PluginBench
MCP Server
Active
MIT

CloakBrowser MCP MCP Server

io.github.swimmwatch/cloakbrowser-mcp

Playwright MCP browser automation with CloakBrowser Chromium for humanized web testing and research.

What is the CloakBrowser MCP MCP server?

CloakBrowser MCP is a Playwright MCP-compatible browser automation server that runs upstream Playwright MCP tools against CloakBrowser Chromium. It provides humanized mouse, keyboard, and scroll behavior, persistent browser profiles, Chrome extension support, and GeoIP-aware proxy matching for interaction-sensitive workflows.

CloakBrowser MCP bridges Playwright's browser automation tools with CloakBrowser's anti-detection Chromium, enabling AI agents to perform realistic web research, daily automation, and testing tasks. It supports npm and Docker installation with stdio or Streamable HTTP transport, includes persistent profiles and Chrome extensions, and offers humanized input behavior for sites sensitive to bot detection.

How to install CloakBrowser MCP

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • PLAYWRIGHT_MCP_BROWSER_ENGINE

    Bridge browser engine: cloak or playwright.

  • PLAYWRIGHT_MCP_HEADLESS

    Run the browser in headless mode.

  • PLAYWRIGHT_MCP_OUTPUT_DIR

    Directory where upstream Playwright MCP writes artifacts.

  • PLAYWRIGHT_MCP_CODEGEN

    Generate code in typescript, python, java, csharp, or none.

  • PLAYWRIGHT_MCP_SNAPSHOT_BOXES

    Include element bounding boxes in browser snapshots.

  • PLAYWRIGHT_MCP_TIMEOUT_SETTLE

    Milliseconds to wait after actions for triggered work to settle.

  • PLAYWRIGHT_MCP_USER_DATA_DIR

    Persistent Chromium profile directory. The bridge resolves it to an absolute path and writes it to generated Playwright MCP config.

  • CLOAK_PLAYWRIGHT_MCP_CONTEXT_OPTIONS

    JSON object with validated Playwright context options such as viewport, locale, timezoneId, permissions, geolocation, and headers.

  • CLOAK_PLAYWRIGHT_MCP_EXTENSION_PATHS

    JSON array or comma-separated list of Chrome extension directories. Requires PLAYWRIGHT_MCP_USER_DATA_DIR.

  • CLOAK_PLAYWRIGHT_MCP_CONSOLE_FALLBACK

    Patch upstream console message collection for CloakBrowser compatibility.

  • CLOAK_PLAYWRIGHT_MCP_GEOIP_PROXY_MATCH

    Resolve proxy GeoIP and match CloakBrowser timezone/locale fingerprint flags when PLAYWRIGHT_MCP_PROXY_SERVER is set.

  • CLOAK_PLAYWRIGHT_MCP_EXTRA_ARGS

    Comma-separated or JSON array of extra Chromium launch arguments.

  • CLOAK_PLAYWRIGHT_MCP_HTTP_HOST

    Streamable HTTP bind host.

  • CLOAK_PLAYWRIGHT_MCP_HTTP_PORT

    Streamable HTTP bind port.

  • CLOAK_PLAYWRIGHT_MCP_HTTP_ENDPOINT

    Streamable HTTP endpoint path.

  • CLOAK_PLAYWRIGHT_MCP_HTTP_AUTH_TOKEN
    secret

    Optional Streamable HTTP Bearer token.

  • CLOAK_PLAYWRIGHT_MCP_HTTP_SESSION_BACKEND

    Session metadata backend. Only memory is implemented in this release.

  • CLOAK_PLAYWRIGHT_MCP_HTTP_SESSION_IDLE_TTL_MS

    Idle TTL for Streamable HTTP sessions.

  • CLOAK_PLAYWRIGHT_MCP_HTTP_SESSION_MAX

    Maximum active Streamable HTTP sessions in one process.

