BrowseraiSAFE
A powerful Model Context Protocol (MCP) server that provides an access to serverless browser for AI agents and apps
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Browserai MCP Empower AI Agents with Real-Time Web Data
🌟 Overview
Welcome to the Browserai Model Context Protocol (MCP) server, designed to enable LLMs, AI agents, and applications to access, discover, and extract web data in real-time. This server empowers MCP clients—such as Claude Desktop, VS Code, Cursor, and WindSurf—to seamlessly search the web, navigate websites, perform actions, and retrieve data efficiently, even from sites with anti-scraping measures.
⚙️ How it Works
The Browserai MCP server functions as an intermediary between your AI agent (the MCP client) and the internet:
- Your AI agent (e.g., Claude Desktop, a VSCode extension) dispatches a request to the Browserai MCP server via the Model Context Protocol.
- The MCP server, utilizing your Browserai API token and project configurations, executes the requested web action (e.g., search, navigate, extract data).
- It leverages Browserai's robust infrastructure to manage complexities such as bypassing geo-restrictions and bot detection mechanisms.
- The server then delivers the structured data or action outcome back to your AI agent.
This architecture allows your agent to access real-time web information and capabilities without the need to directly manage browser instances or anti-blocking technologies.
✨ Features
- Real-Time Web Access: Retrieve up-to-date information directly from the web.
- Bypass Geo-restrictions: Access content without geographical limitations.
- Web Unlocker: Navigate websites protected by bot detection systems.
- Browser Control: Utilize optional remote browser automation capabilities.
- Seamless Integration: Compatible with all MCP-compliant AI assistants.
🔧 Account Setup
To begin using the Browserai MCP server, a Browserai account and API key are required.
- Ensure you have an account on [bro
f2f514e17a15OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add browserai-mcp --env API_TOKEN=${API_TOKEN} -- npx -y @brightdata/[email protected]{
"mcpServers": {
"browserai-mcp": {
"command": "npx",
"args": [
"-y",
"@brightdata/[email protected]"
],
"env": {
"API_TOKEN": "${API_TOKEN}"
}
}
}
}Exposed tools (9)
7 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
batch_actions | write | Execute multiple actions in sequence within a single browser session. |
extract_from_session | read | Extract specific data from the current page in a browser session. |
get_page_info | read | Get comprehensive information about the current page including title, URL, meta tags, and page structure. |
get_session_status | read | Check the current status and information of a browser session. |
interact_and_extract_in_session | read | Interact with elements in an existing browser session. |
list_active_sessions | read | List all currently active browser sessions with their status and basic information. |
navigate_to_url | read | Navigate to a specific URL in an existing browser session. |
start_new_session | write | Start a new browser session. |
wait_for_element | read | Wait for a specific element to appear on the page before proceeding. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (1)
fastmcp, zod
Gates applied: no_behavioural_pass.
f2f514e17a15full audit observations/trust-audit/mcp-server/brightdata__browserai-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | f2f514e17a15 | SAFE | B | 89 | first audit |
Questions
What is the Browserai MCP server?
A powerful Model Context Protocol (MCP) server that provides an access to serverless browser for AI agents and apps
What tools does Browserai expose?
9 in total: 7 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Browserai safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Browserai need?
It reads API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (f2f514e17a15), read on 2026-10-08. The repository is watched and re-audited when it changes.