login-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| LOGIN_MCP_KEY | No | If set, exit encrypts the site profiles with scrypt and AES-256-GCM and removes the plaintext directory until the next use by this process. Without the key, profiles are only protected by filesystem permissions (chmod 0700). The key is never logged. Do not put the key on the command line. | |
| LOGIN_MCP_DATA_DIR | No | The data directory for storing per-site Chrome profiles at $LOGIN_MCP_DATA_DIR/sites/<site>/profile. | ./data |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| auth_statusA | One line per site: site id, confirmed login and work origins, last used time, last confirmed time, session age, and session ok or needs_login. needs_login means the last open saw a login page. Age makes a stale ok visible. Returns no cookies, tokens, or URL query secrets. |
| auth_loginB | Open a visible Chrome window for one site id so a human can log in. Also opens a local tab that lists the login origin and work origin, then the button 이 사이트 허용. That button confirms those origins. Returns immediately. Does not type credentials or return the confirmation code. |
| auth_confirmA | Record origins for one site after a human allow signal from the last 10 minutes. The 이 사이트 허용 button already confirms origins; use this after the terminal confirm command. Refuses if that signal is missing. Optional workOrigin must be part of the same human signal. Does not read cookies. |
| auth_openA | Open a URL in that site's Chrome profile. The origin must already be human-confirmed for the site (login origin or a work origin). Re-resolves every A/AAAA and pins Chrome to one address from that checked set, then fails closed if the connected address is outside the set. Returns human_action_required and no page text when the page looks like a login or challenge, or when the final origin is not a confirmed login or work origin. Blocks subresource requests to link-local or metadata hosts. |
| auth_readA | Read visible text from this site's current page, or navigate first when url is set and its origin is human-confirmed for the site. Re-resolves DNS on every call. Refuses unconfirmed origins. Truncates long text. Never returns cookies or storage. |
| auth_actA | Perform one click, fill, or press on this site's current page. Re-resolves DNS on every call. Refuses unconfirmed origins, password fields, and challenge widgets. fill and press require value. Does not solve CAPTCHA or 2FA. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 6 tools
auth_login (human-driven login window) and auth_open (agent-driven navigation in a confirmed profile) both open Chrome, which could cause confusion, but their descriptions clearly delineate human login vs. agent browsing. auth_read and auth_act are cleanly separated by read vs. interaction, and auth_status is distinct.
All six tools use the consistent auth_ verb_noun pattern (auth_login, auth_confirm, auth_open, auth_read, auth_act, auth_status). Names are predictable and map cleanly to actions.
Six tools is well-scoped for an authenticated-browsing server: setup (login, confirm), operations (open, read, act), and introspection (status). Each tool earns its place with no redundancy.
The surface covers the full login-to-automation lifecycle including origin confirmation and status reporting, with sensible safety boundaries. Session teardown/logout or multi-step action batching are minor gaps an agent can work around.