The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Aginx Browser listing page.
The Browser for AI Agents. See the live web. Read it. Act on it. Remember it.
A browser built for agents from the first line of code — not a human browser bolted onto automation. See the world, read it, search it, act on it, and keep what you read: one Rust binary with built-in V8, no Chromium required.
Humans have Chrome. Agents have AginxBrowser.
One binary, zero dependencies, instant service. HTTP API + native MCP + CDP — agents plug in and go, and existing Playwright / Puppeteer / browser-use code attaches directly.
Real pages rendered by AginxBrowser's diting engine (no Chromium) — Wikipedia, this repo, Rust. Screenshot it yourself →

Measured against headless Chrome on the same 20 pages, same network (bench, 2026-08-28): 7.6× faster to agent-usable text (p50 532 ms vs 4 053 ms), ~10× less memory (227 MB for the whole process vs ~2.1 GB per Chrome page), and 0 hard failures where Chrome's --dump-dom produced no DOM on 5 of 40 loads. An agent's total cost is browser efficiency × model efficiency — this is the browser half.
Existing "browser automation" was built for humans or for one-shot scraping — not for agents:
| AginxBrowser | Puppeteer/Playwright | Firecrawl | Browser-use | |
|---|---|---|---|---|
| Designed for | Agents first | Human debugging | Scraping service | LLM wrapper |
| Dependencies | Single binary, no Chromium | Chromium ~500MB | Docker ~1GB | Chromium |
| Sees (screenshots) | ✅ built-in diting rendering engine | Needs Chromium | ❌ | Needs Chromium |
| Reads | markdown + js_extract + fetch receipts | DIY | markdown | DIY |
| Finds (search) | ✅ 15 engines, 7 categories, merged | ❌ | ❌ | ❌ |
| Acts | indexed session interaction | DevTools API | ❌ | LLM-driven |
| Remembers | ✅ local fetch/search cache (SQLite FTS5) | ❌ | crawl cache | ❌ |
| Protocol | HTTP + native MCP + CDP | Node API | HTTP | Python |
| TLS fingerprints | ✅ Chrome/Firefox/Safari/Edge | Plugin required | ❌ | ❌ |
| CAPTCHA | ✅ detect + auto-wait + optional 2captcha | DIY | ❌ | ❌ |
| Interactive sessions | ✅ persistent | ✅ | ❌ | ✅ |
An agent needs five things from a browser: see, read, find, act, remember. One binary covers them all — systemd-friendly, MCP-native for Claude/Cursor, zero dependencies.
Core advantage: no Chromium. AginxBrowser inlines a full browser engine (V8 + Rust HTTP stack + the diting CSS/layout/paint rendering engine, with the Blitz/Stylo/Taffy lineage as its reference implementation). No Puppeteer, no Chrome, no Docker. One Rust binary under systemd is your agent browsing infrastructure.
Most new "agent browsers" are stateless, fingerprint-less one-shot renderers — fine for public pages, dead on arrival against Cloudflare or login flows. AginxBrowser goes the opposite way:
cf_clearance. Fingerprint-less engines eat 403s — we get through.session_create(cookies=...) ↔ session_cookies), surviving pagination and multi-step flows; persistent: true even survives idle eviction and server restarts — the same session id comes back logged in. One-shot engines throw state away.Reference point: Cloudflare's Kitesurf explicitly ships neither real TLS-fingerprint negotiation nor persistent auth sessions — anti-bot and login territory is exactly where AginxBrowser plays.
Apache-2.0 open source, single binary — self-host today, no cloud lock-in.
Agents act on what a browser tells them, so the response reports what actually happened — not just "got a 200":
tier — which path served the page: plain HTTP (~100 ms) or the V8-rendered browser tier. An agent can see why a fetch was fast or slow.redirected_from — the full redirect trail. redirected_from[0] is the URL you asked for, url is where the content actually came from — requested paired with effective, every hop visible.content_hash + changed_since_prev — every fetch is hashed; consecutive samples of the same URL can be diffed. A rate-limited origin serving the same frozen 200 body for days reads as changed_since_prev: false — the cheapest drift detector there is.captcha_event — when a challenge page was detected (and solved, if a solver is configured), the response says so instead of handing over a challenge page as if it were content.The local cache builds on the same idea: search hits come back with [§ heading] section prefixes so an agent knows where on the page a hit landed, and ranking fuses keyword relevance with freshness.