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "cloakbrowser-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "cloakbrowser-mcp"
      ],
      "env": {
        "PLAYWRIGHT_MCP_BROWSER_ENGINE": "<YOUR_PLAYWRIGHT_MCP_BROWSER_ENGINE>",
        "PLAYWRIGHT_MCP_HEADLESS": "<YOUR_PLAYWRIGHT_MCP_HEADLESS>",
        "PLAYWRIGHT_MCP_OUTPUT_DIR": "<YOUR_PLAYWRIGHT_MCP_OUTPUT_DIR>",
        "PLAYWRIGHT_MCP_CODEGEN": "<YOUR_PLAYWRIGHT_MCP_CODEGEN>",
        "PLAYWRIGHT_MCP_SNAPSHOT_BOXES": "<YOUR_PLAYWRIGHT_MCP_SNAPSHOT_BOXES>",
        "PLAYWRIGHT_MCP_TIMEOUT_SETTLE": "<YOUR_PLAYWRIGHT_MCP_TIMEOUT_SETTLE>",
        "PLAYWRIGHT_MCP_USER_DATA_DIR": "<YOUR_PLAYWRIGHT_MCP_USER_DATA_DIR>",
        "CLOAK_PLAYWRIGHT_MCP_CONTEXT_OPTIONS": "<YOUR_CLOAK_PLAYWRIGHT_MCP_CONTEXT_OPTIONS>",
        "CLOAK_PLAYWRIGHT_MCP_EXTENSION_PATHS": "<YOUR_CLOAK_PLAYWRIGHT_MCP_EXTENSION_PATHS>",
        "CLOAK_PLAYWRIGHT_MCP_CONSOLE_FALLBACK": "<YOUR_CLOAK_PLAYWRIGHT_MCP_CONSOLE_FALLBACK>",
        "CLOAK_PLAYWRIGHT_MCP_GEOIP_PROXY_MATCH": "<YOUR_CLOAK_PLAYWRIGHT_MCP_GEOIP_PROXY_MATCH>",
        "CLOAK_PLAYWRIGHT_MCP_EXTRA_ARGS": "<YOUR_CLOAK_PLAYWRIGHT_MCP_EXTRA_ARGS>",
        "CLOAK_PLAYWRIGHT_MCP_HTTP_HOST": "<YOUR_CLOAK_PLAYWRIGHT_MCP_HTTP_HOST>",
        "CLOAK_PLAYWRIGHT_MCP_HTTP_PORT": "<YOUR_CLOAK_PLAYWRIGHT_MCP_HTTP_PORT>",
        "CLOAK_PLAYWRIGHT_MCP_HTTP_ENDPOINT": "<YOUR_CLOAK_PLAYWRIGHT_MCP_HTTP_ENDPOINT>",
        "CLOAK_PLAYWRIGHT_MCP_HTTP_AUTH_TOKEN": "<YOUR_CLOAK_PLAYWRIGHT_MCP_HTTP_AUTH_TOKEN>",
        "CLOAK_PLAYWRIGHT_MCP_HTTP_SESSION_BACKEND": "<YOUR_CLOAK_PLAYWRIGHT_MCP_HTTP_SESSION_BACKEND>",
        "CLOAK_PLAYWRIGHT_MCP_HTTP_SESSION_IDLE_TTL_MS": "<YOUR_CLOAK_PLAYWRIGHT_MCP_HTTP_SESSION_IDLE_TTL_MS>",
        "CLOAK_PLAYWRIGHT_MCP_HTTP_SESSION_MAX": "<YOUR_CLOAK_PLAYWRIGHT_MCP_HTTP_SESSION_MAX>"
      }
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • cloakbrowser_binary_info — Returns CloakBrowser package, platform, cache, and resolved binary data.
  • cloakbrowser_bridge_info — Returns bridge metadata, upstream package/version, and local tool names.
  • Playwright MCP tools — Full upstream Playwright MCP browser automation tool surface including page navigation, interaction, screenshot, and testing capabilities.

