Tether
Provides integration with HashiCorp Vault, allowing the server to incorporate Vault secrets into browser-automation workflows.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@TetherGo to my inbox and summarize my top 3 unread emails"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.

Private, local-first browser control for AI assistants — your browser, your rules.
2. See It Work
Real-time execution: local daemon, Chrome MV3 extension, and governed MCP tool calls against test fixtures.
Popup Control | Live Session Feed | Tier-2 Approval Card |
Popup: Transport status & one-click injection | Governed Click: Tier pills, refs & ms timing | Per-Action Consent: Diff rows & Deny action |
Related MCP server: Umbra MCP Server
3. What Tether Is
A standard connector, not an autonomous agent: Your AI client (Claude, ChatGPT, Cursor) brings the reasoning; Tether enforces your rules.
Single point of policy: Every action is decided inside the local extension service worker (
TRD §2.3). Relays and daemons cannot grant permissions.Zero remote code (HR-1): Strictly Manifest V3. No
eval, no remote CDNs, no runtime script fetching.Page content is untrusted data (HR-6): Extracted text carries
trust: "untrusted"; prompt injection cannot trigger browser tools.Local OCR redaction: Screenshot text is scanned locally; PANs, tokens, and credentials are blacked out before returning image bytes.
Sub-200ms hard kill switch (HR-10): Instantly terminates sockets, revokes tokens, and aborts in-flight actions.
Three Operating Modes (PRD §7.2)
Mode | Transport | Where Page Data Lives |
A: Local Daemon (Default) | Loopback stdio / Streamable HTTP ( | Stays 100% on machine ( |
B: Encrypted Relay | Outbound WSS + X25519 & AES-256-GCM sealed envelopes | Client & browser only; relay handles blind ciphertext |
C: WebMCP Proxy | Chrome 149+ declarative web model context proxy | Retained in local browser origin context |
4. Quick Start (Mode A)
git clone https://github.com/jyotitiwari250657/Tether-MCP-server.git
cd Tether-MCP-server && pnpm install && pnpm build
node apps/daemon/dist/index.js serve
# Chrome → Extensions → Developer Mode → "Load unpacked" → apps/extension/.output/chrome-mv3Verify streamable HTTP MCP directly using curl:
# 1. Initialize MCP session (returns Mcp-Session-Id header)
curl -s -i -X POST http://127.0.0.1:18796/mcp -H "Content-Type: application/json" -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"curl","version":"0.1"}}}'
# → HTTP/1.1 200 OK | Mcp-Session-Id: a3f8… | {"jsonrpc":"2.0","id":1,"result":{"protocolVersion":"2025-06-18",…}}
# 2. List tools (returns 40 frozen tools)
curl -s -X POST http://127.0.0.1:18796/mcp -H "Content-Type: application/json" -H "Mcp-Session-Id: a3f8…" -d '{"jsonrpc":"2.0","id":2,"method":"tools/list"}'
# → {"jsonrpc":"2.0","id":2,"result":{"tools":[{"name":"browser_snapshot",…},{"name":"browser_click",…}… 40 tools]}}
# 3. Call tool (snapshot active tab)
curl -s -X POST http://127.0.0.1:18796/mcp -H "Content-Type: application/json" -H "Mcp-Session-Id: a3f8…" -d '{"jsonrpc":"2.0","id":3,"method":"tools/call","params":{"name":"browser_snapshot","arguments":{}}}'
# → {"jsonrpc":"2.0","id":3,"result":{"content":[{"type":"text","text":"# Acme Docs\n[A1] link \"Overview\"\n…"}]}}5. Architecture
flowchart LR
Client["AI Clients<br/>(Claude, ChatGPT, Codex, Cursor)"] --> Trans["Transport Layer<br/>stdio MCP / Streamable HTTP :18796 / Relay WSS"]
Trans --> Daemon["Daemon / Relay"]
Daemon -->|"loopback WS :18795"| SW["Extension Service Worker"]
SW --> Policy["Policy Engine<br/>(Single Point of Policy)"]
Policy --> CS["Content Script Bridge"]
CS --> Page["Browser DOM Page"]
SW --> Vault["Vault → OS Keychain"]
SW --> OCR["OCR → Native Backend"]
SW --> Audit["Audit → SHA-256 Hash Chain"]Components
Package / App | Role | Key Invariant |
| Wire types, envelopes, and 40 tool schemas | Frozen schemas ( |
| MV3 Service worker, UI panels, policy engine, DOM refs | Single point of policy ( |
| Loopback WS server, stdio/HTTP MCP, OS keyring bridge | Zero policy granting power; binds loopback |
| Cloudflare Worker + Durable Objects for remote clients | Blind ciphertext routing; zero plaintext storage ( |
| Native OS OCR wrappers (Windows/macOS/Linux) | Redacts PII locally before image serialization |
| 50-task automated benchmark runner | Tests navigation, form-filling, extraction, policy |
| Landing site, documentation, and pairing UI | Zero trackers, zero remote CDNs |
Anatomy of One Tool Call
Client Request: AI issues JSON-RPC
tools/callover stdio or Streamable HTTP.Daemon Auth: Daemon validates origin and auth token, packaging request into typed envelope.
Loopback Transport: Dispatched across WebSocket (
:18795) to the Chrome MV3 service worker.Policy Decision:
engine.tschecks origin grant level; prompts diff card if Tier 2 (HR-8).Ref Resolution: Element ref (e.g.
A1) resolves to live DOM node via SHA-1 text signature.Isolated Action: Synthetic input sequence (pointer, focus, click) executes safely in content script.
Redaction Pipeline: Output sanitized against PAN/email regex and native OCR redactor (
HR-7).Audit Seal: Write-ahead SHA-256 tamper-evident entry committed before returning result.