tier field)/search. Search → read in one stepcategories=images hits Baidu/Bing image indexes and returns direct binary image_url links (downloadable straight to jpg/png) plus source_url provenancestate/click/input/scroll/eval) — agents browse like humans do, and session_export turns what an agent figured out into a runnable curl replay script (zero model tokens on re-run). Session tools also cover the acting part: session_viewport simulates device viewports (media queries respond), session_wait blocks on a selector or predicate with a timeout, session_screenshot renders the live state, session_console replays the page's console ring, and session_storage exports/restores cookies plus localStorage for login hand-offsession_network(filter=media) extracts the m3u8/mp4/dash URLs a page's player actually requested at runtime — links found only in page HTML are often decoys, so the request log is the source of truth. GET /session/{id}/har exports the same traffic as HAR 1.2 (retained bodies included)/json/version + /devtools/{kind}/{id} WebSocket — chromium.connectOverCDP() from Playwright, Puppeteer, or browser-use attaches with one line (integration guide). DevTools ecosystem compatibility without becoming a CDP shim~/.aginxbrowser/cache.db. The cache tool re-answers from what the agent already read instead of re-paying network time: full-text search with CJK substring matching, keyword × freshness fusion ranking, [§ heading] section-aware snippets, per-URL content hashes for drift detection, TTL-bounded, per-session scoping for shared deploymentsjs_extract pulls window.__INITIAL_STATE__ and other structured data out of SPAs/screenshot endpoint (opt-in --features screenshot) paints the JS-rendered DOM with the diting rendering engine — pure CPU, no Chromium — to PNG. Vision input for agents--mcp mode exposes 28 tools (fetch/eval/search/download/cache + session + screenshot tools) — Claude Code / Claude Desktop / Cursor call them directly/v1/scrape endpoint — existing Firecrawl clients migrate by changing the base URLAginxBrowser exists for real-time retrieval: an agent arrives with a question, reads a handful of pages, leaves with the answer. It is not a crawling tool — and the product is shaped so it can't quietly become one:
AGINXBROWSER_HONOR_ROBOTS=1.AGINXBROWSER_DOMAIN_RATE_PER_MIN / AGINXBROWSER_SESSION_PAGE_LIMIT (0 disables on your own instance). Generous for an agent grinding through docs or a console; fatal to the page-after-page crawl pattern, including subdomain rotation (one registrable domain, one budget).Not demos — real jobs agent browsers are doing today:
Try the hosted instance first: https://browser.aginx.net/
One-command full install (SKILL.md trigger surface + MCP tools + verification):
Register MCP only:
Install the skill trigger surface via skills.sh:
Self-hosting:
Requirements: Rust 1.78+; the V8 static library downloads automatically on first build. The stealth feature additionally needs go, cmake, and a C++ compiler. The screenshot feature ships with a bundled CJK font subset (GB2312 + common symbols) — no system fonts required for correct Chinese rendering.
If your network can't reach the rusty_v8 CDN (build hangs with zero progress after "downloading v8"), pre-fill ~/.cache/rusty_v8 with the librusty_v8.a.gz for your version (fetch it from any reachable mirror/host and gunzip into place) and the build script skips the download.
