What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
There are two supported Docker paths for Browser Use MCP: run it as an HTTP service behind your own reverse proxy, or run it over stdio through Docker MCP Gateway for a local MCP client. The HTTP route suits a shared service; Gateway suits a desktop client that needs a persistent browser session. Both require durable encrypted state, injected secrets, and a correctly configured Steel browser backend.
Choose the Docker transport first
| Route | Transport and client fit | Exposure model | State requirements |
|---|---|---|---|
| HTTP container | Network HTTP endpoint for remote or service-based MCP clients | Keep the container on a private network and expose only a TLS-terminating reverse proxy | Named volume mounted at /data; environment file or secret manager |
| Docker MCP Gateway | Gateway launches the image over stdio for an MCP client | Normally local to the client; Gateway profile controls which servers are available | longLived: true, named volume for encrypted profiles, and the same storage master key whenever that volume is reused |
The project describes itself as “Persistent, secure browser automation for AI agents over MCP.” Follow the current official repository README for the complete variable list because repository configuration can change.
Prerequisites
- Python 3.12 through 3.14 and
uvif you will build or run the source locally. - A Steel deployment. Steel Cloud use requires its API key.
- An OpenAI-compatible Chat Completions endpoint for semantic actions. Deterministic controls do not call a model.
- Docker Engine or Docker Desktop. Docker’s Toolkit UI guidance applies to Docker Desktop 4.62 and later and is currently marked beta.
- A Base64-encoded 256-bit storage master key. Keep it stable for any data volume you intend to reuse.
Get the image or build it
Pull the published image
Each successful main build publishes an Alpine-based, non-root image to GitHub Container Registry. The repository documents both a mutable latest tag and immutable sha-<commit> tags.
docker pull ghcr.io/s-block/browser-use-mcp:latest
Use latest for convenience. For reproducible deployments, replace it with the exact commit tag you have approved; the repository does not specify a particular commit digest here.
#1 Best Overall
Build from source
git clone https://github.com/s-block/browser-use-mcp.git
cd browser-use-mcp
uv sync --frozen
docker build -t browser-use-mcp:local .
Building locally is required for the documented Docker MCP Gateway workflow.
Run an HTTP container securely
The project’s example intentionally does not publish an application port on the host. A reverse proxy on the same private Docker network should be the only component that publishes a host port and should terminate HTTPS.
1. Create the persistent volume and private network
docker volume create browser-use-mcp-data
docker network create mcp-backend
2. Prepare the environment file
Create /etc/browser-use-mcp/runtime.env with root-only permissions, or inject equivalent values through your secret manager. Do not commit it or paste secrets into shell history. The values you need depend on your deployment, but the README’s example covers:
- non-loopback host and port settings;
- bearer authentication mode and the client-credential digest;
- the Base64-encoded 256-bit storage master key;
- allowed hosts and origins;
- the TLS-termination assertion;
- public-network egress enforcement and Steel proxy/network identity;
- Steel API credentials; and
- an OpenAI-compatible endpoint, key, and model for semantic actions.
Use the repository’s configuration table for exact variable names and required formatting.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall3. Start the hardened container
docker run --rm --read-only --cap-drop=ALL
--security-opt=no-new-privileges
--tmpfs /tmp:rw,noexec,nosuid,size=16m
--mount type=volume,source=browser-use-mcp-data,target=/data
--network mcp-backend
--name browser-use-mcp
--env-file /etc/browser-use-mcp/runtime.env
ghcr.io/s-block/browser-use-mcp:latest
The image runs as UID 10001. The only required persistent writable path is /data; the read-only root filesystem, dropped capabilities, non-root user, and restricted temporary filesystem reduce the container’s writable and privilege surface.
4. Put a reverse proxy in front
Bind the MCP service to a private network address and let your HTTPS reverse proxy publish the public port. For a non-loopback bind, set BROWSER_USE_MCP_TLS_TERMINATED=true only when that proxy really terminates TLS. Bearer authentication authenticates requests but does not encrypt transport. Use a trusted proxy, private container/host networking, and HTTPS for confidentiality.
5. Apply host and origin rules
Configure allowed-host patterns for the hostname clients actually use. Browser-based clients that send an Origin header may also need a matching allowed-origin value. A mismatch commonly appears as a rejected connection even though the container is healthy.
Connect through Docker MCP Gateway over stdio
Gateway is a different deployment model: it starts the container as a stdio MCP server for a selected Toolkit profile. Build the image first:
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
docker build -t browser-use-mcp:local .
Configure a long-lived server entry
In the Gateway server configuration, select stdio and reference browser-use-mcp:local. Keep the server alive across related browser tool calls and mount a named volume for encrypted profile state. The repository requires longLived: true because one call starts a browser session and later calls use that same session. Store declared secrets in Docker MCP Toolkit/Gateway secret storage rather than in a checked-in configuration file.
A conceptual entry has these properties (use the exact schema shown by your Docker Desktop version):
{
"image": "browser-use-mcp:local",
"transport": "stdio",
"longLived": true,
"volumes": ["browser-use-mcp-data:/data"]
}
Retain the same storage master key whenever you reuse browser-use-mcp-data. If two trust boundaries must not share browser profiles, create separate Gateway profiles, server entries, data volumes, and keys.
Launch the Gateway profile for a client
Docker’s Toolkit documentation shows the client-facing pattern:
docker mcp gateway run --profile my_profile
Configure your MCP client to launch that command as a stdio server. Profiles group server configurations, so select the profile containing your Browser Use entry. The exact Desktop menus differ by release; Docker’s current Toolkit pages document the interface for Desktop 4.62 and later.
