Drive your real logged-in browser from any MCP client. Governed or wide open, one portable binary.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Give your agent a visible place in the browser you already use.

A launch brief moves from empty form to ready for review, in full view.
Install Ghostlight | See where it fits | Installation guide | Trust Center
Your agent needs a page you are signed in to. The usual answer is a second, empty browser that knows none of your sessions, driven by a model that has to learn Chrome internals to get anything done.
Ghostlight gives it a tab group inside the Chromium you already have open. The work happens in front of you: watch it, pause it, take the wheel, or end the session. The model says what it wants, and Ghostlight does the browser part.
Ask an agent to read a page, complete a form, handle a file, follow a popup, or investigate a failed web workflow. Ghostlight carries the task across tabs and browser changes while keeping the browser work and its controls on your machine.
A light left burning, so the halls stay safe.
The published release is 1.3. It is available as the GitHub release
v1.3.2, the npm package
ghostlight@1.3.2, the Chrome Web Store adapter v1.0.0 (adapter 1.1.0 is in review), and the
MCP Registry record org.sylin/ghostlight 1.3.2, all observed on 2026-09-02 and recorded in
docs/public-status.json.
You need Chrome, Edge, Brave, or Chromium 116+, an MCP client, and Node.js for the installer. The service you run afterward is native Rust.
Install Ghostlight and register the MCP clients it finds:
Add Ghostlight in Browser from the Chrome Web Store.
Restart an MCP client if it does not hot-reload tools.
Give it one small, read-only task:
Open https://example.com/ in a new Ghostlight tab, summarize the page, and tell me which tab you used. Do not click, type, submit, or change the page.
A sky-blue Ghostlight group should appear in your browser. The agent opens the page, reads it, and names the exact tab it used. That one prompt proves the whole connection without authorizing a click or write. Next time, it reuses that group and the nearest tab it already owns on that site, so repeated work stops littering your tab strip.
If a step needs attention, run:
doctor checks the client entry, local service, browser connection, and extension, then names the
next action. The installation guide covers targeted clients, source
builds, updates, uninstall, and symptom-led recovery.
Ghostlight is at its best when browser work has a thread to follow:
Use the same browser capability from Codex, Claude Code, Claude Desktop, Cursor, VS Code, Windsurf, Zed, OpenCode, Crush, or another compatible stdio MCP client. Agents receive structured page reads, exact element references, bounded action receipts, and specific recovery guidance. They can ask the policy tool to explain the authority in force at any moment.
Ghostlight works in a dedicated sky-blue tab group inside the browser window you chose. Page scans, clicks, typing, drags, and longer phases share one visual language, so the movement on screen has an explanation.
Pause the workspace, take over for a delicate step, or stop it. Move its tabs where you want them; Ghostlight follows the workspace instead of snapping it back. Ordinary tabs remain outside the agent's owned set.
Closing a tab needs two independent yes votes: the orchestrator's authority, and the browser's own preserve-tabs setting, which ships on. That keeps the evidence of what happened in front of you. Closing a tab yourself always works.
Personal use is complete without a policy manifest. Start with the full browser engine and get
useful work done. When a workflow needs stronger boundaries, grant read, action, write, and
execute capabilities by MCP identity and domain. Add sacred domains, dry-run preflight, and
structured audit while the browser experience stays the same. The
governance guide shows the operating model, and the
Trust Center carries the security, privacy, continuity, deployment, and
procurement evidence.
With no policy configured, HTTP(S) browsing is allowed, including localhost, loopback, and link-local destinations. Host restrictions belong to policy. Non-HTTP schemes, credential fields, and stale handles stay protected. Optional local and managed policy layers can only take capability away, and per-request restrictions narrow things further. Nothing hands access back.
Credential-class fields come to you. Ghostlight does not type secrets.
The audit record holds identifiers, decisions, and content-minimized measurements: which tool ran,
whether authority allowed it, how long it took, and what it did -- 3 fields, 1,240 words, 1280x720.
The site an action landed on is named, because that answers where your agent went and is already in
your own tab strip. Paths, queries, fragments, page text, field values, screenshots, selectors, and
dialog text never enter it. docs/guides/siem-integration.md is
the exact record shape.
The full catalog is in docs/1.0/LANGUAGE.md, and the exact policy schema
is in docs/guides/governance-configuration.md.
Open the tray icon and you land At a glance: the action running right now in full, finished actions stacking below it, newest first, each in Ghostlight's own words -- "Opened example.com.", "Read 1,240 words.", "Filled 3 fields and submitted the form." -- never the page's. Beside it sit MCP integrations, which connects the coding clients you already have and merges into their configuration with a backup; Status, which answers whether the stack is healthy; Policy, which states what the current rules allow, one plain line per capability, naming the layer that decided each one; and About, which carries the promise underneath it: it never phones home.
Pause and resume sit in the header beside the lamp, the same control the tray offers. Closing the window returns it to the tray and leaves the authority running. If the desktop shell cannot start, Ghostlight exits instead of leaving an invisible authority.
Rust 1.82 or newer, plus Chromium 116 or newer for browser validation.
Three executables land side by side:
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/ghostlight)<a href="https://allmcps.com/mcp/ghostlight"><img src="https://allmcps.com/api/badge/ghostlight?style=directory" alt="Ghostlight on AllMCPs" /></a>