NeoBrowser: An MCP server that drives real Chrome with your logged-in sessions
pitiflautico
33 points
29 comments
August 18, 2026
Related Discussions
Found 5 related stories in 40.5ms across 4,128 title embeddings via pgvector HNSW
- Show HN: Browser Tools SDK – an optimal browser harness for agents tanishqkanc · 11 pts · July 21, 2026 · 56% similar
- Brow6el: A full-featured web browser for the terminal using Chromium nerdypepper · 45 pts · July 23, 2026 · 55% similar
- Show HN: Watching browser fingerprinting calls via Chromium's Blink layer brnbs · 11 pts · August 10, 2026 · 55% similar
- Show HN: An MCP server that turns async-work practices into tools benbalter · 17 pts · July 21, 2026 · 51% similar
- Orion Browser by Kagi sebjones · 138 pts · July 19, 2026 · 49% similar
Discussion Highlights (12 comments)
pitiflautico
I built NeoBrowser because every browser MCP I tried had the same failure mode: it launches a fresh, fingerprintable headless browser with no cookies, so the model hits login walls and bot checks constantly. NeoBrowser drives the real Google Chrome binary over CDP and can reuse your actual logged-in profile, so the model lands already authenticated and looks like a genuine user — because it is one. What's different: - Real sessions: optionally decrypts + injects cookies from your real Chrome profile (macOS Keychain / Linux secret-service / Windows DPAPI). Opt-in; session-identity cookies are excluded so your real browser isn't logged out. - Genuine stealth, not spoofing: real UA matching its Client Hints, real GPU WebGL, navigator.webdriver gone. Passes bot.sannysoft live in CI. It doesn't pretend to beat interactive challenges — reCAPTCHA/Turnstile can still wall you — instead it detects the wall and tells the model how to react. - Human-like input: clicks travel along an eased, jittered path; typing can be per-key with realistic timing. - One ~5 MB static Rust binary, 43 tools (multi-tab, forms, upload/download, search, playbooks), zero runtime deps. I also ran a neutral benchmark against Playwright MCP with a shared task matrix, nothing tuned to make either win. Honest results: Playwright MCP is faster (my headless frame-forcing costs ~2x latency); NeoBrowser passes upload + session persistence tasks Playwright MCP can't, and on adversarial pages both get walled equally. Full methodology in bench/ if you want to poke holes in it — I'd rather be called out than overclaim. Repo: https://github.com/pitiflautico/neobrowser
Johnny_Bonk
Interesting, I will have to check this out as a lot of what I do everyday involves asking claude and chat go use my signed in profile, I even built a skill for it with some other tools.
nateb2022
https://github.com/browser-use/browser-use has been great so far
Icingdeath
When I need an coding agent to interact with an existing session I just use /Applications/Google\ Chrome.app/Contents/MacOS/Google\ Chrome --remote-debugging-port=9222 --user-data-dir=/tmp/chrome-profile-stable and tell it
billylo
This pattern of using original source code and rewrite to improve them (and get rid of technical debt) is very real. I did one for an old app in Objective C, move it to Flutter and said goodbye to my old //TODOs. And get an Android build as a bonus. :-)
dbbk
Doesn't Claude already do this?
dmix
I use BrowserOS for this, which is also a yc company The fingerprint and mouse thing is interesting though
nater5000
>It doesn't pretend to be invisible: when a site throws an interactive challenge (reCAPTCHA, Turnstile) NeoBrowser detects it and hands control back with a real-session or human path — that honesty is what makes it dependable. Maybe it's just me, but if you can't be bothered to clean up your vibecoded README, I'm going to assume I'd be better off just vibecoding my own version of this solution.
dongkeren
I am wondering how it solves the security issues: I saw opt-in, file permissions and SSRF in README, but I do not see: domain allowlist; human approval before submiting/deleting; persistent audit record after operations; how to revoke a previously granted access; The prompt injection may also induce the agent to perform write operations. Reuse the real user-login session also delegate the user's full authority to the agent, which obviously has potential security issues. The point is, the more real authority the agent has, the more important the responsibility the agent must take, which I think should be designed in from the beginning.
npodbielski
It spits out password in logs according to gif. No thank you.
cute_boi
Another vibe coded slop. Claude and codex can attach to real chrome without any issue.
andreidbr
I've been using the Chrome CDP skill for Claude Code with great success for test automation purposes (locator detection, troubleshooting mobile layout, and so on). I found it here on HN: https://github.com/pasky/chrome-cdp-skill I remember seeing another Chromium-based "MCP-focused" browser at that point in time, but I can't remember what it was called.