Browser automation for Chromium-based browsers (Chrome, Edge, Brave) via OpenCode - readable extension, native messaging host, and OpenCode plugin.
11
stars
10
commits
JavaScript
primary language
Sep 8, 2026
updated
Provider-neutral Chromium automation for MCP clients, OpenCode V2, Codex, and direct JavaScript agents.
The roadmap is shaped by users — open a proposal, upvote with reactions, and follow announcements on GitHub Discussions:
planned, in progress, released).
Open a proposal →browser_run, browser_observe, browser_session, and browser_finalize.html/styles (available only through detail: "debug"), and inline responses stay within the 4,096-character budget with oversized output spilled to artifact resources.fullPage: false grabs the visible viewport, fullPage: true captures the entire scrollable page (dimension-capped, with automatic jpeg compression for oversized captures).browser_observe mode diagnostic records CDP traces and computes LCP, CLS, long tasks, TBT, and more in the native host; raw traces are artifact-first and CrUX/field data stays off.Install the published package once, then connect any supported client. The
package ships the CLI (opencode-chromium), the MCP server bin
(opencode-chromium-mcp), the browser extension, and the native host
installer:
npx -y opencode-chromium-mcp
| Client | Surface | Setup |
|---|---|---|
| OpenCode V2 | Native plugin | "plugin": ["opencode-chromium"] in opencode.json |
| Codex | MCP server (stdio) | codex mcp add opencode-browser-plugin -- npx -y opencode-chromium-mcp |
| Any MCP client | MCP server (stdio) | npx -y opencode-chromium-mcp as a stdio server |
| Direct JavaScript | SDK (opencode-chromium/sdk) | import { createBrowserAgent } from "opencode-chromium/sdk" |
npm install -g opencode-chromium
Install opencode-chromium from the Chrome Web Store. The unpacked flow below remains available for development and local testing.
Open chrome://extensions, enable Developer mode, and load the unpacked
extension/ folder from the installed package:
npm root -g
# load "<that path>\opencode-chromium\extension" as an unpacked extension
The extension ID is derived from the load path, so keep the folder where it
is. Note the ID shown in chrome://extensions.
node "$(npm root -g)/opencode-chromium/scripts/install-native-host.js" --extension-id <extension-id> --browsers chrome
Add the package name to the global
~/.config/opencode/opencode.json:
{
"$schema": "https://opencode.ai/config.json",
"plugin": ["opencode-chromium"]
}
Register the MCP server:
codex mcp add opencode-browser-plugin -- npx -y opencode-chromium-mcp
Add the stdio server:
{
"mcpServers": {
"opencode-browser-plugin": {
"command": "npx",
"args": ["-y", "opencode-chromium-mcp"]
}
}
}
Use createBrowserAgent from opencode-chromium/sdk. See the SDK example.
Choose only the setup for your client; you do not need all of them.
opencode-chromium doctor --json
opencode-chromium verify
All four tools (browser_run, browser_observe, browser_session,
browser_finalize) are then available in every connected client. Do not
enable both the native OpenCode adapter and the MCP server in one client
session unless duplicate tools are intentional.
Open the extension’s Profiles tab, choose a connected profile, and click Copy agent selector. Paste that selector into your first browser request. Renaming the current profile is optional.
The Overview defaults to this profile. Choose all profiles, select several profiles, or view older unassigned history. Actions are shared locally across profiles; selecting two profiles counts a shared action once while keeping their execution totals separate. Storage controls apply to the shared database.
Enable action memory in Settings. Page search works with the default settings; model downloads and search tuning are under Advanced search settings. A dash means no result yet, and an unavailable message means the host could not supply statistics.
The installed extension version appears in its header. Package and store versions can differ while a release is under review; a successful upload does not mean store approval.
On connection, the extension compares its version with the local native host and connected CLI/MCP clients. A toolbar badge and compact notice flag differences or unreported versions. Expand How to update for instructions, or choose Remind me in a week; instructions remain in Settings, and a different version combination prompts again. Checks stay local and do not install updates automatically. If local tools are newer, the notice explains that the store extension may still be awaiting approval.
extension/ loaded.bun install --frozen-lockfile
bun run build
bun run build:extension
bun test
bun run check
The package is released under the npm name opencode-chromium. The stable runtime and MCP server identity remains opencode-browser-plugin for client compatibility; the current release version is defined in package.json.
Run the four-tool server over stdio:
bun run mcp
Or use the packaged binary:
opencode-chromium-mcp
Loopback Streamable HTTP is available with:
bun run mcp:http
Non-loopback HTTP requires a bearer token in AGENT_BROWSER_AUTH_TOKEN (or the variable selected with --auth-token-env). The default server name is opencode-browser-plugin. Origin and file-root safety configuration is server-level: pass --allowed-origin / --blocked-origin globs, or set AGENT_BROWSER_ALLOWED_ORIGINS, AGENT_BROWSER_BLOCKED_ORIGINS, and AGENT_BROWSER_ALLOWED_FILE_ROOTS (see docs/mcp.md).
