Drive your real Chrome over MCP: real logins and cookies, multi-tab automation, deny-all by default.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
Let Claude use the Chrome you are already logged into. Not a fresh automated browser that greets every site as a stranger β your Chrome, with your sessions, your cookies, your 2FA already done. If you can see a page in your browser, your agent can read it, without logging in again and without pasting credentials anywhere.
Most browser MCP servers launch their own Chromium and hand your agent a
signed-out window. chrome-mcp does the opposite: an MV3 extension dials into a
localhost WebSocket server and drives the browser you already have open, through
chrome.scripting/chrome.tabs. Works with Claude Code, Claude Desktop, and any
other MCP host.
Distributed as an npx CLI (the MCP server) plus an extension, from the
Chrome Web Store
or loaded unpacked.
This build is extension-only. It never launches or attaches a Chromium of its own, so the extension is required, not optional β without it, no tool can run. The CDP flags (
--cdp-fallback,--no-cdp-fallback,--cdp-endpoint,--prefer) are still accepted for back-compat but are ignored.
Full design:
docs/BLUEPRINT.mdβ architecture, wire protocol, the complete tool surface, the extension manifest, the security model, and the phased build plan.
You are already signed in to Gmail, GitHub, your analytics dashboards, the admin panel, the CRM. chrome-mcp lets Claude (Claude Code, Claude Desktop, or any other MCP host) work in those same tabs: no re-login, no second 2FA prompt, no password or cookie in a config file. The extension runs inside your normal Chrome, so a page the agent opens is the page you would see.
Other tools drive a signed-in Chrome too (the hangwin/mcp-chrome extension,
for one), so the question is what you get on top of the session:
--allow-domain mail.google.com --allow-domain github.com
opens exactly those hosts (*.example.com covers a domain and its
subdomains); every other site is refused before the call reaches the page.
Reads are gated, not only clicks, and the extension re-checks the same policy
on its side. Mutations, eval, downloads and uploads are separate opt-ins.--redact scrubs tokens, API
keys and JWTs out of page reads.batch: open pages with active: false and read many
at once in one call, without stealing focus from the tab you are working in.profile_use.auth_check: when a session does expire, the agent gets an
[AUTH_REQUIRED] signal instead of a confusing timeout, so it can stop and
ask you to sign in again. chrome-mcp never holds credentials or signs in for
you.Setup is two pieces: the MCP server (npx, below) and the extension, which you
can install from the Chrome Web Store
or load from the folder the server unpacks.
Hand this to your AI agent (Claude Code, Cursor, Windsurf, anything MCP) and it installs the server, wires it into the client, and walks you through the two steps that must happen inside Chrome:
Prefer to read before you run an agent on your machine? SETUP.md
is the exact file the agent follows. The manual steps are below.
1. Register the MCP server with your host.
Everything before -- belongs to Claude Code; everything after it is this
server's command and flags. Keep the -- or --allow-domain gets read as a
Claude Code option.
-s user registers it for every project on your machine. Use -s local (the
default) for just the current project, or -s project to write a .mcp.json
your team can commit.
Check it came up with claude mcp list. After upgrading the server, reconnect it
with /mcp inside a session β no restart needed.
By default everything is deny-all (no domains, no eval, no mutations). Grant
exactly what you need with --allow-domain <glob> (repeatable), --enable-mutations,
--enable-downloads, --enable-uploads, --unsafe-enable-eval, or --unsafe-all-domains.
--enable-uploadspermitsupload_file(setting local file(s) on a page's file<input>). It is off by default because sending local files to a page is an exfiltration risk; it is also gated by the destination-domain allowlist. Pair it with--uploads-dir <path>to restrict uploads to files inside that directory (..traversal is blocked) β strongly recommended for unattended use.
Pair once, never again. Both examples above include --persist-token, which
is what makes the pairing survive a restart β drop it if you'd rather have the
stricter default described next.
Without --persist-token a fresh token is minted every boot (the secure
default), which means re-pairing the extension on each restart. With it, the
token is stored 0600 at ~/.chrome-mcp/token and reused; the extension's
keepalive auto-reconnects with no manual step. CHROME_MCP_TOKEN pins the token
explicitly (and is never written to disk).
2. Load the extension β required; the server can drive nothing without it.
Two ways to get it:
The extension ships prebuilt inside the npm package, and every time the server boots it copies it to a plain folder right under your home directory:
So after step 1 has started the server once (restart your client, or /mcp in
Claude Code), the folder is already there. To create it without a client, or
to print the exact path:
Then chrome://extensions β enable Developer mode β Load unpacked β
pick chrome-mcp-extension in your home folder. After upgrading the package the
server refreshes the files on its next boot and the extension reloads itself
within 30 seconds; nothing to click. CHROME_MCP_EXTENSION_DIR moves the
folder somewhere else. (Working from a git clone instead? Run
npm install && npm run build:ext first β extension-dist/ is gitignored, and
the server mirrors it to the same home folder.)
3. Pair it β usually nothing to do. Every time the server boots it writes
pairing.json (mode 0600, never shipped in the tarball) into the very
chrome-mcp-extension folder you just loaded. The extension reads that file
from its own folder on startup and pairs itself, so the toolbar badge turns
green with no token to paste. Load the extension before the server has ever
run? It re-checks every 30 seconds and pairs as soon as the file appears.
Where to see the badge: it sits on the extension's icon in Chrome's
toolbar, not on the chrome://extensions page. Chrome hides new extensions
behind the puzzle-piece button at the right of the address bar, so click that,
find MCP Extension for Chrome, and click the pin next to it once; the icon then
stays in the toolbar. Hover it for the status in words.
| Badge | Meaning |
|---|---|
| green dot | paired and connected |
| yellow dots | connecting |
| grey circle | not paired yet (no server has run, or no pairing file) |
| red exclamation mark | token rejected; the server rotated it, re-pairs by itself in a moment |
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/chrome-mcp)<a href="https://allmcps.com/mcp/chrome-mcp"><img src="https://allmcps.com/api/badge/chrome-mcp?style=directory" alt="Chrome MCP on AllMCPs" /></a>