Use cases

  • Perform web research and data collection with humanized browser behavior to avoid detection
  • Automate daily tasks like form filling, login, and data scraping with persistent browser profiles
  • Run browser-based QA testing with regional proxy matching for GeoIP-aware testing
  • Load and test Chrome extensions within automated browser contexts
  • Execute interaction-sensitive workflows that require realistic mouse, keyboard, and scroll patterns

CloakBrowser MCP MCP server FAQ

What is CloakBrowser MCP?

CloakBrowser MCP is a Playwright MCP-compatible browser automation server that runs Playwright's tools against CloakBrowser Chromium, adding anti-detection features like humanized input behavior, persistent profiles, and Chrome extension support.

Is CloakBrowser MCP free?

Yes, CloakBrowser MCP is open-source under the MIT license and available via npm and Docker at no cost.

How do I install it in Claude Desktop or Cursor?

Add an MCP server entry to your client's config with command 'npx' and args ['-y', 'cloakbrowser-mcp@latest'], or use Docker with the swimmwatch/cloakbrowser-mcp image.

What are the system requirements?

Node.js 22.13+ or 24+, or Docker. Supports Linux x64/arm64, macOS arm64/x64, and Windows x64.

Does it require authentication?

No authentication is required to run CloakBrowser MCP itself, though you may configure proxies or other services separately.

How does it differ from plain Playwright MCP?

CloakBrowser MCP uses CloakBrowser Chromium with humanized input behavior, persistent profiles, Chrome extension support, and GeoIP proxy matching—features designed to avoid detection on interaction-sensitive sites.

README (reference)

Source of truth, from the repository.

cloakbrowser-mcp

<p align="center"> <img src="docs/assets/brand/logo-wordmark.svg" alt="CloakBrowser MCP" width="640" /> </p>

CI codecov Actionlint CodeQL Dependency Review OpenSSF Scorecard Zizmor Release GitHub Release MCP Registry cloakbrowser-mcp MCP server Awesome MCP Servers npm npm downloads Docker Hub pulls Docker image Node.js 22.13+ or 24+ TypeScript strict Cross-platform Available on CodeGuilds MCP Server MCP transports Docker License: MIT MCP Toplist

cloakbrowser-mcp is a drop-in Playwright MCP-compatible browser automation server with unchanged upstream tools, CloakBrowser Chromium, and production-ready npm, Docker, and Streamable HTTP packaging. It runs upstream @playwright/mcp as the canonical tool surface and points that runtime at CloakBrowser.

30-second demo

30-second demo showing CloakBrowser MCP startup, humanized research prompt typing, web automation, and testing workflows

Run npx -y cloakbrowser-mcp@latest, connect Claude Desktop or Codex CLI, ask for web research, daily automation, or testing in plain English, and inspect the real browser result.

Documentation: swimmwatch.github.io/cloakbrowser-mcp · Comparison · Recipes

Use it when you need:

  • Playwright MCP browser automation backed by CloakBrowser;
  • unchanged upstream browser tools plus two local introspection tools;
  • npm or Docker installation over stdio or Streamable HTTP;
  • opt-in, session-scoped managed CDP access for CDP-capable clients through chromium.connectOverCDP();
  • persistent browser profiles, validated context options, and Chrome extension loading;
  • GeoIP-aware proxy matching for regional QA;
  • humanized mouse, keyboard, and scroll behavior for interaction-sensitive flows.

Cross-platform checks cover npm on Linux x64/arm64, macOS arm64/x64, and Windows x64 across Node.js 22 and 24-26. Docker images are built and smoke-tested for linux/amd64 and linux/arm64.

See @playwright/mcp vs cloakbrowser-mcp when deciding whether plain upstream Playwright MCP or CloakBrowser MCP fits a deployment better. The Recipes pages show task-focused setup paths for persistent login profiles, Chrome extensions, reverse proxies, regional QA, client connections, and CI smoke tests.

Install With npm

npx -y cloakbrowser-mcp@latest

Requires Node.js 22.13+ in the 22.x line, or Node.js 24+. Run diagnostics before wiring a client:

npx -y cloakbrowser-mcp@latest doctor

For Streamable HTTP instead of stdio:

npx -y cloakbrowser-mcp@latest --transport streamable-http --http-port 3000

See the generated CLI Reference for all flags.

