PluginBench
MCP Server
Active

Oya Browser MCP Server

io.github.OyadotAI/oya-browser

Real Chrome for agents: start a browser, read pages as numbered markdown, click, type, and automate with built-in automation.

What is the Oya Browser MCP server?

The Oya Browser MCP server is a real Chrome browser with automation built inside the process, not attached over a debugging protocol. It lets AI agents start browsers, read pages as numbered markdown, click elements, type text, and record tasks as replayable playbooks. Unlike headless Chrome, Oya maintains session state (cookies and localStorage), imports existing logins, and avoids bot detection.

Oya Browser gives AI agents a real, stealth Chrome instance where automation runs inside the browser process. You can start a browser, navigate to pages, ask questions about content, click and type on elements, and record workflows as playbooks that replay without a model in the loop. It handles logins by importing existing credentials, solves CAPTCHAs and 2FA where possible, and maintains anti-bot evasion through Chrome's native emulation rather than external protocol manipulation.

How to install Oya Browser

Copy-paste configuration for popular MCP clients.

transport: http
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • Authorization
    required
    secret

    Your Oya API key from oyabrowser.com, sent as a bearer token

~/.cursor/mcp.json
{
  "mcpServers": {
    "oya-browser": {
      "url": "https://oyabrowser.com/mcp/pool"
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • browser.start() — Start a real Chrome browser instance for the session
  • browser.goto() — Navigate to a URL
  • browser.ask() — Ask the agent to read the page and answer a question
  • browser.analyze() — Get page content as numbered markdown and clickable elements
  • browser.click() — Click an element by number or selector
  • browser.type() — Type text into a field
  • browser.toPlaybook() — Save a recorded task as a replayable playbook
  • replay.play() — Replay a saved playbook with new variable inputs, no model required
  • desktop.connect() — Connect to the Oya desktop app to use an existing signed-in browser
  • playbooks.export() / import() — Export and import playbooks to move them between environments

Use cases

  • Automate multi-step web tasks (form filling, data entry, account management) with logins that persist across browser sessions
  • Record a workflow once and replay it indefinitely with different inputs, eliminating repeated model calls
  • Scrape and summarize web content by asking the browser questions about page structure and content
  • Bypass bot detection on sites that flag headless Chrome by using a real browser with native emulation
  • Integrate browser automation into AI agent workflows without external debugging protocol overhead

Oya Browser MCP server FAQ

What is the Oya Browser MCP server?

Oya Browser is an MCP server that gives AI agents access to a real Chrome browser with automation built into the process. Unlike headless Chrome driven over a debugging protocol, Oya runs automation inside the browser, maintains session state, imports logins, and avoids bot detection.

Is Oya Browser free?

The SDK and CLI are MIT-licensed and free. Self-hosting is free up to 5 cloud browsers running at once. Beyond that or for serious production use, you need a license key from sales@getoya.ai. Oya Cloud is available at oyabrowser.com.

How do I install Oya Browser in Claude or Cursor?

In Claude Code or Cursor, run: `claude mcp add --transport http oya https://oyabrowser.com/mcp/pool --header "Authorization: Bearer $OYA_API_KEY"`. Get your API key from oyabrowser.com. Then ask the agent to start a browser and perform tasks.

Do I need to set up authentication?

Set the `OYA_API_KEY` environment variable from oyabrowser.com, or let your agent sign itself up. For desktop use, the desktop app imports logins from Chrome, Arc, Brave, Edge, or Firefox so every browser you start is already signed in.

Can Oya replay tasks without calling the model every time?

Yes. Use `browser.toPlaybook()` to save a recorded task, then `replay.play()` to run it again with new inputs. Nine of ten public sites replay every step with no model. If a page changes, the agent fixes the broken steps and the next replay runs clean.

Does Oya get detected as a bot?

Oya uses Chrome's native emulation (platform, timezone, locale, screen) and isolated worlds for reading, avoiding known detection vectors. Measured results show 0% CreepJS headless score and 31/31 on Bot.Sannysoft tests, though no tool can guarantee zero detection.

