Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Agent Browser MCP lets an MCP-capable client control a local Chrome or Chromium browser and work through GitHub’s web interface. The documented setup is a local stdio server: install the Agent Browser CLI, then configure your client to launch agent-browser with the argument mcp. This is separate from GitHub’s repository-level MCP settings for Copilot cloud agent and code review. The two features use different configuration paths, run in different environments, and should not be treated as interchangeable.

What you are connecting

Agent Browser is a browser-automation CLI from Vercel Labs for AI agents. It drives Chrome or Chromium through the Chrome DevTools Protocol (CDP) and exposes an accessibility-tree workflow. Instead of asking an agent to guess CSS selectors, the client can request a compact snapshot containing references such as @e1, inspect the visible page, and use a current reference for the next interaction.

In MCP mode, Agent Browser starts a stdio server. Your MCP client starts the process and communicates with it over standard input and output. The project’s documented launch is the command agent-browser with mcp as its argument. The exact JSON file and property names depend on the MCP client you use.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What this is useful for on GitHub

  • Opening a repository, issue, pull request, release, or documentation page.
  • Reading visible repository information and locating links.
  • Following a low-impact navigation flow while an agent observes each page state.
  • Performing an approved action, such as editing or submitting content, when the signed-in account and permissions allow it.

A browser session is not the same as GitHub’s API or a repository integration. It sees the web page available to the authenticated browser, including UI state, prompts, and permission errors.

Prerequisites

  • An MCP-capable desktop client, such as an MCP-enabled coding or assistant application.
  • Node.js and the Agent Browser CLI installed according to the project’s current installation instructions.
  • Chrome or Chromium available on the machine where the MCP client launches the server.
  • A GitHub account with only the permissions needed for the task.
  • A trusted local computer. Browser profiles and state files can contain reusable session credentials.

Installation commands and supported flags can change as the project evolves, so use the current Agent Browser README for the installation step. The stable MCP concept is the client launch command: executable agent-browser, argument mcp.

Configure an MCP client to launch Agent Browser

  1. Install Agent Browser and confirm that the executable is on the PATH visible to your MCP client. If the client runs under a different user or sandbox, use the executable’s absolute path instead.
  2. Open your MCP client’s server configuration. The location is client-specific; look for a section named MCP servers, integrations, or tools.
  3. Add a server entry whose command is agent-browser and whose arguments array contains mcp.
  4. Save the configuration and restart or reload the client so it can spawn the stdio process.
  5. Approve the browser permission prompt, if the client displays one, and open a GitHub page through the exposed browser tool.

A generic configuration shape looks like this; adapt the surrounding property names to your client:

{
  "mcpServers": {
    "agent-browser": {
      "command": "agent-browser",
      "args": ["mcp"]
    }
  }
}

Do not paste this block into a client that uses a different schema without checking that client’s documentation. The important values are the command and the mcp argument, not the outer key names.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Optional profiles

The default core profile provides everyday browser functions. Agent Browser also documents optional profiles named network, state, debug, tabs, react, mobile, and all. Enable only what your task requires. Broader profiles expose more capability and make permission review harder.

The GitHub browser loop

Use a repeating observe–act–observe cycle. References are tied to the current page state; after navigation, a modal, a filter change, or an error, take a new snapshot before selecting another element.

  1. Open the page. Ask the client to navigate to a specific GitHub URL, for example a repository’s main page.
  2. Take a snapshot. Request the accessibility-tree snapshot and read the returned headings, links, buttons, and their references.
  3. Choose a low-impact target. Use the reference shown in the current snapshot, such as @e1, rather than relying on a reference remembered from an earlier state.
  4. Interact. Click the link or control, or enter text only after checking that the target and account are correct.
  5. Snapshot again. Confirm the resulting page, dialog, or validation message before continuing.

The CLI examples in the project documentation use commands equivalent to agent-browser open, agent-browser snapshot, and agent-browser click @eN. Through MCP, your client normally exposes those capabilities as tools rather than requiring you to type the CLI commands manually.

Safe example: read a repository page

  1. Open the repository URL.
  2. Snapshot the page.
  3. Identify the visible description, default branch, latest release link, or an issue link.
  4. Click one link from the fresh snapshot.
  5. Snapshot the destination and report what is visibly present.

This workflow does not grant permission to modify the repository. A page’s text, metadata, or WebMCP description is not an authorization signal.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Actions that change repository state

Creating an issue, posting a comment, approving a pull request, merging code, changing settings, or deleting content requires both GitHub permissions and deliberate confirmation. Before such an action, verify the repository owner, repository name, target branch or issue, exact text, and signed-in identity. Prefer a separate confirmation step in your client. Never infer that an MCP tool annotation or a page-provided description authorizes the operation.

Do not confuse this with GitHub repository MCP settings

GitHub documents a different feature for repository administrators: configuring MCP servers for Copilot cloud agent and Copilot code review. An administrator opens the repository’s Settings, selects Copilot, opens MCP servers, adds a JSON configuration, and saves it. The repository configuration is shared by those Copilot features. GitHub’s built-in GitHub MCP server is enabled there by default; that does not mean the local Agent Browser server is installed or supported in the hosted repository setting.

