PluginBench
MCP Server
Active
Apache-2.0

unbrowser by Unchained MCP Server

io.github.protostatis/unbrowser

Chrome-free MCP web runtime for agents with stateful cookies, DOM queries, and bounded script execution.

What is the unbrowser by Unchained MCP server?

unbrowser is a stateful, non-visual web runtime MCP server that sits between curl and a real browser. It retains cookies and DOM state, returns queryable element references, handles links and HTML forms, detects challenge and SPA signals, and can run bounded QuickJS page scripts when static HTML is insufficient.

unbrowser provides agents with structured web access without requiring Chrome or a full browser. It returns low-token page maps (BlockMaps) with landmarks, headings, and interactives, supports stateful cookies and form submission, detects when pages need real browser escalation, and optionally executes bounded JavaScript for light hydration. Use it when HTTP alone is too simple but a full browser is too expensive.

How to install unbrowser by Unchained

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "unbrowser": {
      "command": "uvx",
      "args": [
        "pyunbrowser",
        "--mcp"
      ]
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • navigate — Fetch and parse a URL, returning a BlockMap with page structure, landmarks, headings, interactives, and density signals. Optionally execute bounded QuickJS scripts with exec_scripts: true.
  • query — Query the DOM using CSS selectors to retrieve stable element references (e.g., e:142) for later interaction.
  • click — Click on a previously queried element reference.
  • type — Type text into a form field or input element.
  • submit — Submit a form using a stable element reference.
  • extract — Structured extraction helper for common workflows like card extraction and table normalization.
  • cookies_set — Import session cookies from an authorized browser session for authenticated tasks.
  • help — Discover available tools and get detailed documentation on specific topics.

Use cases

  • Scrape and parse static or server-rendered web pages with structured element references for agent interaction
  • Navigate multi-step forms and workflows while maintaining cookies and session state across requests
  • Detect when a page requires real browser capabilities (pixels, Canvas, V8, anti-bot challenges) and escalate appropriately
  • Extract structured data like cards, tables, and text from web pages using built-in helpers
  • Execute light client-side JavaScript hydration on SPAs when static HTML is insufficient, without full browser overhead

unbrowser by Unchained MCP server FAQ

What is unbrowser?

unbrowser is a stateful web runtime for AI agents that provides structured web access without Chrome. It handles cookies, DOM queries, forms, and can detect when pages need real browser escalation. It returns low-token page maps and stable element references for agent interaction.

Is unbrowser free?

Yes, unbrowser is open-source under the Apache-2.0 license. A public demo is available at unchainedsky.com/unbrowser, and a shared HTTP MCP endpoint is available for public smoke tests. Production use should run a local install.

How do I install unbrowser in Cursor or Claude?

Install via PyPI (`pipx install pyunbrowser` or `pip install pyunbrowser`), Cargo (`cargo install unbrowser`), or Docker (`docker pull ghcr.io/protostatis/unbrowser:latest`). Then configure it in your MCP settings with the command `unbrowser --mcp` or Docker equivalent.

Does unbrowser require authentication?

unbrowser does not require authentication to run. However, you can import session cookies from an authorized browser using `cookies_set` for authenticated tasks on sites you have permission to access. Treat session cookies as credentials and keep them local.

When should I use unbrowser vs. a real browser?

Use unbrowser for static/SSR HTML, cookie-based workflows, and light form interactions. Escalate to a real browser (Chrome) when you need pixels, Canvas/WebGL, Workers, extensions, V8 fidelity, or interactive anti-bot challenges that unbrowser cannot handle.

What does 'escalation' mean in unbrowser?

Escalation is when unbrowser detects that a page requires real browser capabilities (e.g., challenge.provider, thin_shell, heavy SPA) and recommends switching to an authorized Chrome session or Unchained service. The output includes escalation taxonomy with severity and evidence.

README (reference)

Source of truth, from the repository.

unbrowser

The cheap browser pass for agents. One native binary. No Chrome.

unbrowser MCP server

Official MCP Registry identity: mcp-name: io.github.protostatis/unbrowser

unbrowser is a stateful, non-visual web runtime for agents. It sits between curl/WebFetch and a real browser: it retains cookies and DOM state, returns queryable element refs, handles links and HTML forms, detects challenge and SPA signals, and can run bounded QuickJS page scripts when static HTML is not enough.

Default navigate is a fast static/SSR pass. Set exec_scripts: true only when you need bounded QuickJS execution. Heavy SPAs, pixels, V8 fidelity, extensions, and interactive anti-bot challenges belong in a real Chrome tier.

Try the live public-web demo before installing. It accepts only the fixed public source sets shown on the page; do not send private data, cookies, or authenticated tasks through it. A shared Streamable HTTP MCP endpoint is available at https://unchainedsky.com/unbrowser-mcp for public smoke tests; production sessions should use a local install.

Use unbrowser only on sites, accounts, and data you are permitted to access. Challenge detection and cookie import do not grant permission to bypass access controls or site terms. Treat session cookies as credentials: keep them local, scope them to the authorized task, and never send them to the public demo.