Install With Docker

docker run --rm -i \
  -v "$PWD/artifacts:/data" \
  swimmwatch/cloakbrowser-mcp:latest

For Streamable HTTP:

docker run --rm -p 127.0.0.1:3000:3000 \
  -v "$PWD/artifacts:/data" \
  swimmwatch/cloakbrowser-mcp:latest \
  --transport streamable-http --http-host 0.0.0.0 --http-port 3000

The Docker image writes artifacts to /data and is published for linux/amd64 and linux/arm64. It defaults to CLOAK_PLAYWRIGHT_MCP_NO_SANDBOX=true for compatibility with containerized runtimes where Chromium sandboxing is often unavailable. If your host and container runtime support Chromium sandboxing, set CLOAK_PLAYWRIGHT_MCP_NO_SANDBOX=false; for untrusted pages, keep container network access and mounted host directories tightly scoped. The same tags are also available from ghcr.io/swimmwatch/cloakbrowser-mcp. See Docker for persistent profiles, extension mounts, HTTPS, and smoke-test examples, or use the reverse proxy recipe for a focused Streamable HTTP deployment.

Add To MCP Clients

Codex CLI

codex mcp add cloakbrowser -- npx -y cloakbrowser-mcp@latest

Claude Code

claude mcp add --transport stdio cloakbrowser -- npx -y cloakbrowser-mcp@latest

GitHub Copilot In VS Code

{
  "servers": {
    "cloakbrowser": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "cloakbrowser-mcp@latest"]
    }
  }
}

Claude Desktop, Cursor, Cline, Windsurf, Warp, And Other mcpServers Clients

Add this server entry to the client's MCP JSON config:

{
  "mcpServers": {
    "cloakbrowser": {
      "command": "npx",
      "args": ["-y", "cloakbrowser-mcp@latest"]
    }
  }
}

Docker-backed stdio

{
  "mcpServers": {
    "cloakbrowser": {
      "command": "docker",
      "args": [
        "run",
        "--rm",
        "-i",
        "-v",
        "/tmp/cloakbrowser-artifacts:/data",
        "swimmwatch/cloakbrowser-mcp:latest"
      ]
    }
  }
}

Already-running Streamable HTTP server

npx -y cloakbrowser-mcp@latest --transport streamable-http --http-port 3000
codex mcp add cloakbrowser --url http://127.0.0.1:3000/mcp
claude mcp add --transport http cloakbrowser http://127.0.0.1:3000/mcp

Prompt For A Code Assistant

Paste this into Codex, Claude Code, Copilot, Cursor, Cline, Windsurf, or a similar coding assistant that can edit MCP config:

Install the CloakBrowser MCP server for this workspace. Name it "cloakbrowser".
Prefer stdio with command "npx" and args ["-y", "cloakbrowser-mcp@latest"].
If this client uses VS Code mcp.json, add it under "servers" with type "stdio".
If this client uses Claude/Cursor/Cline/Windsurf/Warp-style config, add it under
"mcpServers" with the same command and args. Do not add secrets.

More examples are in Getting Started, with dedicated recipes for Claude Desktop and Codex CLI.

Configuration

Use upstream PLAYWRIGHT_MCP_* variables for browser, artifacts, timeouts, network, and tool capability settings. Cloak-specific bridge toggles use CLOAK_PLAYWRIGHT_MCP_*. Select a Pro Preview browser build before startup with --release-channel preview or CLOAK_PLAYWRIGHT_MCP_RELEASE_CHANNEL=preview; the default is stable.

The common variable table now lives in Configuration. That page also covers persistent profiles, validated context options, Chrome extensions, Streamable HTTP metadata, and HTTPS/auth options. See GeoIP Proxy Matching for regional proxy behavior, Humanized Input Behavior for interaction realism, and Recipes for task-focused configurations.

