Oya Browser MCP Server
io.github.OyadotAI/oya-browser
Real Chrome for agents: start a browser, read pages as numbered markdown, click, type, and automate with built-in automation.
What is the Oya Browser MCP server?
The Oya Browser MCP server is a real Chrome browser with automation built inside the process, not attached over a debugging protocol. It lets AI agents start browsers, read pages as numbered markdown, click elements, type text, and record tasks as replayable playbooks. Unlike headless Chrome, Oya maintains session state (cookies and localStorage), imports existing logins, and avoids bot detection.
Oya Browser gives AI agents a real, stealth Chrome instance where automation runs inside the browser process. You can start a browser, navigate to pages, ask questions about content, click and type on elements, and record workflows as playbooks that replay without a model in the loop. It handles logins by importing existing credentials, solves CAPTCHAs and 2FA where possible, and maintains anti-bot evasion through Chrome's native emulation rather than external protocol manipulation.
How to install Oya Browser
Copy-paste configuration for popular MCP clients.
AuthorizationrequiredsecretYour Oya API key from oyabrowser.com, sent as a bearer token
Tools & capabilities
Tools this server exposes to the agent.
browser.start()— Start a real Chrome browser instance for the sessionbrowser.goto()— Navigate to a URLbrowser.ask()— Ask the agent to read the page and answer a questionbrowser.analyze()— Get page content as numbered markdown and clickable elementsbrowser.click()— Click an element by number or selectorbrowser.type()— Type text into a fieldbrowser.toPlaybook()— Save a recorded task as a replayable playbookreplay.play()— Replay a saved playbook with new variable inputs, no model requireddesktop.connect()— Connect to the Oya desktop app to use an existing signed-in browserplaybooks.export() / import()— Export and import playbooks to move them between environments
Use cases
- Automate multi-step web tasks (form filling, data entry, account management) with logins that persist across browser sessions
- Record a workflow once and replay it indefinitely with different inputs, eliminating repeated model calls
- Scrape and summarize web content by asking the browser questions about page structure and content
- Bypass bot detection on sites that flag headless Chrome by using a real browser with native emulation
- Integrate browser automation into AI agent workflows without external debugging protocol overhead
Oya Browser MCP server FAQ
Oya Browser is an MCP server that gives AI agents access to a real Chrome browser with automation built into the process. Unlike headless Chrome driven over a debugging protocol, Oya runs automation inside the browser, maintains session state, imports logins, and avoids bot detection.
The SDK and CLI are MIT-licensed and free. Self-hosting is free up to 5 cloud browsers running at once. Beyond that or for serious production use, you need a license key from sales@getoya.ai. Oya Cloud is available at oyabrowser.com.
In Claude Code or Cursor, run: `claude mcp add --transport http oya https://oyabrowser.com/mcp/pool --header "Authorization: Bearer $OYA_API_KEY"`. Get your API key from oyabrowser.com. Then ask the agent to start a browser and perform tasks.
Set the `OYA_API_KEY` environment variable from oyabrowser.com, or let your agent sign itself up. For desktop use, the desktop app imports logins from Chrome, Arc, Brave, Edge, or Firefox so every browser you start is already signed in.
Yes. Use `browser.toPlaybook()` to save a recorded task, then `replay.play()` to run it again with new inputs. Nine of ten public sites replay every step with no model. If a page changes, the agent fixes the broken steps and the next replay runs clean.
Oya uses Chrome's native emulation (platform, timezone, locale, screen) and isolated worlds for reading, avoiding known detection vectors. Measured results show 0% CreepJS headless score and 31/31 on Bot.Sannysoft tests, though no tool can guarantee zero detection.
README (reference)
Source of truth, from the repository.