Pick the right tier

Needcurl / WebFetchunbrowserReal Chrome
Static / SSR HTMLraw responsestructured BlockMap + DOM queriesfull browser
Cookies, links, HTML formsDIYbuilt inbuilt in
Client-side page scripts❌bounded QuickJS, opt-inV8
Pixels, Canvas, WebGL, Workers, extensions❌❌✅
Agent-oriented outputDIY parsingelement refs, page signals, structured extractionDIY CDP / DOM parsing
Interactive access challenge❌detect + stop or escalateauthorized browser / human confirmation

Use unbrowser when HTTP alone is too dumb and a full browser is too expensive. When the page needs Chrome, the output tells the agent to escalate rather than pretending compatibility it does not have.

Quick start

Docker — Linux amd64/arm64, ~13 MiB pull

docker pull ghcr.io/protostatis/unbrowser:latest

# One-shot navigation
docker run --rm ghcr.io/protostatis/unbrowser:latest \
  navigate https://example.com --json

# Default mode: MCP over stdio
docker run --rm -i ghcr.io/protostatis/unbrowser:latest

The image is distroless and runs as non-root: no shell, package manager, or persistent state. Pin :vX.Y.Z or an image digest in production.

Python

pipx install pyunbrowser   # recommended on macOS / modern Linux
# or, inside a Python 3.10+ virtual environment:
pip install pyunbrowser
from unbrowser import Client

with Client() as ub:
    ub.navigate("https://news.ycombinator.com")
    for link in ub.query(".titleline > a")[:3]:
        print(link["text"], link["attrs"]["href"])

On macOS, /usr/bin/python3 is 3.9 and cannot install the wheel; use pipx or a Homebrew Python. The PyPI distribution is pyunbrowser, while the import and executable remain unbrowser.

MCP

{
  "mcpServers": {
    "unbrowser": {
      "command": "unbrowser",
      "args": ["--mcp"]
    }
  }
}

Minimal surface: add "--mcp-profile", "minimal" to expose only navigate/query/extract/help and let the agent discover the rest via help(topic). The Python wrapper ships a 3-tool smart server (search/open/help) as the unbrowser-smart console script.

<details> <summary>Docker MCP configuration</summary>
{
  "mcpServers": {
    "unbrowser": {
      "command": "docker",
      "args": [
        "run", "--rm", "-i",
        "ghcr.io/protostatis/unbrowser:latest"
      ]
    }
  }
}
</details>

See installation and interface reference for Cargo, release archives, source builds, persistent shell sessions, raw JSON-RPC, and all MCP options.

What an agent gets

  • navigate returns a BlockMap: page title, landmarks, headings, interactives, density signals, and an ASCII outline. Its size is page-dependent; it is structured for planning rather than a fixed-token promise.
  • Stable element refs (e:142): query an element once, then click, type, or submit it without re-parsing HTML.
  • Stateful cookies and forms: cookie jar, GET and URL-encoded POST form submission, links, and redirects persist within a session.
  • Page and challenge signals: density.likely_js_filled, thin_shell, and challenge.provider tell an agent whether to run scripts, inspect embedded data, stop, or escalate to an authorized browser session.
  • Routing aids on every result: micro_hint (the single next concrete step), next_tools (ranked candidates), avoid (tools with nothing to act on), and a stable escalation taxonomy (challenge, thin_shell, partial_result, …) with retryable/severity/evidence — recommendations never contradict avoid.
  • Structured helpers: route discovery, card extraction, table normalization, text_main, and selector debugging cover common extraction workflows.

Script mode and escalation

{"id":1,"method":"navigate","params":{"url":"https://example.com","exec_scripts":true}}

With exec_scripts: true, inline and external scripts run in QuickJS under a bounded watchdog. This can materialize light hydration and fetch-visible data; it is not V8 or a rendering engine. Heavy React/Vue/Ember apps may still leave an empty shell.

Escalate to unchainedsky-cli or Unchained when a permitted task needs real pixels, Canvas/WebGL, Workers, browser extensions, V8 compatibility, an authenticated profile, or human confirmation. When the user has already established an authorized session in Chrome, cookies_set can import the required session cookie locally until it expires; it is not a license to circumvent a site's controls.

Documentation

NeedRead
Install paths, session CLI, one-shot CLI, raw RPC, MCP, shims, full RPC tableUsage reference
Script compatibility, SPA signals, challenge handling, authorized cookie handoff, escalationCompatibility and escalation
Distribution and supported directory listingsDistribution notes
Build the native binaryBuild instructions

License

Apache-2.0 — see LICENSE.

Related MCP servers

PRProvenTools logo

Read-only ProvenTools business ideas, evidence, build prompts, and validation reports.

1
JavaScript
MIT
View repository →

Encrypted database backups and restore-to-any-host disaster recovery for MySQL and PostgreSQL.

Keep a target database continuously in sync with a source on another provider, then promote it.

Move a database between providers, or convert MySQL to PostgreSQL, with integrity verified.

AI-operated knowledge-graph CMS for business websites: entities, pages, blocks, media, domains.

View repository →

The full Prufa QA agent over MCP: audits, flows, monitors, gremlin chaos, discovery.

2
Python
Apache-2.0
View repository →