KernelCAUTION
Open-source MCP server for secure, low-latency cloud-browser automation on Kernel.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://opensource.org/licenses/MIT) [](https://nodejs.org/) [](https://nextjs.org/) [](https://smithery.ai/server/kernel)
A Model Context Protocol (MCP) server that provides AI assistants with secure access to Kernel platform tools and browser automation capabilities.
🌐 Use instantly at https://mcp.onkernel.com/mcp — no installation required!
What is this?
The Kernel MCP Server bridges AI assistants (like Claude, Cursor, fx, or other MCP-compatible tools) with the Kernel platform, enabling them to:
- 🚀 Deploy and manage Kernel apps in the cloud
- 🌐 Launch and control headless Chromium sessions for web automation
- 📊 Monitor deployments and track invocations
- 🔍 Search Kernel documentation and inject context
- 💻 Execute arbitrary Playwright code against live browsers
- 🧠 Run persistent JavaScript Browser REPL cells with native helpers, Patchright, Playwright, and raw CDP
- 🎥 Record MP4 video replays of browser automation
Open-source & fully-managed — the complete codebase is available here, and we run the production instance so you don't need to deploy anything.
The server uses OAuth 2.0 authentication via Clerk to ensure secure access to your Kernel resources. During authorization, users can grant organization-wide access or restrict the resulting access and refresh tokens to one Kernel project. Project-scoped tokens cannot switch projects; organization-wide authorization remains available for existing workflows.
For a deeper dive into why and how we built this server, see our blog post: [Introducing Kernel MCP Server](https://blog.onkernel.
5447a4a5e217OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add kernel-mcp-server --env BRAINTRUST_API_KEY=${BRAINTRUST_API_KEY} --env CLERK_SECRET_KEY=${CLERK_SECRET_KEY} --env MANAGED_AUTH_APP_ORIGIN=${MANAGED_AUTH_APP_ORIGIN} --env MINTLIFY_ASSISTANT_API_TOKEN=${MINTLIFY_ASSISTANT_API_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"kernel-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"BRAINTRUST_API_KEY": "${BRAINTRUST_API_KEY}",
"CLERK_SECRET_KEY": "${CLERK_SECRET_KEY}",
"MANAGED_AUTH_APP_ORIGIN": "${MANAGED_AUTH_APP_ORIGIN}",
"MINTLIFY_ASSISTANT_API_TOKEN": "${MINTLIFY_ASSISTANT_API_TOKEN}"
}
}
}
}Exposed tools (45)
42 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
api_failure | read | |
authorization_code_org_scoped_pkce | read | PKCE authorization for an organization-wide scope: authorize stores the oauth-request context, the code exchange consumes it and persists jwt/refresh mappings. |
authorization_code_project_scoped_pkce | read | Same as above but the selected scope is a single project, so the persisted context carries project_id. |
begin_auth_login | read | |
browser_curl | read | |
browser_repl | read | |
coded_api_failure | read | |
computer_action | read | |
custom_search | read | Search via CDP |
exec_command | write | |
execute_playwright_code | write | |
get_connection_context | read | |
input_guard | read | |
legacy_non_pkce_client | read | An allowlisted legacy client without PKCE: authorize stores the context under the literal client:<client_id> key, which its exchanges read. |
manage_api_keys | read | |
manage_apps | read | |
manage_auth_connections | read | |
manage_browser_files | read | |
manage_browser_pools | read | |
manage_browsers | read | |
manage_config_registry | read | |
manage_credential_providers | read | |
manage_credentials | read | |
manage_extensions | read | |
manage_playwright_executors | read | |
manage_profiles | read | |
manage_projects | read | |
manage_proxies | read | |
manage_replays | read | |
manage_vault_cards | read | |
manage_vault_credentials | read | |
manage_vault_items | read | |
manage_vault_provider_configs | read | |
manage_vault_wallets | read | |
manage_vaults | read | |
open_auth_login | read | |
ping | read | |
refresh_backfills_clerk_user_id_from_id_token | read | A pre-existing context without clerk_user_id (stored by older versions) is refreshed: the id_token subject is backfilled into the newly written contexts. |
refresh_token_rotation_sliding_ttl | read | An initial org-scoped grant is followed by a refresh_token grant: the old refresh mapping is deleted, the rotated one is written with a fresh sliding TTL. |
search | read | Search |
search_docs | read | |
submit | write | Submit |
title | read | Read title |
web_search | read | |
webmcp | read |
Trust audit
CAUTIONgrade C · trust 77/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (21)
const secret = "private-password-value";
const secret = "private-duplicate-value";
const secret = "secret-sentinel+/configuration";
printf '%s\n' '-----BEGIN PRIVATE KEY-----'
.prettierignore
.semgrepignore
const digest = createHash("sha1")harness_root=$(cd "$(dirname "${BASH_SOURCE[0]}")/../../.." && pwd)new URL("../../../fixtures/mcp-http-server.ts", import.meta.url).pathname,import { name, version } from "../../../server.json";http://127.0.0.1:3002/mcp \
if curl -fsS -X POST http://127.0.0.1:3002/mcp \
"http://127.0.0.1:58432/callback",
"http://127.0.0.1:3000",
return JSON.parse(atob(normalized + padding)) as Record<string, unknown>;
const decoded = atob(authHeader.slice(6));
@clerk/nextjs, @clerk/themes, @types/jsonwebtoken, @types/redis, builtin-modules, install, jose, jsonwebtoken
- `manage_vault_items` - List, get, invoke advertised operations (including fill and `webmcp_invoke` with value-free bindings), observe events, and delete vault items. Read credential definitions, pre
`manage_vault_items` can read existing credential items and invoke advertised `collect`.
the agent-controlled browser; they open it on a device with the 1Password app and
`1pw_update_access_token`, and never returns them. It can read such credentials,
Gates applied: no_behavioural_pass.
5447a4a5e217full audit observations/trust-audit/mcp-server/onkernel__kernel-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 5447a4a5e217 | CAUTION | C | 77 | first audit |
Questions
What is the Kernel MCP server?
Open-source MCP server for secure, low-latency cloud-browser automation on Kernel.
What tools does Kernel expose?
45 in total: 42 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Kernel safe to connect to an agent?
With care. The audit graded it C (77/100) and found 21 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Kernel need?
It reads BRAINTRUST_API_KEY, CLERK_SECRET_KEY, MANAGED_AUTH_APP_ORIGIN, MINTLIFY_ASSISTANT_API_TOKEN, NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY, OAUTH_LEGACY_NON_PKCE_CLIENT_IDS, OAUTH_RECORDING_ALLOW_REMOTE_REDIS, OAUTH_RECORDING_REDIS_URL, POSTHOG_PROJECT_TOKEN, TEST_API_KEY and TEST_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Kernel run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as kernel-mcp-server at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (5447a4a5e217), read on 2026-10-09. The repository is watched and re-audited when it changes.