The MCP browser extension for the Chrome you are already logged into.
Let Claude Code, Cursor or any MCP agent use your real Chrome, not a fresh browser that greets every site as a stranger. Your sessions, your 2FA already done. A browser MCP server plus an extension, 40 tools, deny-all until you say otherwise.
claude mcp add chrome-mcp -s user -- \
npx -y @mehmoodqureshi/chrome-mcp \
--allow-domain example.com --enable-mutations --persist-token- batch { ops: [tab_new x3] }
- 3 background tabs openednews.ycombinator.com, github.com, modelcontextprotocol.io in 149 ms
- batch { ops: [read_as_markdown x3] }
- 3 pages as markdown10 KB, 31 KB and 3 KB, read in parallel in 179 ms
- snapshot { interactiveOnly: true }
- link "Hacker News" ref=e2link "new" ref=e3, in 7 ms
- screenshot { tab: github.com/Mehmoodqureshi/chrome-mcp }
- 1710 x 946 PNG in 867 mssigned in: the repo shows Settings and Unpin
Why an MCP browser extension, not a headless browser
Most browser MCP servers launch their own Chromium and hand your agent a signed-out window. MCP Browser Extension does the opposite. How Claude uses your signed-in Chrome.
Your sessions, not a stranger’s
Drives the Chrome you already have open. Logged-in dashboards, admin panels and CRMs work with no credentials in any config file and no 2FA to redo.
Deny-all by default
Empty domain allowlist, eval off, downloads off, mutations off. You name the domains and the capabilities; everything else is refused before it reaches the page.
Real multi-tab concurrency
One batch call fans out across tabs, in parallel or in series, with per-tab serialisation so nothing races. Wall-clock is the slowest tab, not the sum.
Snapshots the model can act on
An accessibility snapshot with stable refs, or a diff of what changed since the last one. Target elements by role and name without guessing CSS selectors.
See why a page broke
Console output, network requests and native dialogs are captured, so the agent learns what happened rather than only what the page looks like afterwards.
An audit trail you can read
Every call lands in history.jsonl with the URL, the policy verdict, duration, bytes returned and secrets scrubbed. Password values are always blanked.
A real run, not a demo reel
One task folder, ten review sites, thirty tabs at a time. Every page it reads lands in results/ with its URL, every action lands in the log, and nothing was typed by hand. Recorded on a normal Chrome window with the extension paired.
Read the guidesThirty tabs, one call
Open the pages in the background, then read them all at once. Each sub-op goes through the same policy gate, rate limit and error envelope as a direct call. Parallel ops must name their tab, so nothing is ever mis-routed.
Read the batch guide{ "name": "batch", "arguments": { "ops": [
{ "tool": "tab_new", "args": { "url": "https://a.example/p" } },
{ "tool": "tab_new", "args": { "url": "https://b.example/p" } },
{ "tool": "tab_new", "args": { "url": "https://c.example/p" } }
]}}
{ "name": "batch", "arguments": { "ops": [
{ "tool": "read_as_markdown", "args": { "tabId": "<a>" } },
{ "tool": "read_as_markdown", "args": { "tabId": "<b>" } },
{ "tool": "read_as_markdown", "args": { "tabId": "<c>" } }
]}}Set up the Chrome MCP server in three steps
- 01
Register the server
One command in Claude Code, or a five-line JSON block in any other MCP host. npx fetches the package; nothing else to install.
- 02
Add the extension
Load the plain folder the server drops in your home directory via chrome://extensions, or install it from the Chrome Web Store.
- 03
Pair it once
The bundled folder pairs itself: the server writes a 0600 pairing file into it and the badge turns green. A Web Store install is paired once from its Options page.
MCP host (Claude Code / Desktop / Cursor)
| JSON-RPC over stdio
v
npx @mehmoodqureshi/chrome-mcp policy gate, rate limit, audit log
| localhost WebSocket, per-boot 256-bit token
v
MV3 extension chrome.scripting / chrome.tabs
|
v
your Chrome, your sessions- MCP host
- npx @mehmoodqureshi/chrome-mcp
- MV3 extension
- your Chrome, your sessions
40 browser MCP tools, generated from the source
The reference is built from the same catalog the server advertises, so it cannot drift from what your agent sees.
Full referenceTabs
Open, list, focus and close tabs in the real Chrome window.
tabs_list tab_new tab_select tab_close
Navigation
Move a tab between pages and wait for the page to settle.
navigate back forward reload wait_for
Interaction
Click, type, select and scroll. Target by CSS selector, snapshot ref, or role and accessible name.
click type select_option press hover scroll fill_form upload_file
Reading
Get the page back as text, markdown, HTML, an accessibility snapshot, a screenshot or a PDF.
snapshot get_text read_as_markdown get_html extract_links screenshot print_pdf frames_list
State and scripting
Cookies, storage, downloads and JavaScript evaluation.
get_cookies storage download_file eval
Observers
Console output, network requests and native dialogs. Requires --enable-observers.
console_logs network_log dialogs
Session and artifacts
Backend status, sign-in wall detection, and where downloads, results and screenshots are stored.
chrome_status auth_check profile_use task_new tasks_list task_status
Batch
Run many tool calls in one request, in parallel or in series.
batch
Other
Tools not yet categorised.
profile_rename
Nothing is allowed until you allow it
The allowlist decides which pages may be read. Password values are always blanked. --redact scrubs JWTs, cloud keys and bearer tokens before the output cap, so a truncated read cannot leak what a full one would hide. The pairing token is 0600 on disk and the server fails closed if it is not.
- Empty domain allowlist until you add one
- Password values always blanked
- --redact scrubs JWTs, cloud keys and bearer tokens
- Pairing token is 0600 and the server fails closed
From the blog
Setup guides for each agent, and how the browser MCP servers compare.
All postsMCP browser extension: what it is and when you need one
What an MCP browser extension is, how it differs from a browser MCP server that launches its own Chromium, how the pieces connect, and when headless is better.
Claude Code browser access: connect it to your logged-in Chrome
Set up Claude Code browser access through an MCP server and a Chrome extension, so it works in the Chrome you are signed into. Exact commands and fixes.
Cursor browser MCP: give Cursor your real, signed-in Chrome
Set up a Cursor browser MCP server that drives your real Chrome: the exact mcp.json, the extension, pairing, use cases like local dev and dashboards, limits.
Questions people ask
- What is an MCP browser extension?
- An MCP server plus a Chrome extension. Your agent talks to the server over MCP, and the extension carries out each call inside the Chrome you already have open, so the agent sees the sites you are signed into.
- Which AI tools does it work with?
- Claude Code, Claude Desktop, Cursor, Windsurf and any other MCP host that can start a server with npx.
- Is it safe to give an agent my logged-in browser?
- It starts deny-all: an empty domain allowlist, with eval, downloads and mutations off until you turn them on. Password values are always blanked and every call is written to an audit log.
- Is a browser MCP safe?
- It depends on the defaults. This one starts deny-all: no domains, no eval, no downloads and no clicking or typing until you allow them, and reads are gated by the same domain allowlist as clicks. Password field values are never returned, --redact scrubs secret-shaped strings before the output cap, and every call is recorded in history.jsonl with the URL and the allow or deny verdict.
- Do I need a separate browser or a headless Chromium?
- No. It drives the Chrome you already use, with your cookies and your 2FA already done. If you want a clean, signed-out browser for testing, a headless MCP server such as Playwright MCP fits better.
- Is it free?
- Yes. It is open source under the MIT licence, on npm as @mehmoodqureshi/chrome-mcp, with the extension on the Chrome Web Store.