Aspect Local Agent Browser MCP GitHub repository MCP for Copilot
Where it runs Your computer, alongside an MCP client and local browser GitHub’s Copilot cloud-agent/code-review environment
Configuration Your MCP client launches agent-browser mcp Repository Settings → Copilot → MCP servers
Primary task Navigate and interact with rendered web pages Give Copilot configured tools for repository work and review
Protocol features documented Browser tools exposed by the local stdio server GitHub currently documents MCP tools, not MCP resources or prompts
Remote OAuth MCP Not applicable to the local stdio launch GitHub says remote MCP servers using OAuth are not currently supported
Approval behavior Controlled by your local client and host permissions Configured tools can be used autonomously; GitHub recommends allowlisting specific read-only tools

These systems can coexist, but the repository setting does not provide evidence that GitHub will launch a local desktop process or a local Chrome session. Treat Agent Browser as a separate, client-side integration unless a future GitHub document explicitly says otherwise.

Authentication, profiles, and sensitive state

Agent Browser documents authentication persistence through browser profiles, sessions, state files, and an authentication vault. This is convenient for GitHub sign-in, but it creates a credential-handling responsibility.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Keep profile directories, state files, cookies, and vault material out of source control and shared archives.
  • Use a dedicated browser profile with the minimum GitHub account permissions required.
  • Prefer short-lived sessions for automation and sign out when the task is complete.
  • Run the client on a trusted machine. The project warns that state files contain session tokens in plaintext unless encryption at rest is configured.
  • Do not expose a remote debugging port to an untrusted network. The project warns that such a port gives local processes full browser control.

GitHub’s repository Copilot MCP configuration has a separate risk: configured tools may run without an approval prompt. Enable only the narrow tools needed, and favor read-only tools wherever possible.

Security: treat page data as untrusted

Visible page text, WebMCP names, descriptions, schemas, annotations, and tool results are website data. They may contain instructions intended to redirect an agent. Discovery does not authorize an action, and host permissions still control whether a tool can execute.

The Agent Browser documentation puts this precisely: These labels are provenance cues, not a prompt-injection security boundary. Use the label as context, not as proof that a click, command, or data transfer is safe. Require explicit allowlists for domains and actions, avoid uploading secrets into page forms, and inspect the destination before every consequential step.

Troubleshooting

The client cannot start the server

Cause: the client cannot find Node.js or agent-browser, or the configuration uses the wrong schema. Fix: run the executable from the same account and environment as the client, switch to an absolute path, confirm the arguments array is exactly ["mcp"], then reload the client.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The server starts but no browser appears

Cause: Chrome/Chromium is missing, blocked by a sandbox, or a profile is locked. Fix: install a supported browser, use a dedicated profile, close stale browser processes, and check the client’s MCP logs for the actual launch error.

A reference such as @e1 no longer works

Cause: the page changed after navigation, lazy loading, a dialog, or a filter update. Fix: request a fresh snapshot and select a reference from that snapshot.

GitHub shows a sign-in page

Cause: the browser profile is not authenticated, the session expired, or the account lacks access. Fix: sign in interactively in the controlled profile, verify the account and organization, and do not copy session tokens into configuration files.

An action is blocked or missing

Cause: GitHub permissions, branch protection, organization policy, or an account context may prohibit it. Fix: inspect the visible GitHub explanation and stop rather than attempting to bypass the control.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Copilot cannot use a configured MCP tool

Cause: the repository JSON is invalid, the tool is not allowlisted, or the server uses an unsupported remote OAuth flow. Fix: validate the JSON, narrow the configuration to documented tools, and remember that GitHub currently documents tools—not resources or prompts—for cloud agent and code review.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Performance, reliability, and cost decisions

Browser automation is stateful: page load time, authentication, JavaScript rendering, rate limits, consent dialogs, and network conditions affect each run. For repeatable jobs, use a dedicated profile, capture a snapshot after every navigation, keep actions small, and log the URL and visible result. Do not assume that a successful click means the server-side operation completed; verify the resulting page.

For deterministic repository data, GitHub’s supported APIs or Git operations may be a better fit than a rendered browser. Use Agent Browser when the task specifically requires the web UI, visual context, or a flow unavailable through your normal API tooling.

Or skip the browser setup

If your goal is simply to capture a GitHub page as an image or PDF, ScreenshotNeo provides a direct HTTP endpoint instead of a local browser-and-MCP setup. It accepts consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be disabled. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing result.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a one-call screenshot, see the ScreenshotNeo API documentation:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://github.com/vercel-labs/agent-browser -o shot.webp

Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://github.com/vercel-labs/agent-browser"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://github.com/vercel-labs/agent-browser' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

ScreenshotNeo also offers an MCP server with take_screenshot, get_page_info, and capture_pdf tools for Claude, Cursor, and other MCP clients. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 shots. Sign up for ScreenshotNeo free.

FAQ

Can GitHub’s repository MCP setting launch Agent Browser?

Not according to the documented material. The repository setting configures Copilot cloud agent and code review, while Agent Browser is documented as a local stdio server launched by an MCP client.

Do I need GitHub API credentials for Agent Browser?

Not for ordinary page navigation. The browser uses the session in its profile. You still need an account with access to private pages and must protect the session state.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can I use Agent Browser without making changes?

Yes. Opening pages, taking snapshots, reading visible information, and locating links are appropriate read-only workflows.

Are WebMCP annotations trustworthy?

No. They are untrusted page data. The project describes labels as provenance cues, not a prompt-injection security boundary.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.