Let AI coding agents read pages through your real, logged-in Chrome browser.
Let your coding agent read pages through YOUR real, logged-in browser.
Claude Code's WebFetch gets 403'd on most sites. Ask it to pull up a doc, check a Reddit thread, or look at a GitHub issue, and it comes back with a 403 — because server-side fetchers don't have your cookies, your logins, or your sessions.
Browser Buddy is a small local MCP bridge: a Chrome extension (Manifest V3) talks to a Python native-messaging host, which exposes two MCP tools. Your agent reads pages exactly as you see them — logged in, past bot checks — and the page never leaves your machine except into the agent's context.
Stdlib only. No dependencies, no cloud, no API keys.
| Tool | What it does |
|---|---|
read_active_tab | Extract readable text (URL, title, cleaned body) from your active Chrome tab |
open_and_read_url | Open a URL in a background tab with your real profile (cookies/logins), extract its text, close the tab |
┌─────────────┐ MCP (JSON-RPC 2.0 ┌──────────────────┐ Unix socket ┌───────────────────┐ Native Messaging ┌────────────────┐
│ Claude Code │ ── over stdio, NDJSON ──▶ │ browser_buddy_mcp │ ── NDJSON ──▶ │ browser_buddy_host │ ── 4-byte LE ──▶ │ Chrome extension │
│ │ ◀────────────────────── │ .py │ ◀──────────── │ .py │ ◀── JSON ─────── │ (your profile) │
└─────────────┘ └──────────────────┘ └───────────────────┘ └────────────────┘
▲ │ │
│ │ one request per socket connection; │ chrome.tabs +
└──────── page text lands here ──────────┘ host routes replies by request id │ chrome.scripting
▼
real logged-in page
extension/): MV3 service worker. Holds a persistent chrome.runtime.connectNative port to the host (auto-reconnects). Executes read_active_tab / open_and_read_url against your real tabs and posts extracted text back.host/browser_buddy_host.py): launched by Chrome. Bridges the extension (length-prefixed stdio) and the MCP server (Unix socket at $TMPDIR/browser-buddy/browser-buddy.sock). Correlates requests by id, with a 90 s timeout.pypi/browser_buddy_mcp.py): hand-rolled JSON-RPC 2.0 over stdio (no mcp package). Forwards tool calls to the host; returns page text as MCP content.chrome://extensions, enable Developer mode.extension/ folder.cd host
./install.sh <paste-extension-id-here>
This writes com.browserbuddy.host.json into Chrome's NativeMessagingHosts
directory (Linux/macOS) pointing at browser_buddy_host.py. Restart Chrome,
then open the extension's service worker console — you should see
[browser-buddy] native host connected.
claude mcp add browser-buddy -- python3 /absolute/path/to/pypi/browser_buddy_mcp.py
Or in ~/.claude.json / project .mcp.json:
{
"mcpServers": {
"browser-buddy": {
"command": "python3",
"args": ["/absolute/path/to/browser-buddy/pypi/browser_buddy_mcp.py"]
}
}
}
Requires Python 3.9+. No pip install needed — or install the published
package: pip install browser-buddy-mcp (built from pypi/; the browser-buddy-mcp
command is the entry point).
Vendor scrapers (Firecrawl, etc.) fetch pages server-side: they never have your cookies, can't get past SSO/2FA/login walls, can't see what you see behind an account, and they charge per page. The official Claude in Chrome goes the other way — full autonomous browser control — but ships a permission dialog per tool call (dozens per session) and sits at 2.7 stars on the Chrome Web Store.
Browser Buddy picks the middle: read-only access through the browser you already logged into. No credentials leave your machine, nothing to pay per page, no dialog spam — just "let the agent see what I see."
(truncated)).open_and_read_url opens URLs in your real, logged-in browser. A
prompt-injected page could otherwise steer the agent toward your email or
other sensitive sites. Restrict which domains the agent may open:
// ~/.config/browser-buddy/config.json
{
"allowed_domains": ["github.com", "stackoverflow.com"]
}
Entries match the domain and its subdomains (docs.github.com is covered by
github.com). When the list is empty (default), any URL is allowed but the
server logs a warning recommending you set it. URLs outside the list are
refused before anything is opened. read_active_tab is unaffected — it only
reads the tab you already opened.
python3 tests/test_smoke.py # 25 tests: framing, bridge routing, MCP handlers,
# socket dir, domain allowlist
node --check extension/background.js
MIT — see LICENSE.
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
uvx browser-buddy-mcpMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"io-github-hahahahahahahahah6-browser-buddy": {
"command": "uvx",
"args": [
"browser-buddy-mcp"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup referencebrowser-buddy works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.