arc-browser
Enables inspection and operation of Arc browser tabs through a Chromium extension and local daemon, supporting DOM snapshots, navigation, clicking, typing, screenshots, scrolling, and other page actions on explicitly allowed hosts.
Enables inspection and operation of Google Chrome tabs through a Chromium extension and local daemon, supporting DOM snapshots, navigation, clicking, typing, screenshots, scrolling, and other page actions on explicitly allowed hosts.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@arc-browserInspect my active browser tab and summarize the page."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Codex Browser Bridge
English | 简体中文
A local Chromium extension, a persistent browser daemon and an MCP adapter that let Codex (or any MCP client) inspect and operate the browser tabs you explicitly allow. Arc, Chrome, multiple browser profiles and multiple Codex sessions can stay connected at the same time.
This is an independent implementation. It does not copy or impersonate OpenAI's proprietary browser extension.
Features
Multi-browser, multi-profile – connect Arc, Chrome and several profiles at once; every profile gets a stable browser ID.
Multi-session – one daemon owns the browser port; each Codex session starts a lightweight MCP adapter, so sessions never fight over the port.
DOM snapshots with stable refs – compact accessibility-oriented snapshots return
eNreferences you can click, type into, hover, etc.Page actions – navigate, click (by ref, CSS selector or exact visible text), type, keypress, scroll, hover, select, wait, screenshot.
Secure by default – loopback-only, token-authenticated, host allowlist, password redaction, action kill switch.
Related MCP server: Local Browser MCP
Architecture
Arc / Chrome profiles (extension)
│ WebSocket ws://127.0.0.1:17373 (pairing token)
▼
Persistent daemon (launchd on macOS, or `npm run daemon`)
│ authenticated local RPC
▼
MCP adapter (session A) MCP adapter (session B) ...
│ stdio
▼
Codex / Claude Code / any MCP clientSecurity model
Listens on
127.0.0.1only; non-loopback hosts are rejected at startup.A random 256-bit pairing token (generated on first run, stored with
0600permissions) authenticates every connection.Only tabs whose host is in the extension's allowlist are visible. The allowlist is empty by default – you must add hosts yourself.
No cookie, local-storage, history or password APIs are exposed. Password values are returned as
[REDACTED], and typing into password fields is refused.Page actions can be switched off in the extension options while read-only inspection keeps working.
MCP tool annotations distinguish read-only tools from actions, so the host can ask for confirmation before consequential actions.
Requirements
Node.js 20+ and npm
Arc, Google Chrome or another Chromium-based browser
macOS for the bundled
launchdinstaller (on other platforms run the daemon withnpm run daemon)
Installation
1. Build and start the daemon
git clone https://github.com/tingfengyinyue/codex-browser-bridge.git
cd codex-browser-bridge
npm install
npm run check # build + tests
./scripts/install-daemon.sh # macOS: install and start the launchd daemon
./scripts/show-pairing-token.shOn Linux / Windows, keep the daemon running in a terminal instead:
npm run build
npm run daemonThe first start creates the pairing token in ~/.config/arc-browser-bridge/config.json. Never commit or share this token.
2. Load the browser extension
Repeat for every Arc / Chrome profile you want Codex to control:
Open
arc://extensionsorchrome://extensions.Turn on Developer mode.
Click Load unpacked and select the
extension/folder of this repository.Open the extension options page and fill in:
Connection name – a unique, human-readable name, e.g.
Chrome-Work.Bridge endpoint – keep
ws://127.0.0.1:17373.Pairing token – paste the output of
./scripts/show-pairing-token.sh.Allowed hosts – one host per line, wildcards allowed, e.g.
github.com,*.example.com. Keep this list as short as possible.Allow click, type, navigation… – uncheck for read-only mode.
Click Save and connect and approve the host permission prompt. The popup should show Connected.
3. Register the MCP server
Codex CLI
codex mcp add arc-browser -- node /absolute/path/to/codex-browser-bridge/dist/index.jsor in ~/.codex/config.toml:
[mcp_servers.arc-browser]
command = "node"
args = ["/absolute/path/to/codex-browser-bridge/dist/index.js"]The repository also ships a Codex plugin manifest (.codex-plugin/plugin.json, .mcp.json) and a skill (skills/arc-browser/SKILL.md) with operating rules for the agent.
