Invisible Browser Agent
Automate real web pages with a stealth Firefox browser, then read and report what the pages show.
- Source repo
- feder-cr/invisible_playwright_mcp
- Stars
- ★ 2.7k
- Last updated
- today
- License
- MIT
- Primary language
- Python
- FA score
- 57/100 · Major gaps
At a glance
- How it runs
- Works with
- Universal · cross-platformCodex · Claude Code
- Cost
- Free software; you pay for model usage
- Setup effort
- Low · running in minutes
- You'll need
- Typical use
- A job seeker wants to open job listings one by one and collect details matching specified criteria.
- Not a fit if
- Teams that require browsing data and conversations to stay entirely on-device
- Users who cannot work within target sites’ rate limits
- Source review
- 57/100 · Major gaps
What does this agent do, and when should you use it?
invisible_playwright_mcp is a Python MCP browser agent that uses Playwright with an anti-detect Firefox engine. It can be called from MCP clients such as Claude Code, Codex, and Gemini CLI, or run through a standalone web interface. The agent interacts with pages using pointer movements and key presses, reads page content, and reports results from the requested task. The web UI sends conversations and page content to OpenRouter; in MCP mode, the connected client sends them to the model it uses. The browser, profiles, sessions, and screenshots are stored locally, while the browser engine is downloaded from a GitHub release on first startup.
Run invisible_playwright_mcp without a subcommand to start the MCP server, or run invisible-playwright-mcp ui for the web interface. Give the agent a URL and instructions; it interacts with the page using pointer movements and key presses, reads page content, and produces a response. The web UI uses an OpenRouter model and needs --openrouter-key or OPENROUTER_API_KEY; MCP mode uses the model configured by the connected client. Optional settings include a proxy, browser profile directory, seed, and browser binary path.
- A job seeker wants to open job listings one by one and collect details matching specified criteria.
- A traveler needs to select dates in a calendar widget and compare fares displayed on a booking site.
- A researcher needs an agent to operate pages that require a browser and read their visible content.
- A user who needs browser login state to persist can set
--profile-dirto retain cookies and profile data. - A user who wants to watch the browser work can open the web UI and view the live page.
How do you install or deploy this agent?
Install uv first, then use the commands for your shell. After that, install the plugin in Claude Code or Codex, or install the Gemini CLI extension; the MCP server is included in the package. The standalone web UI requires an OpenRouter API key.
How do you use this agent?
After installing it in an MCP client, give the agent a URL and a specific browsing task. To run the standalone web UI, use the command below, then open http://127.0.0.1:8765. You can also put the key in a .env file in the current directory as OPENROUTER_API_KEY.
What are this agent's strengths and limitations?
- Uses pointer and keyboard input to operate pages, including controls such as calendar widgets.
- Documents both an MCP server and a standalone web UI as ways to use it.
- Supports
--profile-dirto keep browser login state and cookies on the local machine. - Offers proxy, seed, and model options, and can show the browser window.
- The web UI requires an OpenRouter API key; MCP use relies on the model configured in the connected client.
- It needs network access to target sites and downloads its browser engine at first startup; setting a proxy also fetches a GeoIP database.
- The project says target sites see the browser and the web UI sends conversations and page content to OpenRouter.
- Changing the UI host may expose an interface that has no authentication.
How does this agent compare with similar options?
The README groups it with browser-use, Operator-style agents, and computer-use agents as AI browser agents, but provides no detailed feature comparison.
Key facts side by side with the most closely related agents.
| Agent | Source review | Form / cost | Stars | Updated | Language | Full support on |
|---|---|---|---|---|---|---|
| Invisible Browser Agent This agent | 57 · Major gaps | MCP serverFree + model costs | ★ 2.7k | today | Python | Codex · Claude Code |
| Obscura Headless Browser | 75 · Good | CLIFree | ★ 29k | 1d ago | Rust | Claude.ai |
| Flyto2 Core | 64 · Some gaps | CLIFreemium | ★ 484 | 2d ago | Python | Claude Code |
| AIHawk – AI Browser Agent | 59 · Major gaps | MCP serverFree + model costs | ★ 32k | today | TypeScript | Codex · Claude Code |
How does FollowAgents rate this agent?
Why each dimension lost points
The README describes data sent to target sites, the model provider, and GitHub, warns that a command-line key may be exposed, and recommends environment variables or a .env file; data-flow and sensitive-data guidance are therefore substantial. Dependency floors have specific defect rationales, and CI grants read-only contents permission. Deductions: browser access is broad, and no per-action confirmation or pre-submission gate is shown; a responsibility notice is not a technical confirmation control. Changing the host can expose an unauthenticated interface, while control of side effects and recovery is left largely to the user. Local data can be deleted, but there is no dedicated rollback process. The repository names an author and includes a license, but publisher identity is unverified and maintenance responsibility and support expectations are limited.
The README, pyproject, and CI provide substantial alignment on installation, commands, supported platforms, and dependency requirements. CI covers several Python versions and Windows/Linux, and includes package build, MCP bundle, and browser-flow checks. Deductions: dependencies use lower bounds rather than a complete lock, and some checks require external downloads or manual runs, so availability assurance is not complete. The pyproject records several known defects and their fix floors, helping explain failures, but there is no systematic user-facing troubleshooting or error-message guide.
The documentation presents MCP and standalone web UI use, a travel-fare task example, and options for proxies, browser configuration, and session directories. It identifies real-browser tasks requiring page judgment as a suitable use and advises against submitting content a human has not read. MCP, UI, and option triggers are distinguished, with Windows, Linux, Python versions, and local/proxy environments described. Deductions: macOS is outside the declared platform support, and the configuration and scenario boundaries are not a complete matrix.
The README is organized around installation, use, options, privacy, and licensing, with examples and links to a wiki and articles. Dependency comments and CI reveal several limitations and the reasoning for changes. The MIT license file matches project metadata and the README explains that earlier releases remain under AGPL. Package name, entry points, and version are clear. Deductions: there is no consolidated user-facing changelog; an author email and issues link are present, but ongoing maintainer responsibility and support commitments are not explicit.
The repository provides MCP browser tools and a local chat/browser interface, with task-ready output and an example specifying date-by-date lookup and how to report unavailable dates. Deductions: cost-benefit is only partly assessable: use requires uv, an engine download, and a model-service key, and the documentation says the UI sends conversation and page-read content through OpenRouter. Typical operating costs and resource usage are not documented.
Key installation, data-flow, option, and dependency claims can be traced across the README, pyproject, and CI configuration. Dependency comments give concrete defect and version-floor explanations, while CI shows the configured static workflow coverage. The README presents privacy and runtime behavior as documentation claims and states usage cautions without presenting them as independently verified results. Deductions: some privacy and behavior claims are not corroborated by implementation code or an independent source in the provided material; static review cannot establish runtime behavior.
- Changing the default host can expose an unauthenticated interface; do not expose it on an untrusted network.
- Conversation and page content are sent to the selected model provider. A persistent browser profile keeps login state and cookies in its local directory.
- Anti-detection and captcha circumvention are stated project aims; respect target-site terms and rate limits, and have a person review content before submission.
FAQ
What does the web UI send to the model provider?
Can browser login state survive restarts?
--profile-dir to a directory where the browser profile and cookies can persist locally.What do I need to run the web UI?
http://127.0.0.1:8765.