA | Make the page believe it runs elsewhere, until reset or reload: prefers-color-scheme, prefers-reduced-motion, print mode, navigator.userAgent/platform. user_agent changes only what page JS reads — the request header is network_rules modify_header. Pair with viewport_resize to emulate a device. |
| hoverA | Hover over an element (mouseenter/mouseover), by CSS selector or ref. |
| press_keyA | Send a key to the focused element (or to selector, focusing it first) as a real keydown/keypress/keyup sequence, so framework handlers fire. For typing a value use type_text; this is for Enter, Tab, Escape, arrows and shortcuts. Not idempotent: two calls send the key twice. |
| get_framesA | List frames (main + iframes) with frameId, parent, URL — for the frame_id parameter of DOM tools. |
| tab_actionA | Tab lifecycle: close, activate, reload, back, forward, discard, mute, duplicate, close_session (only tabs this session created). close drops unsaved work and cannot be undone — it may be the user's tab. reload drops injected CSS, emulations and hooks. duplicate works where create_tab is forbidden (chrome-untrusted://) and lands in the source window, app windows included. discard replaces the tab id. |
| upload_fileA | Set a file on input[type=file] from the server filesystem via DataTransfer (max 10MB). |
| dismiss_overlaysA | Dismiss cookie banners/modal overlays: OneTrust, Cookiebot, Usercentrics, then generic heuristic. Idempotent. |
| handle_dialogsA | Auto-accept/dismiss future JS dialogs (alert/confirm/prompt), logging them. reset restores native dialogs and returns the log. |
| find_textA | Find text on the page: parent selector, context, visibility, position per match. Attaches nearby interactive elements (with refs for click/type_text/hover) for the first visible match. |
| network_rulesA | Network interception, browser-wide, survives reloads until cleared: block, redirect, set/remove headers, stub a synthetic body, or record real API responses and replay them with forced errors/latency (local helper; from HTTPS pages the stub host must be trusted). |
| screenshot_diffA | Visual regression: save a named baseline (viewport, element, or a PNG such as the design mockup) and compare later — changed-pixel % and a red-highlighted diff; or compare_urls: production vs staging in this tab, pixels plus text diff, logged-in pages included. Baselines are in-memory (lost on service worker restart). |
| track_eventsA | Decode the tracking beacons the page fired (GA4, Meta Pixel, Google Ads, TikTok, LinkedIn, Pinterest, Microsoft Ads, GTM, Hotjar, Clarity) from the browser network log: one line per event with its key params. Read-only; POST-body params are flagged, not decoded. |
| cookie_auditA | Cookie and consent-banner audit: clears this site's cookies, reloads, records cookies and third-party requests BEFORE consent, accepts the banner, records again; the findings name the trackers contacted before consent. Logs you out of the audited site. |
| handoffA | Hand the browser to the user for what only a person can do — 2FA, CAPTCHA, login, a choice — and wait: a banner in the page shows your message with Done/Cancel, the call returns on click or timeout, redirects included. pick_element: the user clicks an element and you get its selector. Never type credentials yourself. |
| watchA | Keep watching a page in the background — "tell me when the pipeline is green / the Approve button appears / this number changes" — checked every interval_s by the extension. Events are collected, not pushed: action=poll, or a script blocking on "chrome-bridge watch --wait ". Survives extension idling, not a browser restart. |
| read_formA | Read a form as the user filled it — label, type, value, checked/selected, required-but-empty, browser validity — to check it against the project's documents before an irreversible Submit. Password and card values come back [redacted]. Read-only, on request. |
| auditA | One-call page audit, pick the kinds: accessibility, keyboard (tab order and focus issues), SEO, security headers, broken links, Core Web Vitals, unused CSS, resources (which plugin/theme/module/host slows the page), cache (is the CDN serving the new version). A summary line per kind; with save_to the full Markdown report with every finding. Read-only. |
| find_settingA | Where is a setting in an unknown admin panel: follows the panel's menu links (same origin) until a page contains the keyword and reports the menu path. Navigates the tab, leaves it on the page found, stops at max_pages. |
| extract_tableA | Read a real as JSON: thead cells become keys, each row an object. Read-only. Only for tabular markup — |
| drag_and_dropA | Drag an element onto another. html5 = DragEvent+DataTransfer; pointer = pointer/mouse events (sortable libraries). |