README (reference)

Source of truth, from the repository.

<p align="center"> <img src="assets/oya-banner.svg" alt="Oya Browser: the automation lives inside the browser, not attached to it" width="100%"> </p> <h3 align="center">Everyone else drives Chrome from the outside. We built the browser.</h3> <p align="center"> The automation lives inside it, not attached over the debugging protocol, so your agents stop<br> looking like a harness. Sign in once and every browser you start is already signed in.<br> Do the task once and Oya replays it forever, with no model in the loop. </p> <p align="center"> <a href="https://github.com/OyadotAI/oya-browser/actions/workflows/deploy-dev.yaml"><img src="https://img.shields.io/github/actions/workflow/status/OyadotAI/oya-browser/deploy-dev.yaml?branch=main&label=build&logo=github" alt="Build"></a> <a href="https://codecov.io/gh/OyadotAI/oya-browser"><img src="https://img.shields.io/codecov/c/github/OyadotAI/oya-browser?label=coverage&logo=codecov" alt="Coverage"></a> <a href="https://github.com/OyadotAI/oya-browser/releases/latest"><img src="https://img.shields.io/github/v/release/OyadotAI/oya-browser?label=release&color=39ed35" alt="Latest release"></a> <a href="https://www.npmjs.com/package/@oya-ai/browser"><img src="https://img.shields.io/npm/v/@oya-ai/browser?color=39ed35&label=@oya-ai/browser&logo=npm" alt="npm: @oya-ai/browser"></a> <a href="https://www.npmjs.com/package/@oya-ai/browser"><img src="https://img.shields.io/npm/dm/@oya-ai/browser?label=downloads" alt="npm downloads"></a> <br> <a href="https://www.npmjs.com/package/@oya-ai/browser"><img src="https://img.shields.io/npm/types/@oya-ai/browser" alt="TypeScript types included"></a> <a href="https://www.npmjs.com/package/@oya-ai/browser"><img src="https://img.shields.io/node/v/@oya-ai/browser" alt="Node version"></a> <a href="LICENSE.md"><img src="https://img.shields.io/badge/license-Sustainable_Use_%2B_MIT_SDK-157a13" alt="License"></a> <a href="https://github.com/OyadotAI/oya-browser/stargazers"><img src="https://img.shields.io/github/stars/OyadotAI/oya-browser?logo=github" alt="GitHub stars"></a> <a href="https://oyabrowser.com"><img src="https://img.shields.io/badge/hosted-oyabrowser.com-141410?logo=googlechrome&logoColor=39ed35" alt="Hosted"></a> <a href="https://discord.gg/wqSeXJPygn"><img src="https://img.shields.io/badge/Discord-join-5865F2?logo=discord&logoColor=white" alt="Discord"></a> </p> <p align="center"> <a href="https://discord.gg/wqSeXJPygn">Join the Discord</a> · <a href="https://calendly.com/d/dvrm-r65-kkx/oya-founder-call">Talk to the founders</a> </p>

Start

npm i @oya-ai/browser
import { Oya } from "@oya-ai/browser";

const browser = await new Oya().browser.start();     // real Chrome, yours for the session
await browser.goto("https://news.ycombinator.com");
console.log(await browser.ask("What are the top 3 stories?"));
await browser.stop();
DONE: The top 3 stories on Hacker News are:
1. Google's Open Agentic Orchestrator
2. Samsung is expected to more than double output of its HBM4 and HBM4E DRAM
3. What happened to the Snowden archive

Set OYA_API_KEY from oyabrowser.com, or let your agent sign itself up (below). Node 20+.

No provider set up yet? Open the desktop browser on the same key and start() hands that one over, so those five lines work with nothing else configured. npx @oya-ai/cli init picks where browsers run when you want it to start them.