Verify the connection
- Open your MCP client’s server list or status view and confirm that the Gateway profile is connected.
- Invoke a low-risk Browser Use tool and confirm the server remains available for a second, related call; this checks the long-lived requirement.
- If your client or Gateway enables network blocking, allow the configured Steel deployment, its browser WebSocket endpoint, and the model endpoint.
No container execution or client test is implied by these instructions; verification must be done in your environment.
Configuration and network boundaries
Steel and semantic actions
Steel is the browser backend named by the project. Supply its deployment identity and API key as secrets. Semantic actions additionally need an OpenAI-compatible Chat Completions endpoint; deterministic actions can run without a model. Request-scoped model and Steel options are documented in the project’s configuration table.
Gateway allowHosts is not browser egress control
The project warns that Gateway’s allowHosts policy governs traffic originating from the MCP container, not requests made by remote Chromium. If public-only browsing is required, enforce that destination boundary in the Steel proxy. Docker network allowlisting alone is not sufficient protection for remote-browser destinations.
Recommended Free Tools
Best Value
- Docker, Docker Swarm, Docker Compose, Programmer, Developer, Coding, Programming, Software Engineer, Code, DevOps, Deploy, Deployment, Kubernetes, Salt, Puppet, Chef, Terraform, Container, AWS, Azure, Cloud, Geek, Funny, Computer, Software, Tech, IT
- Integration, Scrum, Compile, Compilation, Science, Bug, Debug, Python, Linux, Java, Javascript, Scala, Dotnet, Kotlin
- Lightweight, Classic fit, Double-needle sleeve and bottom hem
Persistent state and key rotation
Encrypted profiles in /data cannot be decrypted after you replace their storage master key. Back up the volume and key together, and plan a deliberate migration if rotation is required. A new key with an old volume is an expected decryption failure, not evidence that Docker lost the data.
Common failures and fixes
| Symptom | Likely cause | Fix |
|---|---|---|
| Container exits immediately | Missing or malformed required environment value | Inspect container logs, compare variable names and formats with the README, and verify the master key is Base64-encoded 256-bit data. |
Permission denied under /data |
Volume ownership or an incorrectly mounted path | Use the named-volume mount shown above and ensure the runtime UID 10001 can write it; do not make the root filesystem writable as a shortcut. |
| Client cannot connect to HTTP service | Host/origin mismatch, missing proxy TLS assertion, or proxy not on mcp-backend |
Match allowed host/origin patterns, confirm proxy-to-container networking, and set the TLS-termination flag only behind real HTTPS termination. |
| Gateway starts but later browser calls lose the session | Server entry is not long-lived or the profile volume is ephemeral | Set longLived: true and mount a named volume at /data. |
| Gateway network blocking rejects a valid operation | Steel, its WebSocket endpoint, or the model endpoint is not allowed | Add the required destinations to the Gateway policy; enforce remote Chromium destination limits in Steel. |
| Existing profiles cannot be opened | The storage master key changed | Restore the original key for that volume or perform a documented migration; do not generate a replacement key and expect old ciphertext to open. |
Or skip the browser setup
If your actual requirement is simply a clean screenshot or PDF endpoint rather than an MCP browser session, ScreenshotNeo provides a one-request API and an MCP server for AI clients. It accepts cookie and consent banners like a visitor, removes more than 60 known consent platforms plus newsletter popups and chat widgets before capture, and bills only clean shots: bot checks, CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed. Its MCP tools are take_screenshot, get_page_info, and capture_pdf.
Start with the documented API examples at ScreenshotNeo’s documentation:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
Every response identifies the page verdict and billing status with X-Page-Verdict and X-Billed headers. You can also request full-page lazy-image loading, CSS-selector element shots, dark mode, device presets, retina scale, PDF paper and page options, custom CSS or JavaScript, clicks, waits, blocked requests, headers, cookies, user agents, authorization, timezone, geolocation, transparent backgrounds, resizing, chosen cache TTLs, signed image links, asynchronous webhooks, bulk capture of up to 100 URLs per call, and usage data. All features are on every plan: 1,000 shots/month free with no card; paid plans start at $5 for 3,000 shots. Sign up free for ScreenshotNeo.
Cost, reliability, and maintenance decisions
- Pin production images: use an approved
sha-<commit>tag instead of silently receiving changes fromlatest. - Back up state: treat the
/datavolume and its master key as one recovery set. - Separate tenants: use distinct Gateway profiles, volumes, and keys where browser profiles must not cross trust boundaries.
- Protect the network: put HTTP behind HTTPS termination and keep the application container off a public host port.
- Plan model costs: semantic actions call your configured OpenAI-compatible endpoint; deterministic controls do not.
- Observe verdicts and logs: for Gateway, use the MCP client’s status and Docker logs; for HTTP, inspect reverse-proxy and container logs together.
Frequently Asked Questions
Can I use the published image with Docker MCP Gateway?
The project’s Gateway instructions specifically have you build locally with docker build -t browser-use-mcp:local .; follow that documented path unless the current README says otherwise.
Does Browser Use MCP require an OpenAI model for every action?
No. The project says semantic actions need an OpenAI-compatible Chat Completions endpoint, while deterministic controls do not call a model.
Where should I store Browser Use secrets?
Use a protected environment file for the HTTP route or Docker MCP Toolkit/Gateway secret storage for stdio. Never commit credentials to the image or configuration repository.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




