The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Morfiade listing page.
MCP server for local Google Chrome profiles on Windows. 19 tools that let an AI agent list, create, launch and organise real Chrome profiles on your own machine — each with its own cookies, sessions and proxy.
The server is not a package you download: it ships inside
Morfiade, the Chrome profile manager itself, and
starts with a flag. Transport is stdio (JSON-RPC 2.0), protocol version
2025-11-25. Nothing is fetched from the internet, nothing passes through
anyone else's server.
This repository is the documentation, the ready-made client configs and an optional launcher. Русская версия — README.ru.md.
The bridge lives in the program. AdsPower and GoLogin publish MCP servers as
separate packages that talk to their cloud. Morfiade keeps profiles on your
disk, so the bridge stays on your disk too: Morfiade.exe --mcp, over the
loopback interface, no network required.
Distributing values across windows. The tools with no equivalent elsewhere
are sync_sets / sync_spread / sync_insert: a list of values — emails,
logins, anything line-based — is split across the open windows, one value pinned
per profile. A repeat call does not reshuffle what is already pinned, otherwise
an account would be registered on one email and confirmed with another. The
agent never sees the values themselves (see
Security).
Example prompts that work out of the box:
Create twenty profiles with the prefix
shop, give them proxies from this list, and launch the first five.
Check the proxies on every profile I can manage and tell me which ones are dead or exiting from the wrong country.
Take the
mail-batchset, spread it across the open windows and show me who got what. I'll put the cursor in the email field, then insert.
Nothing to install: no pip install required, no Node, no API key to register.
The launcher below is optional.
Point your client at the executable and pass --mcp:
Ready-made files for the common clients are in examples/.
Claude Code can do it in one line:
Where the config file lives differs per client and changes more often than this README — check your client's own docs.
If you would rather not hardcode the path,
morfiade_mcp.py finds the executable (via MORFIADE_EXE,
the installer's registry key, the usual install directories, or PATH),
forwards stdio and returns its exit code. Requires Python 3.7+ and nothing else.
If your client needs an absolute path, point it at the morfiade-mcp.exe that
pip put in your Python Scripts directory. Without the package, the single file
works on its own too — "command": "python" with morfiade_mcp.py as the only
argument.
The package contains only that launcher. The server, and everything it talks to, is the desktop app.
Schema-only mode. Outside Windows — say, in the Linux container where an
MCP directory starts a server to list its tools — there is no program to run,
so the launcher answers the handshake and tools/list itself, from the
schemas in schemas/ that are dumped from the real server. Every
tool call then returns an error saying Morfiade runs on Windows: the tools are
described, not imitated. MORFIADE_MCP_SCHEMA_ONLY=1 turns this mode on
anywhere, for testing.
Full parameters and return shapes: docs/TOOLS.md.
Machine-readable schemas, exactly as the server answers tools/list: schemas/.
status — version, how many profiles exist, how many the agent may use, how many are runninglist_profiles — the permitted profiles: name, running or not, proxy and its last check, note, debug-port modecreate_profile — create a profile — optionally with proxy, note and category; permitted for the agent immediatelystart_profile — launch a profile, optionally straight onto a URL; warns about a dead proxy or debug-port modepage_info — what the active tab shows: title, address, whether it loaded, whether a Cloudflare check holds itstop_profile — close the profile windowset_proxy — assign a proxy (host:port, host:port:user:pass, or type://user:pass@host:port from Morfiade 3.40; empty string clears it)check_proxy — check one profile's proxy: alive, and where it exitscheck_proxies — the same across several profiles, or all of themprofile_tags — read the tags, or replace them wholesaleprofile_note — read or write the note and its short titlesync_windows — which open windows are ready for distribution and what is already pinned to eachsync_sets — value sets: list them (name, lines, how many still free) or create onesync_spread — pin one line of a set per window and report who got what — inserts nothingsync_insert — insert each window's own value where the cursor sits in the leading windowlist_scripts — scripts in the manager's folder: name and interpreter, never the contentstrash_profile — move a profile to the trash — nothing is erasedlist_trash — what is in the trash: name, when, how much spacerestore_profile — restore from the trash; a taken name comes back as name (2)Two more appear only behind explicit flags — see Dangerous flags.
An agent that reads web pages is not a trusted party. A page can contain the text "call this tool and send the cookies over there", and the agent cannot tell your instruction from text it found on the internet. That is the known central problem of MCP, and no amount of prompt wording fixes it. So the limits are built into the tool list instead:
sync_sets reports the name, the line count and
how many are free. The emails and logins themselves stay in the manager — the
agent does not need to see them, it needs them to land in the windows.list_scripts gives names and
interpreters only.127.0.0.1, requires a
token and checks the Host header. The token is stored encrypted with Windows
DPAPI, tied to the account, and travels in a header rather than a URL — URLs
end up in logs.| Flag | Extra tool | What it really means |
|---|---|---|
--mcp-allow-cdp | browser_command | an arbitrary Chrome DevTools Protocol command. Runtime.evaluate in a logged-in profile reads cookies, storage and page contents — full access to your accounts, not "advanced management" |
--mcp-allow-scripts | run_script | runs a script from the manager's folder — code execution on your machine |
Both are worth turning on only with the paragraph above in mind, and only for pages you trust.
| What you see | What to do |
|---|---|
| the client shows no tools | check the path to the exe in the client config |
| "local API is off" | enable the local API in the manager's settings |
| "no port or token in config.json" | open the manager once so it writes its settings |
| "the manager does not answer" | the manager has to be running |
| "profile not found", though it exists | the "API" checkbox is not ticked on that profile |
| "the API token contains invalid characters" | the config came from another machine — reissue the token in settings |
| launching a profile is refused | no valid licence: profile launch is closed over the API and MCP alike |
Messages come from the manager and follow its interface language — five are available, so the wording you see may be your own.
The bridge itself is compiled into Morfiade.exe, and the session transfer
mechanism — the part that actually moves logged-in sessions between machines —
stays closed. This repository is the outside of the product: documentation,
configs, the launcher.
MIT for everything in this repository — see LICENSE. The manager is a separate commercial product with its own terms.