Start
npm i @oya-ai/browser
import { Oya } from "@oya-ai/browser";
const browser = await new Oya().browser.start(); // real Chrome, yours for the session
await browser.goto("https://news.ycombinator.com");
console.log(await browser.ask("What are the top 3 stories?"));
await browser.stop();
DONE: The top 3 stories on Hacker News are:
1. Google's Open Agentic Orchestrator
2. Samsung is expected to more than double output of its HBM4 and HBM4E DRAM
3. What happened to the Snowden archive
Set OYA_API_KEY from oyabrowser.com, or let your agent sign itself up
(below). Node 20+.
No provider set up yet? Open the desktop browser on the same
key and start() hands that one over, so those five lines work with nothing else
configured. npx @oya-ai/cli init picks where browsers run when you want it to start them.
For AI agents
Are you an AI agent (OpenClaw, Hermes, Claude Code, Codex, Cursor or any other) looking for a browser? Everything below works with no person at a dashboard. Full reference, written for you: oyabrowser.com/llms.txt.
As a skill, for any agent that reads SKILL.md:
npx skills add OyadotAI/oya-browser
In code (Node 22.3+). Sign yourself up with your person's email, then use their own browser, already signed in to their sites:
import { Oya } from "@oya-ai/browser";
await Oya.signup({ email: "person@example.com" }); // your own key, saved to ~/.oya/config.json
const browser = await new Oya().desktop.connect(); // pairs the Oya desktop app, imports their logins
await browser.goto("https://example.com");
const { markdown, elements } = await browser.analyze();
desktop.connect() asks your person to install the desktop app
if it is missing, and to click Connect when it opens.
Over MCP, for tools that cannot run code (Claude Desktop, Cursor, Windsurf and the rest):
https://oyabrowser.com/mcp/pool with Authorization: Bearer <key>. In Claude Code:
claude mcp add --transport http oya https://oyabrowser.com/mcp/pool \
--header "Authorization: Bearer $OYA_API_KEY"
Then just ask: "Start a browser, open Hacker News and summarise the top 3 stories." Oya is in
the MCP registry as io.github.OyadotAI/oya-browser, on Smithery
and on ClawHub as oya-browser.
Record it once, replay it forever
ask() costs a model call every time. Save the run and it never costs one again.
await browser.ask("Log in with {{user}} and {{pass}}. Open New Request for {{name}}.",
{ data: { name: "Alex Example" }, secrets: { user, pass } });
await browser.toPlaybook("new-request"); // the steps it just took
await replay.play("new-request", { name: "Sam Example", user, pass }); // no model, new inputs
Nine of ten public sites replay every recorded step with no model and no repair. The tenth is named, with its error. When a page really has changed, the agent finishes the run and its fix replaces the broken steps, so the next replay runs clean. A replay that meets a login signs in with the profile's saved credentials and carries on.
Values you gave in the prompt become variables. A free-text field the agent wrote itself, a comment or the answer to a question, is written fresh by your model on every replay instead of repeating the first run's words. Every playbook is also a Playwright module you can read and keep:
export default async function run(page, vars = {}, oya) {
await page.getByLabel("Customer name:").first().fill(`${vars["custname"]}`);
await page.getByLabel("Delivery instructions:").first().fill(vars["comments"] ?? (await oya.llm.answer("Delivery instructions:", vars)));
}
Move one to another environment with oya.playbooks.export(name) and oya.playbooks.import(doc),
oya playbooks export|import on the command line, or Export and Import in the dashboard.
Sign in once
Scripted logins break on Google SSO, Okta, passkeys and Cloudflare. Don't script them. Import the logins you already have from Chrome, Arc, Brave, Edge or Firefox when you connect the desktop app, or sign in by hand once in it. Every browser you start on that persona is then already signed in: the session travels as cookies and localStorage, sealed at rest, because half the portals worth automating keep you signed in with neither one alone. Every way in and out.
For the portals that end the session server-side anyway, store the login and Oya signs in itself, and stops rather than retrying a password the site has already refused, because that is how a real account gets locked out.