Claude Code (works with any MCP client)
claude mcp add arc-browser -- node /absolute/path/to/codex-browser-bridge/dist/index.jsUsage
Start a new Codex session and ask, for example:
"Inspect my active browser tab and summarize the page."
"Find the Query button on the current tab without changing anything."
"Open the dashboard page and read the numbers in the first panel."
Typical tool flow:
arc_browser_status– check that a browser is connected.arc_browser_list_connections/arc_browser_select_connection– pick a profile when several are online (or passbrowser_idto any tool).arc_browser_list_tabs– find the target tab.arc_browser_snapshot– read the page and geteNreferences.arc_browser_click/arc_browser_type/ … – act, then take a fresh snapshot.
MCP tools
Tool | Purpose | Action |
| Pairing and connection state | No |
| All online browser profiles and IDs | No |
| Select the default browser profile | No |
| Allowed tabs | No |
| Compact DOM / accessibility snapshot | No |
| Visible viewport PNG | No |
| Focus a tab | Yes |
| Navigate within allowlisted hosts | Yes |
| Click by snapshot ref, selector or exact visible text | Yes |
| Type into non-password controls | Yes |
| Send an approved key | Yes |
| Scroll page or element | Yes |
| Hover an element | Yes |
| Select a native option | Yes |
| Wait for time or selector | No |
Clicking React menu items by visible text
Snapshots include up to 200 extra candidates for visible elements whose computed cursor is pointer, so menus built from div/span still get eN references. If an item is visible in page_text but has no reference, click it by exact text:
{ "text": "Settings", "scope": ".side-menu", "occurrence": 1 }scope is a CSS selector or a snapshot reference. Whitespace is normalized, and duplicate matches are refused unless scope or a 1-based occurrence disambiguates them. Text clicks still obey the action switch and the host allowlist.
Configuration
Environment variable | Default | Description |
|
| Bind / connect host (loopback only) |
|
| Bridge port |
|
| Token file location |
| – | Override the token from the config file |
|
| launchd label used by the install / uninstall scripts |
Daemon logs (macOS): ~/Library/Logs/CodexBrowserBridge/.
Uninstall
./scripts/uninstall-daemon.shThen remove the extension from chrome://extensions / arc://extensions, and optionally delete ~/.config/arc-browser-bridge/.
Troubleshooting
Symptom | Fix |
| Start the daemon ( |
| Another bridge process owns the port. Stop it, or run the uninstall script, then reinstall. |
| Open the extension options, check the token and endpoint, then click Save and connect. |
| Add the host to Allowed hosts in the extension options. |
| Start the daemon once, then run |
Development
npm run check # tsc build + vitest
node scripts/validate-extension.mjs # static extension security checks
npm run smoke-daemon # daemon smoke testSee docs/acceptance-matrix.md for the capability matrix and docs/manual-acceptance.md for the live acceptance checklist.
License
This server cannot be deployed
Maintenance
Related MCP Connectors
Hosted real Google Chrome MCP with per-user persistent state. Navigate, click, type, screenshot.
Browser MCP for logged-in tasks. Uses your Chrome — credentials stay local. Zero-token replay.
Live browser debugging for AI assistants — DOM, console, network via MCP.
- TabfleetOAuthcom.tabfleet
Launch, inspect, control, and share isolated cloud browsers for your agents.
Related MCP Servers
- FlicenseNot gradedqualityAmaintenanceEnables AI agents to control a persistent local browser with live tabs, navigation, interaction, inspection, and state management through MCP.6-
- AlicenseNot gradedqualityBmaintenanceEnables local control of existing Chrome/Chromium browser tabs through MCP, including tab management, navigation, content reading, screenshots, and page interaction.Apache 2.0
- AlicenseBqualityCmaintenanceEnables MCP clients to drive a real Chromium browser for automation, including navigation, JavaScript execution, CDP commands, network capture, and multi-tab control.750 PyPIGPL 3.0
- AlicenseNot gradedqualityBmaintenanceEnables AI agents and clients to control a real Chromium browser through MCP tool calls, including navigation, clicking, typing, JavaScript evaluation, screenshots, and DOM snapshots. Supports multiple isolated sessions over authenticated HTTP with no disk writes.Apache 2.0