v0.9.15 · MIT · MCP Browser Extension · 148 downloads / week · 6 stars

The MCP browser extension for the Chrome you are already logged into.

Let Claude Code, Cursor or any MCP agent use your real Chrome, not a fresh browser that greets every site as a stranger. Your sessions, your 2FA already done. A browser MCP server plus an extension, 40 tools, deny-all until you say otherwise.

claude mcp add chrome-mcp -s user -- \
  npx -y @mehmoodqureshi/chrome-mcp \
  --allow-domain example.com --enable-mutations --persist-token
paired/recorded run, 9 Oct 2026history.jsonl
  1. batch { ops: [tab_new x3] }
  2. 3 background tabs openednews.ycombinator.com, github.com, modelcontextprotocol.io in 149 ms
  3. batch { ops: [read_as_markdown x3] }
  4. 3 pages as markdown10 KB, 31 KB and 3 KB, read in parallel in 179 ms
  5. snapshot { interactiveOnly: true }
  6. link "Hacker News" ref=e2link "new" ref=e3, in 7 ms
  7. screenshot { tab: github.com/Mehmoodqureshi/chrome-mcp }
  8. 1710 x 946 PNG in 867 mssigned in: the repo shows Settings and Unpin

Why an MCP browser extension, not a headless browser

Most browser MCP servers launch their own Chromium and hand your agent a signed-out window. MCP Browser Extension does the opposite. How Claude uses your signed-in Chrome.

Your sessions, not a stranger’s

Drives the Chrome you already have open. Logged-in dashboards, admin panels and CRMs work with no credentials in any config file and no 2FA to redo.

Deny-all by default

Empty domain allowlist, eval off, downloads off, mutations off. You name the domains and the capabilities; everything else is refused before it reaches the page.

Real multi-tab concurrency

One batch call fans out across tabs, in parallel or in series, with per-tab serialisation so nothing races. Wall-clock is the slowest tab, not the sum.

Snapshots the model can act on

An accessibility snapshot with stable refs, or a diff of what changed since the last one. Target elements by role and name without guessing CSS selectors.

See why a page broke

Console output, network requests and native dialogs are captured, so the agent learns what happened rather than only what the page looks like afterwards.

An audit trail you can read

Every call lands in history.jsonl with the URL, the policy verdict, duration, bytes returned and secrets scrubbed. Password values are always blanked.

A real run, not a demo reel

One task folder, ten review sites, thirty tabs at a time. Every page it reads lands in results/ with its URL, every action lands in the log, and nothing was typed by hand. Recorded on a normal Chrome window with the extension paired.

Read the guides
Real run, 14 September 2026. 7,298 reviews from 10 sources, 30 tabs at a time.

Thirty tabs, one call

Open the pages in the background, then read them all at once. Each sub-op goes through the same policy gate, rate limit and error envelope as a direct call. Parallel ops must name their tab, so nothing is ever mis-routed.

Read the batch guide
Recorded 11 September 2026: one batch call opens four tabs in 45 to 72 ms, then reads, types and clicks by name. Every action lands in the task's history.jsonl.
two batch calls
{ "name": "batch", "arguments": { "ops": [
  { "tool": "tab_new", "args": { "url": "https://a.example/p" } },
  { "tool": "tab_new", "args": { "url": "https://b.example/p" } },
  { "tool": "tab_new", "args": { "url": "https://c.example/p" } }
]}}

{ "name": "batch", "arguments": { "ops": [
  { "tool": "read_as_markdown", "args": { "tabId": "<a>" } },
  { "tool": "read_as_markdown", "args": { "tabId": "<b>" } },
  { "tool": "read_as_markdown", "args": { "tabId": "<c>" } }
]}}

Set up the Chrome MCP server in three steps

  1. 01

    Register the server

    One command in Claude Code, or a five-line JSON block in any other MCP host. npx fetches the package; nothing else to install.

  2. 02

    Add the extension

    Load the plain folder the server drops in your home directory via chrome://extensions, or install it from the Chrome Web Store.

  3. 03

    Pair it once

    The bundled folder pairs itself: the server writes a 0600 pairing file into it and the badge turns green. A Web Store install is paired once from its Options page.

How a call travels from your agent to your Chrome
  1. MCP host
  2. npx @mehmoodqureshi/chrome-mcp
  3. MV3 extension
  4. your Chrome, your sessions

Nothing is allowed until you allow it

The allowlist decides which pages may be read. Password values are always blanked. --redact scrubs JWTs, cloud keys and bearer tokens before the output cap, so a truncated read cannot leak what a full one would hide. The pairing token is 0600 on disk and the server fails closed if it is not.

Read the security model
  • Empty domain allowlist until you add one
  • Password values always blanked
  • --redact scrubs JWTs, cloud keys and bearer tokens
  • Pairing token is 0600 and the server fails closed

Questions people ask

What is an MCP browser extension?
An MCP server plus a Chrome extension. Your agent talks to the server over MCP, and the extension carries out each call inside the Chrome you already have open, so the agent sees the sites you are signed into.
Which AI tools does it work with?
Claude Code, Claude Desktop, Cursor, Windsurf and any other MCP host that can start a server with npx.
Is it safe to give an agent my logged-in browser?
It starts deny-all: an empty domain allowlist, with eval, downloads and mutations off until you turn them on. Password values are always blanked and every call is written to an audit log.
Is a browser MCP safe?
It depends on the defaults. This one starts deny-all: no domains, no eval, no downloads and no clicking or typing until you allow them, and reads are gated by the same domain allowlist as clicks. Password field values are never returned, --redact scrubs secret-shaped strings before the output cap, and every call is recorded in history.jsonl with the URL and the allow or deny verdict.
Do I need a separate browser or a headless Chromium?
No. It drives the Chrome you already use, with your cookies and your 2FA already done. If you want a clean, signed-out browser for testing, a headless MCP server such as Playwright MCP fits better.
Is it free?
Yes. It is open source under the MIT licence, on npm as @mehmoodqureshi/chrome-mcp, with the extension on the Chrome Web Store.