An MCP endpoint is the address an MCP client uses to discover and call browser tools. The browser does not have to run on the same computer. You can run Playwright MCP locally and attach it to a cloud browser over CDP, expose Playwright MCP as an HTTP service, or use a provider-hosted remote MCP service. The right design depends on where the browser and MCP process run, how callers authenticate, how sessions are managed, and which tools you expose to the model.
What an MCP endpoint actually connects
Model Context Protocol (MCP) is the tool connection layer. An MCP client such as Claude, Cursor, or another compatible application connects to a server endpoint, lists the available tools, and invokes them. A browser session can be local, on a private machine, in a cloud provider, or in a managed workspace.
Playwright MCP can attach to an existing Chromium browser through a CDP endpoint or to a running Playwright server. Playwright documents the CDP route as compatible with cloud-browser services. In a different deployment, Playwright MCP itself listens on an HTTP port and the client connects to that URL. Hosted services package some or all of those operations behind their own remote MCP endpoint.
Choose a deployment pattern
| Pattern | Where components run | What you must operate | Best fit |
|---|---|---|---|
| Local MCP plus remote browser | MCP on your workstation; browser in a cloud service | Client configuration, endpoint credentials, session lifecycle and network access | Development when you want local control of the tool server |
| Standalone Playwright MCP over HTTP | Your server runs MCP and launches or reaches browsers | HTTP exposure, authentication, isolation, updates, monitoring and browser capacity | Teams that need one endpoint for several clients |
| Provider-hosted remote MCP | Provider operates the MCP service and browser infrastructure | Provider account, API credentials, service settings, regional and availability constraints | Teams willing to accept a managed service dependency |
These are architectural choices, not a universal ranking. A hosted service can remove browser-server work but adds account, policy and outage dependencies. A self-operated endpoint gives more control but makes you responsible for patching, isolation and capacity.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
Examples of hosted implementations
- Browserbase documents a hosted MCP server over Streamable HTTP that requires a Browserbase API key and describes managed proxies, Verified access and session recording.
- Cloudflare documents a Playwright MCP fork using Browser Run and separate CDP connection patterns for Browser Run.
- Microsoft Playwright Workspaces documents a managed cloud browser with a remote MCP server over Streamable HTTP. Microsoft labels this service preview; its endpoint and behavior can change.
Those implementations are distinct. Their tools, authentication, retention, regions, pricing and reliability should not be assumed to match.
Prerequisites and trust decisions
- An MCP client that supports the transport used by your server (for example, HTTP or Streamable HTTP).
- A current Playwright MCP installation when you operate the server yourself. Playwright’s getting-started guide lists Node.js 20 or newer.
- A browser endpoint from your provider, using the provider’s documented CDP or Playwright-server format and credentials.
- A decision about whether sessions are disposable or may contain logged-in cookies, SSO state and 2FA context.
- An authentication and authorization layer in front of any network-reachable MCP endpoint.
Start with a harmless public page. Confirm that the client sees only the intended tools and the intended browser session before connecting production accounts.
Set up local Playwright MCP with a remote browser
- Install the current MCP package. Use the installation instructions for your client and verify that your Node.js runtime meets the documented requirement.
- Obtain a browser endpoint. A CDP endpoint is passed with
--cdp-endpoint; a running Playwright server is passed with--endpoint. The exact URL shape, token placement and TLS requirements come from the browser provider. - Start MCP with the selected endpoint. An illustrative invocation is
npx @playwright/mcp@latest --cdp-endpoint https://browser.example.invalid/cdp?token=REDACTED. Treat the hostname, token format and package command as examples; use the current Playwright and provider documentation for production values. - Register the MCP server in your client. A generic JSON shape for an HTTP server is:
{
"mcpServers": {
"remote-browser": {
"url": "https://mcp.example.invalid/mcp",
"headers": {
"Authorization": "Bearer YOUR_MCP_TOKEN"
}
}
}
}
Some clients use a command and arguments instead of a URL; others require Streamable HTTP settings. Copy the schema required by your client rather than assuming this JSON is universal.
- Limit capabilities. Configure Playwright MCP so the model receives only the tools your workflow needs. Read-only navigation and screenshots require less privilege than arbitrary page scripting, downloads or filesystem access.
- Run a smoke test. Navigate to a non-sensitive page, take a screenshot or read page information, then close the session. Check server logs and provider session records for unexpected requests.
Run Playwright MCP as an HTTP service
The standalone pattern keeps the MCP process in your infrastructure. Start Playwright MCP on a private port according to the current getting-started guide, then place an authenticated reverse proxy or private network in front of it. Point each client at the resulting URL. Do not expose an unauthenticated listening port directly to the internet.
Recommended Free Tools
Rank #2
Operational checklist
- Terminate TLS at the proxy or service listener.
- Require per-client credentials and rotate them.
- Restrict source networks or use a private link where possible.
- Set idle and maximum session limits so abandoned browsers do not accumulate.
- Record tool calls, browser-session identifiers and error outcomes without logging secrets or page contents unnecessarily.
- Patch the MCP package and browser image on a schedule, and test upgrades against your client configuration.
Use a provider-hosted remote MCP endpoint
Hosted services normally give you an endpoint URL, an API key or OAuth flow, and a documented client configuration. Browserbase’s hosted endpoint uses Streamable HTTP and a Browserbase API key. Cloudflare’s Browser Run documentation describes its own MCP and CDP connection methods. Microsoft’s Workspaces remote MCP service is documented as preview as of September 14, 2026.
