Back to Browse

Browser Mcp Cdp MCP Server

Developer ToolsLow Risk10.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

Local Chrome via CDP with profile-snapshot isolation and shared-broker multi-client support

About

Local Chrome via CDP with profile-snapshot isolation and shared-broker multi-client support

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (2 strong, 4 medium validity signals). No known CVEs in dependencies. Package registry verified. Imported from the Official MCP Registry.

6 files analyzed · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

file_system

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

Shell Command Execution

Runs commands on your machine. Be cautious — only use if you trust this plugin.

network_websocket

Check that this permission is expected for this type of plugin.

database

Check that this permission is expected for this type of plugin.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-zhiqi-li-browser-mcp-cdp": {
      "args": [
        "-y",
        "browser-mcp-cdp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

browser-mcp-cdp

A Model Context Protocol (MCP) server that drives your real local Chrome via the Chrome DevTools Protocol. Designed for agents that need access to your logged-in sessions (Gmail, internal dashboards, banking, etc.) without uploading credentials to a cloud service.

Why another browser MCP?

Different tradeoffs from the alternatives:

browser-mcp-cdpPlaywright MCPChrome DevTools MCP
BrowserYour local ChromeManaged Playwright ChromiumYour local Chrome
Login state✅ Snapshot of your profile (cookies, logins, IndexedDB)❌ Fresh profile✅ Real profile (modifies it)
Profile isolation✅ Copy-on-start, real profile untouchedN/A⚠️ Direct attach
Multi-client✅ Shared broker across MCP clients❌ Per-client❌ Per-client
DependenciesNode only (no Playwright download)Playwright + browsersNode only

The profile snapshot pattern means you can ask an agent to "check my email" — it sees your Gmail logged in — but the agent's actions never modify your real Chrome profile. Each session gets a disposable copy.

Install

claude mcp add browser -- npx -y browser-mcp-cdp

Or add manually to ~/.claude.json / Claude Desktop config:

{
  "mcpServers": {
    "browser": {
      "command": "npx",
      "args": ["-y", "browser-mcp-cdp"]
    }
  }
}

Requires Node 18+ and Google Chrome installed.

Tools

ToolPurpose
browser_navigateLoad a URL, return final URL + title
browser_evaluateRun JS in the page, return result
browser_screenshotPNG of current page
browser_clickClick via CSS selector
browser_click_atClick at pixel coordinates (pierces iframes / overlays)
browser_fillSet value on input/textarea/select
browser_wait_forWait for a selector to appear
browser_get_urlCurrent URL
browser_get_textVisible text of page or element
browser_get_htmlouterHTML of page or element
browser_scrollScroll by (x, y) pixels
browser_tabsList open tabs
browser_new_tabOpen a new tab

Environment variables

VarDefault
BROWSER_MCP_CHROME_PATHAuto-detected per OS
BROWSER_MCP_CHROME_PROFILE_ROOTOS-standard Chrome profile dir
BROWSER_MCP_BROKER_SOCKET_PATH~/.browser-mcp/broker.sock
BROWSER_MCP_BROKER_LOCK_PATH~/.browser-mcp/broker.lock
BROWSER_MCP_BROKER_IDLE_TIMEOUT_MS600000 (10 min)

How it works

  1. First MCP client connection spawns a broker subprocess (detached).
  2. Broker copies your Chrome profile's cookies/local storage/login data to a temp dir.
  3. Broker launches Chrome with --user-data-dir=<temp> and --remote-debugging-port.
  4. Subsequent MCP clients connect to the same broker over a Unix socket → they share one Chrome.
  5. Broker exits after BROKER_IDLE_TIMEOUT_MS of no activity; temp profile is deleted.

Security

This server lets an LLM execute arbitrary JavaScript in a browser that is logged into your accounts. Only use with models and prompts you trust. Profile snapshotting limits damage (no persistent mutations to your real Chrome), but the agent can read cookies, session tokens, and any data visible to logged-in you for the duration of the session.

License

MIT

Reviews

No reviews yet

Be the first to review this server!