The package root exports the native adapter using OpenCode 1.18.x's official { id, server() } path-plugin module shape, alongside the V2 setup contract:
{
"$schema": "https://opencode.ai/config.json",
"plugin": ["opencode-chromium"]
}
For a local build, point the client at dist/adapters/opencode/index.js or
use the opencode-chromium install --client opencode command. The adapter
registers exactly four tools, sets codemode: false, and returns a cleanup
function for reloads.
The same browser runtime is available through MCP compatibility mode; do not enable both surfaces in one client session unless duplicate tools are intentional.
Register the MCP server from the npm package:
codex mcp add opencode-browser-plugin -- npx -y opencode-chromium-mcp
codex mcp list
From a local checkout, register dist/adapters/mcp/server.js with Bun:
codex mcp add opencode-browser-plugin -- bun C:\absolute\path\to\dist\adapters\mcp\server.js
The bundled skill is skills/opencode-browser-plugin/SKILL.md. It follows the open Agent Skills standard and covers connector-first routing, profile selection, action batching, Snowflake-default search, approval tokens, artifacts, and finalization. It ships with agents/openai.yaml for the ChatGPT/Codex desktop Skills picker and MCP dependency metadata.
Install it for every skills-compatible client at once:
opencode-chromium install --client skills
opencode-chromium install --client skills --dry-run
opencode-chromium uninstall --client skills
This copies the skill to ~/.codex/skills/, ~/.claude/skills/, and ~/.agents/skills/ (under opencode-browser-plugin/), and registers an enabled [[skills.config]] entry in ~/.codex/config.toml while removing any stale opencode-browser-adapter entry.
Load extension/ as an unpacked extension, then install the host:
bun run build:extension
bun run install:native-host -- --extension-id <extension-id> --browsers chrome
bun run check:native-host -- --json
The extension source lives in extension-src/: WXT owns the entrypoints, entrypoints/popup/App.tsx is the shared UI root, and static files live under public/. Use bun run extension:dev for development, bun run typecheck:extension for TypeScript checks, and bun run build:extension for the Chrome Web Store-ready package.
Use AGENT_BROWSER_* environment variables for new configuration. The older OPENCODE_BROWSER_* names remain lower-priority aliases through the 1.x compatibility window.
opencode-chromium doctor --json
opencode-chromium verify
opencode-chromium install --client opencode --dry-run
opencode-chromium install --client opencode-mcp --dry-run
opencode-chromium install --client codex --dry-run
opencode-chromium install --client skills --dry-run
opencode-chromium uninstall --client codex --dry-run
opencode-chromium uninstall --client skills --dry-run
Install and uninstall back up the named configuration before changing it, touch only the canonical entry, support dry runs, and report changed files.
The default tool schemas stay small. Request advanced descriptions through:
{"mode":"capabilities","pack":"downloads"}
Execute advanced work through browser_run without adding top-level tools:
{
"steps": [{
"action": "capability",
"capability": "downloads.events",
"input": {}
}]
}
For deep request/response debugging, request the lazy network pack only when needed:
{"mode":"capabilities","pack":"network"}
Then execute network.inspect in browser_run with the target tabId. It follows the tab's CDP request/response lifecycle, supports URL/method/type/status/requestId filters, and returns redacted headers only when includeHeaders is requested. Bodies remain disabled unless explicitly requested and approved; bodyDelivery: "artifact" spills opted-in bodies to the artifact store instead of inline previews. browser_observe mode inspect with target.requestId returns a single request's lifecycle detail.
Large results and screenshots are artifact-first. Screenshot captures are additionally delivered inline as images to OpenCode (tool attachments) and MCP clients (image content), so the model sees the page; MCP clients can also retrieve the original bytes through browser://sessions/<session-id>/artifacts/<artifact-id>, and OpenCode can request the same URI with browser_observe mode artifact.
src/core/ shared runtime, schemas, safety, artifacts, versions
src/browser/ profile-aware IPC client, policies, and operation engine
src/adapters/mcp/ universal MCP server and transports
src/adapters/opencode/ native OpenCode V2 adapter
src/adapters/sdk/ provider schema adapters and direct agent API
src/cli/ install, configure, uninstall, doctor, verify
extension/ Manifest V3 browser integration
native-host/ native messaging host and semantic workers
skills/ provider-neutral browser skill
tests/ unit, contract, browser, and adapter regression tests
docs/ architecture, compatibility, security, and migration guides
bun run build
bun run check:schemas
bun run check:package
bun run check:mcp
bun run test:contracts
bun run test:opencode
bun run pack
bun run test:tarball
bun run check:release
The release check rejects stale V1 paths, personal state, duplicate legacy package surfaces, schema growth beyond budget, and tarballs missing the built adapters.