For AI agents

Are you an AI agent (OpenClaw, Hermes, Claude Code, Codex, Cursor or any other) looking for a browser? Everything below works with no person at a dashboard. Full reference, written for you: oyabrowser.com/llms.txt.

As a skill, for any agent that reads SKILL.md:

npx skills add OyadotAI/oya-browser

In code (Node 22.3+). Sign yourself up with your person's email, then use their own browser, already signed in to their sites:

import { Oya } from "@oya-ai/browser";

await Oya.signup({ email: "person@example.com" });   // your own key, saved to ~/.oya/config.json
const browser = await new Oya().desktop.connect();   // pairs the Oya desktop app, imports their logins
await browser.goto("https://example.com");
const { markdown, elements } = await browser.analyze();

desktop.connect() asks your person to install the desktop app if it is missing, and to click Connect when it opens.

Over MCP, for tools that cannot run code (Claude Desktop, Cursor, Windsurf and the rest): https://oyabrowser.com/mcp/pool with Authorization: Bearer <key>. In Claude Code:

claude mcp add --transport http oya https://oyabrowser.com/mcp/pool \
  --header "Authorization: Bearer $OYA_API_KEY"

Then just ask: "Start a browser, open Hacker News and summarise the top 3 stories." Oya is in the MCP registry as io.github.OyadotAI/oya-browser, on Smithery and on ClawHub as oya-browser.

Record it once, replay it forever

ask() costs a model call every time. Save the run and it never costs one again.

await browser.ask("Log in with {{user}} and {{pass}}. Open New Request for {{name}}.",
  { data: { name: "Alex Example" }, secrets: { user, pass } });
await browser.toPlaybook("new-request");             // the steps it just took

await replay.play("new-request", { name: "Sam Example", user, pass });   // no model, new inputs

Nine of ten public sites replay every recorded step with no model and no repair. The tenth is named, with its error. When a page really has changed, the agent finishes the run and its fix replaces the broken steps, so the next replay runs clean. A replay that meets a login signs in with the profile's saved credentials and carries on.

Values you gave in the prompt become variables. A free-text field the agent wrote itself, a comment or the answer to a question, is written fresh by your model on every replay instead of repeating the first run's words. Every playbook is also a Playwright module you can read and keep:

export default async function run(page, vars = {}, oya) {
  await page.getByLabel("Customer name:").first().fill(`${vars["custname"]}`);
  await page.getByLabel("Delivery instructions:").first().fill(vars["comments"] ?? (await oya.llm.answer("Delivery instructions:", vars)));
}

Move one to another environment with oya.playbooks.export(name) and oya.playbooks.import(doc), oya playbooks export|import on the command line, or Export and Import in the dashboard.

Sign in once

Scripted logins break on Google SSO, Okta, passkeys and Cloudflare. Don't script them. Import the logins you already have from Chrome, Arc, Brave, Edge or Firefox when you connect the desktop app, or sign in by hand once in it. Every browser you start on that persona is then already signed in: the session travels as cookies and localStorage, sealed at rest, because half the portals worth automating keep you signed in with neither one alone. Every way in and out.

For the portals that end the session server-side anyway, store the login and Oya signs in itself, and stops rather than retrying a password the site has already refused, because that is how a real account gets locked out.

Why it isn't flagged as a bot

Everyone else ships an SDK that drives headless Chrome over the debugging protocol. That is the easy way, and it is the shape anti-bot vendors have learned to look for. Oya is a real headful browser a person can sit in front of, and the automation runs inside the process:

  • The persona's platform, timezone, locale, cores and screen are set through Chrome's own emulation before the first document, and again in workers and cross-site iframes. A value Chrome reports about itself cannot be caught lying.
  • Reading a page uses an isolated world, so it needs no Runtime.enable, which is a known detection vector. Replay never turns it on.
  • Console and network come from browser-process APIs, not the Log and Network domains, so watching a run adds nothing a page can see.