| clipboardA | Read or write the system clipboard (text). Activates the tab first. write overwrites whatever the user had copied, which is not recoverable. |
| set_geolocationA | Override navigator.geolocation with fixed coordinates (page-level patch). reset restores native. |
| manage_downloadsA | List downloads, start one, or wait for the newest to finish. Files land in the browser Downloads folder, not on the server. download reports the real state: with Chrome set to ask where to save, it comes back waiting_for_user — bytes fetched, nothing moves until someone picks a destination. |
| save_pageA | Save the full page (DOM, styles, images) as an MHTML archive file on the server filesystem. |
| http_requestA | HTTP request sent from the browser, with the logged-in user's cookies: fetches what a server-side request gets a login page for (invoices, authenticated JSON, exports). Text bodies inline (capped by max_length); save_to writes the bytes — the way to read a PDF, since read_page returns nothing on a PDF tab. |
| move_tabA | Move an existing tab into another window (chrome.tabs.move), keeping id, history and page state; works on chrome-untrusted:// tabs too. The destination must be a normal window: out of an app/popup window is fine, into one is refused. A ChromeOS Terminal tab can be pulled out (new_window, window_type popup) but never merged back: extensions cannot create app windows. |
| tile_windowsA | Tile Chrome windows over one monitor in equal parts with no gap. Only Chrome windows. The monitor is the one of a window already on it, whose work area is read from a page there: at least one target needs a scriptable tab (not chrome://). Maximized windows are restored first, since maximized ignores bounds. |
| window_layoutA | Save the current window arrangement under a name, restore, list or delete. save overwrites silently. Window ids do not survive a browser restart: restore matches windows by the overlap of their tab URLs and reports the ones it cannot recognise instead of guessing. |
| http_authA | Set/clear credentials for HTTP Basic/Digest auth dialogs (browser-wide, in-memory only). |
| session_fixtureA | Snapshot localStorage, sessionStorage and cookies of the current origin into a named fixture (a logged-in state, usually), restore one, or list them. save overwrites silently; restore writes on top without clearing and refuses on a different origin — cookies would attach to the wrong site. |
| get_interactivesA | List actionable elements (buttons, links, inputs, [role], [onclick]) with ready-to-use CSS selector, label, position, flags. Prefer this over dumping HTML to discover selectors. |
| extractA | Read repeated non-tabular structures — product cards, list items, search results — as one record per item: item_selector matches the repeating block, fields map output names to selectors relative to it. Read-only, deterministic, parsed server-side from the main-document HTML. |
| assertA | Assert a page condition, polling until timeout: element exists/visible (optionally with count or containing text), text on page, tab url/title. Patterns: substring, or "/…/" for regex. Recorded flows replay it as a test. |
| session_recordA | Record the commands of this session as a replayable jsonl (chrome-bridge replay --file ); observe what the user does in a tab ("watch how I do it") into the same format plus a readable procedure, never recording sensitive values; export a recording as a Playwright test for CI. Replays target the tab they navigate. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 59 tools
Most tools have clear, distinct purposes. Overlap exists among reading tools (read_page, extract, extract_table, find_text, query_dom) but each targets a different structure or use case, so ambiguity is limited. A few similar-sounding pairs (watch vs watch_dom, screenshot vs element_screenshot) are still distinct enough.
The naming convention is mostly verb_noun (e.g., navigate, get_page_info, type_text, extract_table), but there are many variations: bare verbs (click, scroll, hover, watch), noun-style names (cookie_audit, session_fixture, handoff), and mixed prefixes (get_, set_, find_, read_, create_, manage_). This inconsistency makes the API slightly less predictable.
With 59 tools, the count is well above the typical MCP range (3–15) and feels heavy for a single server. While the breadth covers many browser automation features, several tools could be consolidated (e.g., get_page_info/query_dom/read_page), suggesting the set is larger than necessary.
The surface is exceptionally comprehensive, covering navigation, DOM interaction, forms, screenshots, file handling, dialogs, storage, cookies, performance/accessibility audits, session recording, network interception, and even human handoff. No significant gaps for a browser automation use case.