browser-use-mcp-server

An MCP server that lets an agent drive a real browser: open pages, click and fill forms through Playwright

MCP server

Medium risk

We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.

Why this level

  • Drives a real browser and makes network requests
  • Acts on sites on your behalf under model control
All reasons and checks
Needs a VPN

kontext-security/browser-use-mcp-server

Install

Manual install

uv tool install mcp-proxy
uv pip install playwright
uv run playwright install --with-deps --no-shell chromium
uv build
uv tool install dist/browser_use_mcp_server-*.whl

Build and install the server via uv, then run browser-use-mcp-server.

This is third-party code. Review the repository files before installing.

What it does

The server wraps a browser agent built on the browser-use library and Playwright and exposes it over MCP. Through it an assistant opens sites, follows links, clicks and fills fields on your behalf. It runs in two transports, SSE and stdio, with ready configs for Cursor, Windsurf and Claude. A language model drives the browser actions, so an OpenAI key is required.

Who it is for. For developers and testers who want an agent to operate a browser on its own.

Good fit when

  • You want the agent to navigate a site and fill forms
  • You need a browser inside Cursor, Windsurf or Claude as an MCP tool
  • You want an isolated browser environment via Docker

Not a fit when

  • You have no OpenAI key and cannot use an external model
  • Browser actions must stay strictly manual, without an autonomous agent

Example request

Open the site, find its pricing page and list the plans

Limitations

It needs an OpenAI key, and that API is not reachable from Russia without a VPN. It requires Playwright and a Chromium browser, and Docker helps isolate it. The agent acts in the browser on its own, so run it only on your own accounts and resources and watch what it does.

How to disable. Remove the server entry from your MCP client config and uninstall the tool with uv tool uninstall browser-use-mcp-server.

MCP

Transport
sse, stdio
Authentication
API key
Environment variables
Environment variables
OPENAI_API_KEY
required, secret
OpenAI key: the model drives the browser actions.

Security check

  • Drives a real browser and makes network requests
  • Acts on sites on your behalf under model control

README in short

The README covers installation via uv, Playwright with Chromium, and running in SSE or stdio mode. It lists client configs for Cursor, Windsurf and Claude with the paths to their settings files. It offers a Docker run with mapped ports and an OPENAI_API_KEY variable. The project is Python, MIT licensed.

FAQ

Which transports are supported?

SSE and stdio. For SSE the client connects by URL; for stdio the server runs as a command with arguments.

Why an OpenAI key?

A language model drives the browser actions, deciding where to click and what to type, so an external key is needed.

Editors’ pick

CLI, skill and Python library for browser control: the agent clicks, fills forms and reads pages over CDP

CLIHigh risk116.6KRepository stars
Editors’ pick

A skill that gathers the last 30 days of discussion on a topic from Reddit, X, YouTube, HN, Polymarket and GitHub into one brief

SkillHigh risk63.1KRepository stars
Official

The Chrome DevTools team's official MCP server: the agent drives a live Chrome, reads network and console, and records performance traces

MCP serverMedium risk52.7KRepository stars
Official

A fast Rust CLI for agent browser automation: accessibility snapshots with element refs, an MCP server and skills

CLIHigh risk43.3KRepository stars
Foxx AIbrowser-use-mcp-server

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.