bb-mcp
Drives labelled Google Chrome profiles through a locally installed extension and native messaging host. Agents can list available browsers/profiles, bind a conversation to one after user confirmation, work within a dedicated tab group, adopt existing tabs by URL, capture page snapshots (with password, payment and one-time-code fields redacted), upload files from allowed local folders, and run JavaScript in the conversation's own tabs.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@bb-mcpOpen the PR in my work browser and summarize the discussion."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
browser-bridge
Local-only browser control for AI agents. Any MCP client (Claude Code, Codex CLI, Grok Build CLI) can drive one labelled Chrome profile per conversation. Nothing leaves the machine: no cloud relay, no network port, no telemetry.
It is built for people who keep several signed-in Chrome profiles (for example work and personal) and run several agent conversations at once:
Each conversation binds to one profile, and only after you confirm it.
Each conversation works only in its own tab group, so conversations never act in each other's tabs.
A closed profile pauses the conversation instead of sending its actions to another profile.
See docs/design.md for the architecture, protocol and security model.
Requirements
macOS with Google Chrome 116 or later
At least one MCP client: Claude Code, Codex CLI or Grok Build CLI
Related MCP server: Umbra MCP Server
Install
git clone https://github.com/jbjzq/browser-bridge.git
cd browser-bridge
bun install
bun run setupsetup compiles bb-hub, bb-mcp and bb-native-host into ~/.browser-bridge/bin/, installs the Chrome native messaging manifest, registers bb-mcp with every installed agent CLI, copies the built extension to ~/Desktop/browser-bridge-extension (override with BB_EXT_DIR), and prints how to load it.
Then, in each Chrome profile you want agents to use:
Open
chrome://extensionsand turn on Developer mode.Click Load unpacked and choose the extension folder printed by
setup.Click the browser-bridge icon and set a label, such as
workorpersonal.
A label belongs to the first profile that claims it, even while that profile is closed. Ownership is kept in ~/.browser-bridge/labels.json.
Use
In a conversation the agent calls bb_list_browsers, proposes a browser with bb_select_browser, asks you to confirm, then calls bb_confirm_browser. From then on it works only in its own tab group in that profile. To hand it one of your tabs, give it the URL; it calls bb_adopt_tab.
Per-repo browser hint
Add --prefer <label> in the repo's own MCP config so the agent proposes the right browser first. It is a hint only; you still confirm. Replace /Users/<you> with your home directory.
Claude Code (.mcp.json in the repo, overrides the user-scope entry):
{ "mcpServers": { "browser-bridge": { "command": "/Users/<you>/.browser-bridge/bin/bb-mcp", "args": ["--prefer", "work"] } } }Codex (.codex/config.toml) and Grok Build (.grok/config.toml):
[mcp_servers.browser-bridge]
command = "/Users/<you>/.browser-bridge/bin/bb-mcp"
args = ["--prefer", "personal"]Security
The hub listens on a Unix socket (
0600, in a0700directory), so only your macOS user can connect. There is no TCP port.Chrome starts the native host only for this extension's id.
Password, payment-card and one-time-code fields are redacted in page snapshots, and the agent cannot type into them.
bb_uploadonly sends non-hidden files from~/Downloads,~/Desktopand the conversation's folder.A web page can still contain text that tries to steer the agent (prompt injection). Tab confinement limits the damage to the conversation's own tabs in the bound profile; it does not prevent it there.
bb_evalruns arbitrary JavaScript in those tabs.
Troubleshooting
Popup says "Not connected": run
bun run setupagain and reload the extension. The native host manifest must list this extension's id.label_duplicatein the popup: another profile already uses that label.browser_not_running: the bound profile is closed. Open it; the binding is kept.bb_uploadrefuses a file: the file is outside the allowed folders or hidden. Add folders withBB_UPLOAD_DIRS=/path/a:/path/bin the MCP server's environment.The yellow "started debugging this browser" banner is Chrome's and cannot be hidden by the extension.
Develop
bun test # unit + integration
bun run typecheck
bun run build:extensionLicense
This server cannot be deployed
Maintenance
Related MCP Connectors
Browser MCP for logged-in tasks. Uses your Chrome — credentials stay local. Zero-token replay.
Your own cloud computer run by an AI agent: signed-in browser, its own email, files, long jobs.
Real Chrome for agents: start a browser, read pages as numbered markdown, click, type, hand off.
Run multi-step tasks in a real Chrome browser: persistent environments, live view, human takeover.
Related MCP Servers
- AlicenseAqualityDmaintenanceDrives your real local Chrome with profile isolation, allowing LLMs to interact with your logged-in sessions without modifying your actual profile.1338 npmMIT
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to securely control a user's existing signed-in Chrome browser through isolated tab groups, with strict per-session ownership and no cookie or token exposure.3 npmISC
- FlicenseNot gradedqualityAmaintenanceEnables AI agents to control existing Chrome and Firefox browser sessions locally, including tab management, navigation, form filling, screenshots, and persistent scripts, without remote relays or debugging ports.11 npm-
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to control a user's existing Chrome browser with preserved logins, performing tab management, element interaction, script execution, and screenshots, all locally via a Chrome extension and Python bridge.2MIT