unbrowser by Unchained
Leichter MCP-Browser für LLM-Agenten: kein Chrome, tokenarme BlockMaps, zustandsbehaftete Sitzungen, JavaScript-Ausführung, Formulare, Cookies und Eskalationshinweise.
Dokumentation
unbrowser
The cheap browser pass for agents. One native binary. No Chrome.
Official MCP Registry identity: mcp-name: io.github.protostatis/unbrowser
unbrowser is a stateful, non-visual web runtime for agents. It sits between curl/WebFetch and a real browser: it retains cookies and DOM state, returns queryable element refs, handles links and HTML forms, detects challenge and SPA signals, and can run bounded QuickJS page scripts when static HTML is not enough.
Default
navigateis a fast static/SSR pass. Setexec_scripts: trueonly when you need bounded QuickJS execution. Heavy SPAs, pixels, V8 fidelity, extensions, and interactive anti-bot challenges belong in a real Chrome tier.
Try the live public-web demo before installing. It accepts only the fixed public source sets shown on the page; do not send private data, cookies, or authenticated tasks through it. A shared Streamable HTTP MCP endpoint is available at https://unchainedsky.com/unbrowser-mcp for public smoke tests; production sessions should use a local install.
Pick the right tier
| Need | curl / WebFetch | unbrowser | Real Chrome |
|---|---|---|---|
| Static / SSR HTML | raw response | structured BlockMap + DOM queries | full browser |
| Cookies, links, HTML forms | DIY | built in | built in |
| Client-side page scripts | ❌ | bounded QuickJS, opt-in | V8 |
| Pixels, Canvas, WebGL, Workers, extensions | ❌ | ❌ | ✅ |
| Agent-oriented output | DIY parsing | element refs, page signals, structured extraction | DIY CDP / DOM parsing |
| Hard bot challenge | ❌ | detect + cookie replay | browser / human / solver |
Use unbrowser when HTTP alone is too dumb and a full browser is too expensive. When the page needs Chrome, the output tells the agent to escalate rather than pretending compatibility it does not have.
Quick start
Docker — Linux amd64/arm64, ~13 MiB pull
docker pull ghcr.io/protostatis/unbrowser:latest
# One-shot navigation
docker run --rm ghcr.io/protostatis/unbrowser:latest \
navigate https://example.com --json
# Default mode: MCP over stdio
docker run --rm -i ghcr.io/protostatis/unbrowser:latest
The image is distroless and runs as non-root: no shell, package manager, or persistent state. Pin :vX.Y.Z or an image digest in production.
Python
pipx install pyunbrowser # recommended on macOS / modern Linux
# or, inside a Python 3.10+ virtual environment:
pip install pyunbrowser
from unbrowser import Client
with Client() as ub:
ub.navigate("https://news.ycombinator.com")
for link in ub.query(".titleline > a")[:3]:
print(link["text"], link["attrs"]["href"])
On macOS, /usr/bin/python3 is 3.9 and cannot install the wheel; use pipx or a Homebrew Python. The PyPI distribution is pyunbrowser, while the import and executable remain unbrowser.
MCP
{
"mcpServers": {
"unbrowser": {
"command": "unbrowser",
"args": ["--mcp"]
}
}
}
Docker MCP configuration
{
"mcpServers": {
"unbrowser": {
"command": "docker",
"args": [
"run", "--rm", "-i",
"ghcr.io/protostatis/unbrowser:latest"
]
}
}
}
See installation and interface reference for Cargo, release archives, source builds, persistent shell sessions, raw JSON-RPC, and all MCP options.
What an agent gets
navigatereturns a BlockMap: page title, landmarks, headings, interactives, density signals, and an ASCII outline. Its size is page-dependent; it is structured for planning rather than a fixed-token promise.- Stable element refs (
e:142): query an element once, thenclick,type, orsubmitit without re-parsing HTML. - Stateful cookies and forms: cookie jar, GET and URL-encoded POST form submission, links, and redirects persist within a session.
- Page and challenge signals:
density.likely_js_filled,thin_shell, andchallenge.providertell an agent whether to run scripts, inspect embedded data, replay a clearance cookie, or escalate. - Structured helpers: route discovery, card extraction, table normalization,
text_main, and selector debugging cover common extraction workflows.
Script mode and escalation
{"id":1,"method":"navigate","params":{"url":"https://example.com","exec_scripts":true}}
With exec_scripts: true, inline and external scripts run in QuickJS under a bounded watchdog. This can materialize light hydration and fetch-visible data; it is not V8 or a rendering engine. Heavy React/Vue/Ember apps may still leave an empty shell.
Escalate to unchainedsky-cli or Unchained when a task needs real pixels, Canvas/WebGL, Workers, browser extensions, V8 compatibility, or active challenge solving. For many bot walls, solve once in Chrome and replay the resulting clearance cookie with cookies_set until it expires.
Documentation
| Need | Read |
|---|---|
| Install paths, session CLI, one-shot CLI, raw RPC, MCP, shims, full RPC table | Usage reference |
| Script compatibility, SPA signals, challenge handling, cookie solver, escalation | Compatibility and escalation |
| Distribution and supported directory listings | Distribution notes |
| Build the native binary | Build instructions |
License
Apache-2.0 — see LICENSE.