Version Compatibility

<!-- compatibility-table:start -->
cloakbrowser-mcp@playwright/mcpCloakBrowserNode.jsPlatform
1.14.1^0.0.82^0.5.10`^22.13.0
1.14.0^0.0.82^0.5.10`^22.13.0
1.13.0^0.0.80^0.5.10`^22.13.0
1.12.0^0.0.79^0.5.7`^22.13.0
1.11.0^0.0.79^0.5.6`^22.13.0
1.10.0^0.0.78^0.5.3`^22.13.0
1.9.0^0.0.78^0.5.1`^22.13.0
1.8.0^0.0.78^0.4.10`^22.13.0
1.7.0^0.0.77^0.4.8>=22.12npm on Linux x64/arm64, macOS arm64/x64, Windows x64; Docker linux/amd64, linux/arm64
1.6.1^0.0.77^0.4.7>=22.12npm on Linux x64/arm64, macOS arm64/x64, Windows x64; Docker linux/amd64, linux/arm64
1.6.0^0.0.77^0.4.7>=22.12npm on Linux x64/arm64, macOS arm64/x64, Windows x64; Docker linux/amd64, linux/arm64
1.5.0^0.0.76^0.4.3>=22.12npm on Linux x64/arm64, macOS arm64/x64, Windows x64; Docker linux/amd64, linux/arm64
1.4.0^0.0.76^0.3.32>=22.12npm on Linux x64/arm64, macOS arm64/x64, Windows x64; Docker linux/amd64, linux/arm64
1.3.0^0.0.75^0.3.31>=20Docker linux/amd64, Node.js local
1.2.7^0.0.75^0.3.30>=20Docker linux/amd64, Node.js local
1.2.6^0.0.75^0.3.30>=20Docker linux/amd64, Node.js local
1.2.5^0.0.75^0.3.30>=20Docker linux/amd64, Node.js local
1.2.3^0.0.75^0.3.30>=20Docker linux/amd64, Node.js local
1.2.2^0.0.75^0.3.30>=20Docker linux/amd64, Node.js local
1.2.1^0.0.75^0.3.30>=20Docker linux/amd64, Node.js local
1.2.0^0.0.75^0.3.30>=20Docker linux/amd64, Node.js local
1.1.0^0.0.75^0.3.30>=20Docker linux/amd64, Node.js local
1.0.2^0.0.75^0.3.30>=20Docker linux/amd64, Node.js local
1.0.1^0.0.75^0.3.30>=20Docker linux/amd64, Node.js local
1.0.0^0.0.75^0.3.30>=20Docker linux/amd64, Node.js local
<!-- compatibility-table:end -->

See Version Compatibility for the maintained compatibility table.

Tools

The upstream Playwright MCP tool list is authoritative. This project does not reimplement or re-document upstream browser schemas in source code.

Local tools:

  • cloakbrowser_binary_info returns CloakBrowser package, platform, cache, and resolved binary data.
  • cloakbrowser_bridge_info returns bridge metadata, upstream package/version, and local tool names.

Development

npm install
npm run build
npm test
npm run docker:build
npm run docker:smoke
npm run server:validate
npm run bridge:compare -- cloakbrowser-mcp:dev --report bridge-parity-report.json

Documentation starts at docs/getting-started.md. Contributor material is grouped under docs/contributor-guide.md.

Related MCP servers

ONOn Board logo

On Board

Active

Cross-platform shared memory and ticket coordination for AI agents across MCP clients.

4
Python
Apache-2.0
View repository →
PUPursers logo

Pursers

Active

Coordinate AI-agent work on a local-first, owner-controlled MCP board

1
Python
Apache-2.0
View repository →

Verified knowledge base for AI agents — stop hallucinations with certified facts.

0
Python
View repository →

Verified US rate, savings-gap, card, CD, and product-change tools with freshness and sources.

1
TypeScript
MIT
View repository →

Protected RAG storage with public metadata discovery and token-gated content retrieval for AI agents.

10
TypeScript
MIT
View repository →

Classifies prompt injection, jailbreaks, and out-of-scope input before agents act on it.

10
TypeScript
MIT
View repository →