Measured, not asserted: 0% CreepJS headless score (bare headless Chrome: 100%) and 31 of 31 Bot.Sannysoft, re-run on 2026-09-20. Nobody can promise you are never detected (our own numbers page says so), but you can run the harness yourself and see what it says.

Self-host

curl -fsSL https://raw.githubusercontent.com/OyadotAI/oya-browser/main/install.sh | sh

It checks for git, Docker and Node 20+, asks six questions, then clones, writes the config, builds and waits for /readyz. Storage is SQLite (the default), Postgres or JSON files; browsers run on Docker, Kubernetes or your own machines. For production, deployments/ deploys the control plane and its browsers to one Docker host, Amazon ECS on Fargate, any Kubernetes cluster, or GKE Autopilot, with one deploy.sh each.

Self-hosting is free up to 5 cloud browsers running at once. Past that, or if you are using it seriously, write to sales@getoya.ai for a license key (OYA_LICENSE_KEY). A self-hosted server sends Oya one anonymous ping a day (a random install id, the version and browser counts, nothing about your users or pages); see telemetry.

<p align="center"> <img src="assets/oya-demo.gif" alt="The Oya browser: a task asked in plain language, answered, and kept as a playbook" width="100%"> </p> <p align="center"><sub>The browser itself, filmed in real time: a task asked in the Ask pane, the answer, and the run kept as a playbook. The green boxes are the page as the agent reads it: every element it can act on, numbered. <a href="assets/oya-demo.mp4">The four-minute version</a> goes on to LinkedIn already signed in, Amazon, and a login it completes by itself (subtitles included).</sub></p>

The rest

CAPTCHA and 2FASolved where they can be, handed to a person where they can't
Record it yourselfThe desktop recorder keeps a draft you edit step by step, validate in fresh tabs and save as a playbook (how)
RoutinesSaved prompts the desktop agent runs every N minutes or daily at a set time, with each run's steps and answer kept
It proves what it didA hash-chained audit trail the database won't let you rewrite, host allow-listing, regenerable evidence
It isn't one vendorOya Cloud, Browserbase, Steel, Anchor, Browser Use or your own Chrome (why)
It keeps your toolsEvery browser has a cdpUrl, so Playwright and Puppeteer connect unchanged
Full docsSDK · CLI · self-hosting · deployments · moving logins · examples · oyabrowser.com/docs · for agents

Packages

Package
@oya-ai/browserTypeScript SDK. ESM and CJS, typed, zero runtime dependencies.
@oya-ai/cliThe fleet, the live view, the installer.
server · ui · browserControl plane, console, and the browser itself.
skills/oya-browserThe agent skill: npx skills add OyadotAI/oya-browser.
deploymentsProduction deploys: Docker, ECS, Kubernetes, GKE.
npm test                 # server, CLI and packages; ui and browser run their own (see AGENTS.md)
cd server && npm run stealth -- --live   # the stealth numbers, on your machine

License

The SDK and CLI are MIT. Embed them in commercial agents. Everything else is source-available under the Sustainable Use License: free for internal business use, research and non-commercial use, self-hosted up to 5 cloud browsers at once. Beyond that, write to sales@getoya.ai.

Related MCP servers

MCP server giving AI agents access to 40+ APIs: geo, crypto, screenshots, DNS, and more

View repository →
SCscrapewright logo

Give it a URL, get structured rows. A model writes the parser once; replays are free.

1
Python
MIT
View repository →
EVEverThread logo

Plain-English website security check for agents: certificate, headers, scripts, forms, spam.

0
JavaScript
MIT
View repository →
POpolymnemo logo

polymnemo

Active

Shared cross-LLM long-term memory over MCP: semantic recall, sessions, and media (pgvector).

0
Python
MIT
View repository →

Async MCP server for ArangoDB: 46 tools for graphs, queries, and multi-tenancy.

3
Python
Apache-2.0
View repository →

Search Korean job postings from JobKorea and Saramin by company name

0
JavaScript
MIT
View repository →