Browser MCP

Your browser, under your control.

Loading…

Full browser access

Connecting lets authorized MCP clients read pages and signed-in sessions, type and click as you, run arbitrary JavaScript, take screenshots, and close tabs. Actions may send messages, make purchases, or expose private information.

Only trust an upstream and agents you control. Page text can contain malicious instructions. Consider a separate Chrome profile. The upstream control plane and non-HTTP(S) pages are blocked; this is not a security sandbox for arbitrary JavaScript.

Chrome shows its debugger banner during each command. Attachments are released when commands finish. Cancel the banner or use Pause to stop new commands and detach. Already-run JavaScript may leave timers or other ongoing page activity; pausing cannot undo it. Disconnect also removes the local token; revoke server credentials in the dashboard if compromised.

HTTPS origin only. Loopback HTTP is allowed for local development. Chrome will ask permission for this upstream, not every website.

Opens a regular browser tab for sign-in and explicit device approval. Managed upstream uses GitHub; self-hosted upstreams may offer their configured sign-in methods.

Connect with a browser token instead

Use a browser connection token from your upstream dashboard, not an mcp_ bearer token. Stored only in this Chrome profile's local extension storage, never Chrome Sync or a URL. Anyone with local profile access may retrieve it.