MCP Browser Extension (chrome-mcp)

Lets Claude, Cursor or any MCP client work in the Chrome you are already logged into. Deny-all domain allowlist by default.

Documentation

The MCP browser extension for the Chrome you are already logged into.

Let Claude Code, Cursor or any MCP agent use your real Chrome, not a fresh browser that greets every site as a stranger. Your sessions, your 2FA already done. A browser MCP server plus an extension, 40 tools, deny-all until you say otherwise.

claude mcp add chrome-mcp -s user -- \
  npx -y @mehmoodqureshi/chrome-mcp \
  --allow-domain example.com --enable-mutations --persist-token

paired/recorded run, 9 Oct 2026history.jsonl

  1. batch { ops: [tab_new x3] }
  2. 3 background tabs opened news.ycombinator.com, github.com, modelcontextprotocol.io in 149 ms
  3. batch { ops: [read_as_markdown x3] }
  4. 3 pages as markdown 10 KB, 31 KB and 3 KB, read in parallel in 179 ms
  5. snapshot { interactiveOnly: true }
  6. link "Hacker News" ref=e2 link "new" ref=e3, in 7 ms
  7. screenshot { tab: github.com/Mehmoodqureshi/chrome-mcp }
  8. 1710 x 946 PNG in 867 ms signed in: the repo shows Settings and Unpin

Why an MCP browser extension, not a headless browser

Most browser MCP servers launch their own Chromium and hand your agent a signed-out window. MCP Browser Extension does the opposite. How Claude uses your signed-in Chrome.

Your sessions, not a stranger’s

Drives the Chrome you already have open. Logged-in dashboards, admin panels and CRMs work with no credentials in any config file and no 2FA to redo.

Deny-all by default

Empty domain allowlist, eval off, downloads off, mutations off. You name the domains and the capabilities; everything else is refused before it reaches the page.

Real multi-tab concurrency

One batch call fans out across tabs, in parallel or in series, with per-tab serialisation so nothing races. Wall-clock is the slowest tab, not the sum.

Snapshots the model can act on

An accessibility snapshot with stable refs, or a diff of what changed since the last one. Target elements by role and name without guessing CSS selectors.

See why a page broke

Console output, network requests and native dialogs are captured, so the agent learns what happened rather than only what the page looks like afterwards.

An audit trail you can read

Every call lands in history.jsonl with the URL, the policy verdict, duration, bytes returned and secrets scrubbed. Password values are always blanked.

A real run, not a demo reel

One task folder, ten review sites, thirty tabs at a time. Every page it reads lands in results/ with its URL, every action lands in the log, and nothing was typed by hand. Recorded on a normal Chrome window with the extension paired.

Read the guides

Thirty tabs, one call

Open the pages in the background, then read them all at once. Each sub-op goes through the same policy gate, rate limit and error envelope as a direct call. Parallel ops must name their tab, so nothing is ever mis-routed.

Read the batch guide

{ "name": "batch", "arguments": { "ops": [
  { "tool": "tab_new", "args": { "url": "https://a.example/p" } },
  { "tool": "tab_new", "args": { "url": "https://b.example/p" } },
  { "tool": "tab_new", "args": { "url": "https://c.example/p" } }
]}}

{ "name": "batch", "arguments": { "ops": [
  { "tool": "read_as_markdown", "args": { "tabId": "<a>" } },
  { "tool": "read_as_markdown", "args": { "tabId": "<b>" } },
  { "tool": "read_as_markdown", "args": { "tabId": "<c>" } }
]}}

Set up the Chrome MCP server in three steps

  1. 01

    Register the server

    One command in Claude Code, or a five-line JSON block in any other MCP host. npx fetches the package; nothing else to install.
  2. 02

    Add the extension

    Load the plain folder the server drops in your home directory via chrome://extensions, or install it from the Chrome Web Store.
  3. 03

    Pair it once

    The bundled folder pairs itself: the server writes a 0600 pairing file into it and the badge turns green. A Web Store install is paired once from its Options page.
MCP host (Claude Code / Desktop / Cursor)
    |  JSON-RPC over stdio
    v
npx @mehmoodqureshi/chrome-mcp        policy gate, rate limit, audit log
    |  localhost WebSocket, per-boot 256-bit token
    v
MV3 extension                            chrome.scripting / chrome.tabs
    |
    v
your Chrome, your sessions

40 browser MCP tools, generated from the source

The reference is built from the same catalog the server advertises, so it cannot drift from what your agent sees.

Full reference

  • Tabs

    Open, list, focus and close tabs in the real Chrome window. tabs_list tab_new tab_select tab_close
  • Navigation

    Move a tab between pages and wait for the page to settle. navigate back forward reload wait_for
  • Interaction

    Click, type, select and scroll. Target by CSS selector, snapshot ref, or role and accessible name. click type select_option press hover scroll fill_form upload_file
  • Reading

    Get the page back as text, markdown, HTML, an accessibility snapshot, a screenshot or a PDF. snapshot get_text read_as_markdown get_html extract_links screenshot print_pdf frames_list
  • State and scripting

    Cookies, storage, downloads and JavaScript evaluation. get_cookies storage download_file eval
  • Observers

    Console output, network requests and native dialogs. Requires --enable-observers. console_logs network_log dialogs
  • Session and artifacts

    Backend status, sign-in wall detection, and where downloads, results and screenshots are stored. chrome_status auth_check profile_use task_new tasks_list task_status
  • Batch

    Run many tool calls in one request, in parallel or in series. batch
  • Other

    Tools not yet categorised. profile_rename

Nothing is allowed until you allow it

The allowlist decides which pages may be read. Password values are always blanked. --redact scrubs JWTs, cloud keys and bearer tokens before the output cap, so a truncated read cannot leak what a full one would hide. The pairing token is 0600 on disk and the server fails closed if it is not.

  • Empty domain allowlist until you add one
  • Password values always blanked
  • --redact scrubs JWTs, cloud keys and bearer tokens
  • Pairing token is 0600 and the server fails closed

From the blog

Setup guides for each agent, and how the browser MCP servers compare.

All posts

Questions people ask

What is an MCP browser extension?

An MCP server plus a Chrome extension. Your agent talks to the server over MCP, and the extension carries out each call inside the Chrome you already have open, so the agent sees the sites you are signed into.

Which AI tools does it work with?

Claude Code, Claude Desktop, Cursor, Windsurf and any other MCP host that can start a server with npx.

Is it safe to give an agent my logged-in browser?

It starts deny-all: an empty domain allowlist, with eval, downloads and mutations off until you turn them on. Password values are always blanked and every call is written to an audit log.

Is a browser MCP safe?

It depends on the defaults. This one starts deny-all: no domains, no eval, no downloads and no clicking or typing until you allow them, and reads are gated by the same domain allowlist as clicks. Password field values are never returned, --redact scrubs secret-shaped strings before the output cap, and every call is recorded in history.jsonl with the URL and the allow or deny verdict.

Do I need a separate browser or a headless Chromium?

No. It drives the Chrome you already use, with your cookies and your 2FA already done. If you want a clean, signed-out browser for testing, a headless MCP server such as Playwright MCP fits better.

Is it free?

Yes. It is open source under the MIT licence, on npm as @mehmoodqureshi/chrome-mcp, with the extension on the Chrome Web Store.