For deep dive, see docs/ARCHITECTURE.md.
6. Tool Surface
Tether exposes 40 frozen tools across three functional profiles:
Read-Only Profile ( | Description | Risk |
| Ref-indexed DOM accessibility trees and element lookup | T0 (Read) |
| Structured extraction with | T0 (Read) |
| Local OCR-sanitized viewport capture | T0 (Read) |
| Tab querying and local title searches | T0 (Read) |
Action & Governance Profiles ( | Description | Risk |
| Governed synthetic interactions using resolved refs | T1 (Act) |
| Batch field filling and dropdown selections | T1 (Act) |
| High-risk destructive submissions; diff approval required | T2 (Confirm) |
| Vault secret injection directly to input; never context | T2 (Secret) |
| Runtime capability management for domain boundaries | T3 (Admin) |
| Export tamper-evident log; absolute kill switch ( | T3 (Admin) |
7. Security & Governance
Single Point of Policy (
TRD §2.3): Policy is enforced strictly inapps/extension/lib/policy/engine.ts.Zero Plaintext on Wire: Mode B uses X25519 key exchange + AES-256-GCM authenticated envelopes.
Zero Plaintext at Rest: Credentials resolve from OS Keychain (DPAPI / macOS Keychain / Secret Service).
Default Deny (
HR-12): Sensitive categories (banking, healthcare, auth) blocked until explicit opt-in.Absolute Kill Switch (
HR-10): Aborts in-flight actions and revokes tokens in<200msfrom popup or API.Tamper-Evident Audit & Local OCR: Chained SHA-256 log plus on-device OCR redaction of rendered PANs.
Read the THREAT_MODEL.md and SECURITY.md.
8. Proof & Quality Gates
Every metric below is verified directly from committed artifacts and live suites:
Metric / Gate | Proven Value | Artifact Source |
Unit Test Suite | 438 passed (69 test files) |
|
E2E Integration | 13 scenarios passed (real Chrome + daemon) |
|
Live Eval Benchmark | 50 tasks (80% pass overall, 100% nav, P95 1683ms) | |
Extension Bundle | 342.79 KB JS (budget $\le$ 400 KB) | |
Traceability Matrix | 123/257 requirement IDs verified (47.9%) | |
Frozen Protocol Hash |
| ADR-016 frozen schema integrity assertion |
OCR Redaction Proof | Zero PAN detected after local OCR redaction | |
Kill Switch Latency |
|
9. Repository Layout
tether/
├── apps/
│ ├── daemon/ # Node loopback WS server, stdio/HTTP MCP, keyring bridge
│ ├── extension/ # Chrome Manifest V3 extension (WXT + React 18)
│ ├── relay/ # Cloudflare Worker E2E encrypted routing
│ └── web/ # Astro + Starlight public documentation
├── packages/
│ ├── eval/ # 50-task automated evaluation suite
│ ├── ocr/ # Native OCR redactor bindings
│ └── protocol/ # Frozen schemas, envelopes, and tools (HR-4, HR-5)
├── tests/e2e/ # Playwright suites driving real browser & daemon
├── docs/ # Architecture, design system, specs & logs
└── scripts/ # Gate checks, asset composition, and bundle analyzers10. Beta Status & Honest Limitations
Local Mode A is production-ready; Mode B relay is in active development.
Egress monitor is detect-only: Flags suspicious exfiltration patterns but does not drop packets.
Chromium-only in v1: Targets Manifest V3 on Google Chrome; Firefox and Safari deferred (
NG-5).WebMCP proxy requires Chrome 149+: Pre-release flags required for native in-page model tools.
ChatGPT Actions limitation: State-modifying POST requests require ChatGPT Enterprise/Business.
OCR native requirements: Uses Windows OCR / macOS Vision natively; fallback engine on Linux.
11. Documentation Index
Document | Purpose |
Product Requirements Document, RFC-2119 invariants ( | |
Technical Requirements Document, trust boundaries, and protocols | |
Threat modeling analysis across | |
Design system, Light Ribbon theme tokens, and typography | |
In-depth component decomposition, transport matrices, and diagrams | |
Release engineering, checklist, and distribution channels | |
Store and directory submission package data | |
Developer guidelines, code standards, and setup | |
Community standards and expectations | |
Vulnerability disclosure and bounty scope |
12. Contributing, Security & License
Contributing: Contributions welcome! Please review CONTRIBUTING.md before submitting pull requests.
Security: Report vulnerabilities via GitHub Security Advisories or as detailed in SECURITY.md.
License: Released under the MIT License © 2026 Tether Contributors.
This server cannot be deployed
Maintenance
Related MCP Connectors
Security gateway for AI agents: policy, approval, and audited execution, no secrets shared.
Operate Linux, macOS and Windows from your LLM. Every action runs through an auditable allowlist.
- openhelmOAuthai.openhelm
Autonomous cloud agent tasks: real browser + your tools, structured evidence-backed results.
Supervised API-write gateway for AI agents with policy, human approval and execution receipts.
Related MCP Servers
- AlicenseNot gradedqualityBmaintenanceLets AI assistants control your real Chrome browser to perform web tasks like reading pages, taking screenshots, clicking, and typing, using your existing logged-in sessions.133MIT
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to securely control a user's existing signed-in Chrome browser through isolated tab groups, with strict per-session ownership and no cookie or token exposure.1 npmISC
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to securely control a user's existing Chrome profile locally, providing typed browser actions, form and editor support, WordPress workflows, terminal automation, and Figma inspection with policy-based authorization and redacted auditing.MIT
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to drive a real, already logged-in browser from the CLI or over MCP, with enforceable approval gates for actions and safeguards against prompt injection.3,033,206 npmMozilla Public 2.0