- Create the provider account and project required for browser sessions.
- Enable the documented MCP or CDP capability.
- Create a narrowly scoped credential; never paste a provider key into a prompt or commit it to a repository.
- Configure the MCP client with the provider’s exact transport, URL and authentication fields.
- Specify session timeout, region, recording and proxy settings where the service offers them.
- Test authentication and tool visibility with a non-production session.
Provider documentation is the authority for current endpoint formats, supported regions, retention and terms. The examples above establish connection patterns, not feature or price parity.
Security boundaries you must enforce
Arbitrary code execution
Playwright warns that browser_run_code_unsafe executes arbitrary JavaScript in the MCP server process and is “RCE-equivalent — only enable it for trusted MCP clients.” Treat any client with that tool as a highly privileged operator. Prefer purpose-built navigation, locator and screenshot tools when they are sufficient.
Convenience guardrails are not isolation
Playwright describes origin allow-lists and file-access protections as convenience defenses. They can be worked around, do not affect redirects, and are not a substitute for network isolation and authorization. Secret redaction or substitution is also a convenience feature, not a security boundary. Enforce trust at the deployment layer with authentication, authorization, sandboxing and least-privilege credentials.
Logged-in browser profiles
An extension connection can reuse an existing profile’s cookies and sessions, which helps with SSO and 2FA workflows. It also gives automation access to that profile’s authenticated state. Use a dedicated profile, minimize account scope and destroy or revoke it when the task ends.
Reliability, latency and cost considerations
- Network path: A local client, remote MCP server and cloud browser may create several links. Use regional placement and keep-alive settings supported by your provider, then measure the complete tool-call latency.
- Session lifecycle: Decide whether each task gets a fresh browser or a reused context. Reuse reduces startup time but increases state leakage risk.
- Capacity: Enforce concurrency and queue limits. Browser startup, navigation, downloads and recording consume different resources.
- Observability: Correlate MCP request IDs with browser-session IDs and provider status records. Capture failure reasons, not sensitive page data by default.
- Service dependency: A hosted endpoint can simplify operations but introduces provider outages, account limits and policy changes. Keep a documented fallback or a way to disable automation safely.
Browserbase publishes a figure of more than 35 million browser sessions per month for its infrastructure (August 17, 2026). That is a vendor-published figure, not an independent performance guarantee or a prediction for your workload.
Troubleshooting common failures
The client cannot connect
Check that the URL uses the transport your client supports, TLS certificates are valid, the reverse proxy forwards streaming responses, and firewalls allow the client-to-endpoint path. Test the endpoint from the same network as the client.
Authentication fails
Verify whether the service expects an Authorization header, query parameter, API-key header or OAuth token. Remove expired credentials, check project scope and rotate leaked keys. Do not move a secret into model-visible tool arguments unless the provider explicitly requires it.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesThe MCP server starts but no browser appears
Confirm that the CDP or Playwright-server endpoint is reachable from the MCP host, that the browser session is running, and that the endpoint has not expired. Provider-specific endpoints often require a new session identifier for each run.
Tools are missing
The client may cache a previous tool list, or the server may have been started with a restricted capability set. Restart or refresh the MCP connection, then inspect the server’s enabled-tool configuration.
Navigation hangs or times out
Check DNS and egress rules, provider session limits, target-site bot checks and page dependencies. Use a bounded timeout and capture server logs. Do not solve a timeout by granting arbitrary code execution.
Redirects or file access bypass a filter
That behavior is consistent with Playwright’s warning that origin and file-access controls are convenience defenses. Move enforcement to the proxy, network policy and browser sandbox, and reduce the credentials available to the session.
Best Value
Or skip the browser setup
For a screenshot-only workflow, ScreenshotNeo provides a website screenshot API and MCP server. One GET request returns PNG, JPEG, WebP or PDF. Before capture it accepts cookie and consent banners and removes more than 60 known consent platforms, newsletter popups and chat widgets; each cleanup step can be disabled. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed, and response headers report the page verdict and billing status.
Its MCP server exposes take_screenshot, get_page_info and capture_pdf for Claude, Cursor and other MCP clients. The API also supports full-page captures with lazy images, CSS-selector element shots, dark mode, device presets, custom viewport and retina scale, PDF paper and margin controls, custom CSS and JavaScript, clicks, waits, request blocking, headers, cookies, user agents, Authorization, timezone, geolocation, transparent backgrounds, resizing, configurable caching, signed image links, asynchronous jobs with signed webhooks, bulk capture of up to 100 URLs per call, usage reporting and an OpenAPI specification. Common screenshot-API parameter names are accepted to ease migration.
Use the current ScreenshotNeo documentation for authentication and options. The one-call examples below use the required URL parameter:
cURL
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
The Free plan includes 1,000 screenshots per month without a card. Paid plans start at $5 for 3,000 shots; every feature is available on every plan. Create a free ScreenshotNeo account.
Frequently Asked Questions
Can an MCP client connect directly to a CDP URL?
Yes, when the MCP implementation supports the CDP attachment mode and the browser provider exposes a compatible, reachable endpoint. Authentication and URL format remain provider-specific.
Should I reuse one browser session for multiple agents?
Only when the shared authenticated state is intentional and access is tightly controlled. Otherwise give each task an isolated context or disposable session.
Is a managed MCP service automatically safer than self-hosting?
No. It may reduce operational work, but you still must evaluate credentials, data residency, retention, permissions, provider access and failure handling.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