Why it isn't flagged as a bot
Everyone else ships an SDK that drives headless Chrome over the debugging protocol. That is the easy way, and it is the shape anti-bot vendors have learned to look for. Oya is a real headful browser a person can sit in front of, and the automation runs inside the process:
- The persona's platform, timezone, locale, cores and screen are set through Chrome's own emulation before the first document, and again in workers and cross-site iframes. A value Chrome reports about itself cannot be caught lying.
- Reading a page uses an isolated world, so it needs no
Runtime.enable, which is a known detection vector. Replay never turns it on. - Console and network come from browser-process APIs, not the
LogandNetworkdomains, so watching a run adds nothing a page can see.
Measured, not asserted: 0% CreepJS headless score (bare headless Chrome: 100%) and 31 of 31 Bot.Sannysoft, re-run on 2026-09-20. Nobody can promise you are never detected (our own numbers page says so), but you can run the harness yourself and see what it says.
Self-host
curl -fsSL https://raw.githubusercontent.com/OyadotAI/oya-browser/main/install.sh | sh
It checks for git, Docker and Node 20+, asks six questions, then clones, writes the config, builds and waits for /readyz.
Storage is SQLite (the default), Postgres or JSON files; browsers run on Docker, Kubernetes or your
own machines. For production, deployments/ deploys the control plane and its
browsers to one Docker host, Amazon ECS on Fargate, any Kubernetes cluster, or GKE Autopilot, with
one deploy.sh each.
Self-hosting is free up to 5 cloud browsers running at once. Past that, or if you are using it
seriously, write to sales@getoya.ai for a license key (OYA_LICENSE_KEY). A self-hosted server
sends Oya one anonymous ping a day (a random install id, the version and browser counts, nothing
about your users or pages); see telemetry.
The rest
| CAPTCHA and 2FA | Solved where they can be, handed to a person where they can't |
| Record it yourself | The desktop recorder keeps a draft you edit step by step, validate in fresh tabs and save as a playbook (how) |
| Routines | Saved prompts the desktop agent runs every N minutes or daily at a set time, with each run's steps and answer kept |
| It proves what it did | A hash-chained audit trail the database won't let you rewrite, host allow-listing, regenerable evidence |
| It isn't one vendor | Oya Cloud, Browserbase, Steel, Anchor, Browser Use or your own Chrome (why) |
| It keeps your tools | Every browser has a cdpUrl, so Playwright and Puppeteer connect unchanged |
| Full docs | SDK · CLI · self-hosting · deployments · moving logins · examples · oyabrowser.com/docs · for agents |
Packages
| Package | |
|---|---|
@oya-ai/browser | TypeScript SDK. ESM and CJS, typed, zero runtime dependencies. |
@oya-ai/cli | The fleet, the live view, the installer. |
server · ui · browser | Control plane, console, and the browser itself. |
skills/oya-browser | The agent skill: npx skills add OyadotAI/oya-browser. |
deployments | Production deploys: Docker, ECS, Kubernetes, GKE. |
npm test # server, CLI and packages; ui and browser run their own (see AGENTS.md)
cd server && npm run stealth -- --live # the stealth numbers, on your machine
License
The SDK and CLI are MIT. Embed them in commercial agents. Everything else is source-available under the Sustainable Use License: free for internal business use, research and non-commercial use, self-hosted up to 5 cloud browsers at once. Beyond that, write to sales@getoya.ai.
Related MCP servers
MCP server giving AI agents access to 40+ APIs: geo, crypto, screenshots, DNS, and more
View repository →
scrapewright
Give it a URL, get structured rows. A model writes the parser once; replays are free.

EverThread
Plain-English website security check for agents: certificate, headers, scripts, forms, spam.

polymnemo
Shared cross-LLM long-term memory over MCP: semantic recall, sessions, and media (pgvector).

io.github.PCfVW/mcp-arangodb-async
Async MCP server for ArangoDB: 46 tools for graphs, queries, and multi-tenancy.

io.github.PJW2004/job-search
Search Korean job postings from JobKorea and Saramin by company name