| Variable | Default | Description |
|---|---|---|
AGINXBROWSER_BIND | 0.0.0.0:8089 | Listen address |
AGINXBROWSER_STEALTH | enabled | 0 disables stealth (for diagnostics) |
AGINXBROWSER_UA | Linux Chrome145 | Spoofed User-Agent |
AGINXBROWSER_ACCEPT_LANGUAGE | zh-CN,zh;q=0.9,en;q=0.8 | Accept-Language header |
AGINXBROWSER_PROXY | none | Optional fallback proxy. Blocked-source engines (Google, Bing News, Hugging Face) connect directly first and fall through to this proxy only when the direct attempt fails — overseas deployments need no proxy at all; per-request use_proxy:true also routes fetch/search through it. Browser/session/CDP navigations to known-blocked domains (wikipedia.org, github.com, …) route through it automatically. Standard HTTP_PROXY/HTTPS_PROXY/ALL_PROXY are deliberately ignored by the engine (set them for other tools freely); startup logs a warning when it sees one |
AGINXBROWSER_NAV_CHAIN_LIMIT | 10 | JS navigation-chain cap: documents a page may chain via location/form hops before navigation aborts. The count includes the requested document (10 = initial doc + 9 hops). Raise for legit long chains (SSO handover across providers); HTTP 3xx redirects are budgeted separately (20, per Fetch spec / browser parity) |
AGINXBROWSER_CACHE_TTL_SECS | 600 | /fetch cache TTL, 0 disables |
AGINXBROWSER_HONOR_ROBOTS | unset | robots.txt is not consulted by default on /fetch, /screenshot, /download and MCP tools; set 1 to opt in (operator choice) |
AGINXBROWSER_ROBOTS_TTL_SECS | 3600 | Per-host robots.txt policy cache TTL |
AGINXBROWSER_DOMAIN_RATE_PER_MIN | 20 | Per-registrable-domain page budget per minute (subdomains share one budget); over-budget requests get 429 with the stance message. 0 disables. See "A Browser, Not a Crawler" |
AGINXBROWSER_SESSION_PAGE_LIMIT | 200 | Total pages one interactive session may walk (navigation-causing clicks count); over-budget navigations are refused, the current page stays interactive. 0 disables |
AGINXBROWSER_MCP_ALLOWED_HOSTS | unset | Extra Host values accepted by /mcp (comma-separated) — the transport's DNS-rebinding guard defaults to loopback, so add your LAN IP or Docker hostname when other machines call the instance |
AGINXBROWSER_STORE | on | Local fetch/search cache; 0/false/off disables |
AGINXBROWSER_STORE_PATH | ~/.aginxbrowser/cache.db | SQLite database location (created 0600) |
AGINXBROWSER_STORE_TTL_HOURS | 720 | Cached page TTL |
AGINXBROWSER_STORE_SEARCH_TTL_HOURS | 168 | Cached search-result-set TTL |
AGINXBROWSER_STORE_SCOPE | global | session gives each MCP client session its own cache scope — set this on public multi-client deployments |
CAPTCHA_SOLVER_API_KEY | none | 2captcha API key; enables CAPTCHA auto-solving |
CAPTCHA_SOLVER_SERVICE | 2captcha | CAPTCHA solving provider |
AGINXBROWSER_MEILI_URL | none | Meilisearch base URL; set to enable the private-index engine |
AGINXBROWSER_MEILI_INDEX | none | Meilisearch index uid to query |
AGINXBROWSER_MEILI_KEY | none | Optional Bearer key for the Meilisearch instance |
Full API reference → docs/API.md
CDP integration guide → docs/integrations.md — Playwright / Puppeteer / browser-use one-liners
Security audit notes → docs/skills-sh-audit.md — why skills.sh shows "Critical Risk", and which real product feature each warning corresponds to
Covers:
/fetch, /search, /screenshot, /download, /v1/scrape, /doctor, 18 session endpoints, CDP discovery, MCP transport)AginxBrowser is pure attach-alongside infrastructure — like a real browser, it runs as an independent service that anything can call, without embedding host code or polluting host config. Deploy one instance per machine (under systemd) and every app needing "render + scrape" capability shares it.
Three attach points:
/fetch, /search, /screenshot, /download for any language with an HTTP clientws://your-host:8089/devtools/browser/<id>; see docs/integrations.mdIntegration: read the environment variable AGINXBROWSER_URL=http://127.0.0.1:8089. Unset → behavior unchanged; set → risk-controlled sites automatically route through AginxBrowser for rendering, falling back gracefully on failure.
/screenshot requires cargo build --release --features screenshot (adds the diting rendering stack). The default (and only) render engine in that build is diting — our own CSS+layout+paint stack, zero Blitz/Stylo code. The pinned-rev Blitz reference pipeline is a separate opt-in, --features blitz-reference, for comparison renders and the dual-engine cross-check tests. Complex-site CSS is approximate on both (not pixel-perfect like Chromium)/screenshot with selector returns element page coordinates (selector_rects, CSS px); selector alone crops directly to that element. Inline elements (<a>text</a>) get a rect too on the default diting engine — a union of their flattened inline content, strut-expanded to the element's own line-height like Chrome reports for replaced-only inlines (<a><img></a> → line-box height, not the image height). Empty inlines still have no rect — pick a block ancestor theresrc/href resolve to absolute URLs so Next.js/webpack hydrate and clicks trigger handlers). Heavy-fingerprint auth pages (WorkOS/Cloudflare) probing navigator.plugins, WebGL canvas etc. may still break until stealth fingerprint coverage completesAGINXBROWSER_PROXY__zse_ckIf AginxBrowser saved you a headless-Chrome fleet or a scraping headache, a star is how other agents (and their humans) find the project.
Apache-2.0.