Contributors run the verification suite locally before review. GitHub Actions reserves the complete release gate for a forward SemVer change to package.json on master; that workflow validates the matching extension manifest, publishes npm through Trusted Publishing, submits the extension to the Chrome Web Store, and creates the matching GitHub tag and generated release notes. GitHub's native secret scanning and push protection guard remote pushes without consuming Actions minutes. No npm token is stored in the repository or workflow, and maintainers do not create release tags manually.
Browser content is untrusted. Consequential actions require short-lived immutable approval tokens; writes are never automatically repeated after uncertain execution. Artifacts are session scoped, expire, reject traversal, and are not written to logs. MCP protocol data stays on stdout and diagnostics stay on stderr.
See docs/architecture.md, docs/security.md, docs/compatibility.md, and docs/migration-1.0.md.
MIT
JavaScript
91.0%
TypeScript
5.7%
CSS
2.2%
PowerShell
1.0%
Browser automation for Chromium-based browsers (Chrome, Edge, Brave) via OpenCode - readable extension, native messaging host, and OpenCode plugin.
11
stars
10
commits
JavaScript
primary language
Sep 8, 2026
updated
Provider-neutral Chromium automation for MCP clients, OpenCode V2, Codex, and direct JavaScript agents.
The roadmap is shaped by users — open a proposal, upvote with reactions, and follow announcements on GitHub Discussions:
planned, in progress, released).
Open a proposal →browser_run, browser_observe, browser_session, and browser_finalize.html/styles (available only through detail: "debug"), and inline responses stay within the 4,096-character budget with oversized output spilled to artifact resources.fullPage: false grabs the visible viewport, fullPage: true captures the entire scrollable page (dimension-capped, with automatic jpeg compression for oversized captures).browser_observe mode diagnostic records CDP traces and computes LCP, CLS, long tasks, TBT, and more in the native host; raw traces are artifact-first and CrUX/field data stays off.Install the published package once, then connect any supported client. The
package ships the CLI (opencode-chromium), the MCP server bin
(opencode-chromium-mcp), the browser extension, and the native host
installer:
npx -y opencode-chromium-mcp
| Client | Surface | Setup |
|---|---|---|
| OpenCode V2 | Native plugin | "plugin": ["opencode-chromium"] in opencode.json |
| Codex | MCP server (stdio) | codex mcp add opencode-browser-plugin -- npx -y opencode-chromium-mcp |
| Any MCP client | MCP server (stdio) | npx -y opencode-chromium-mcp as a stdio server |
| Direct JavaScript | SDK (opencode-chromium/sdk) | import { createBrowserAgent } from "opencode-chromium/sdk" |
npm install -g opencode-chromium
Install opencode-chromium from the Chrome Web Store. The unpacked flow below remains available for development and local testing.
Open chrome://extensions, enable Developer mode, and load the unpacked
extension/ folder from the installed package:
npm root -g
# load "<that path>\opencode-chromium\extension" as an unpacked extension
The extension ID is derived from the load path, so keep the folder where it
is. Note the ID shown in chrome://extensions.
node "$(npm root -g)/opencode-chromium/scripts/install-native-host.js" --extension-id <extension-id> --browsers chrome
Add the package name to the global
~/.config/opencode/opencode.json:
{
"$schema": "https://opencode.ai/config.json",
"plugin": ["opencode-chromium"]
}
Register the MCP server:
codex mcp add opencode-browser-plugin -- npx -y opencode-chromium-mcp
Add the stdio server:
{
"mcpServers": {
"opencode-browser-plugin": {
"command": "npx",
"args": ["-y", "opencode-chromium-mcp"]
}
}
}
Use createBrowserAgent from opencode-chromium/sdk. See the SDK example.
Choose only the setup for your client; you do not need all of them.
opencode-chromium doctor --json
opencode-chromium verify
All four tools (browser_run, browser_observe, browser_session,
browser_finalize) are then available in every connected client. Do not
enable both the native OpenCode adapter and the MCP server in one client
session unless duplicate tools are intentional.
Open the extension’s Profiles tab, choose a connected profile, and click Copy agent selector. Paste that selector into your first browser request. Renaming the current profile is optional.
The Overview defaults to this profile. Choose all profiles, select several profiles, or view older unassigned history. Actions are shared locally across profiles; selecting two profiles counts a shared action once while keeping their execution totals separate. Storage controls apply to the shared database.
Enable action memory in Settings. Page search works with the default settings; model downloads and search tuning are under Advanced search settings. A dash means no result yet, and an unavailable message means the host could not supply statistics.
The installed extension version appears in its header. Package and store versions can differ while a release is under review; a successful upload does not mean store approval.
On connection, the extension compares its version with the local native host and connected CLI/MCP clients. A toolbar badge and compact notice flag differences or unreported versions. Expand How to update for instructions, or choose Remind me in a week; instructions remain in Settings, and a different version combination prompts again. Checks stay local and do not install updates automatically. If local tools are newer, the notice explains that the store extension may still be awaiting approval.
extension/ loaded.bun install --frozen-lockfile
bun run build
bun run build:extension
bun test
bun run check
The package is released under the npm name opencode-chromium. The stable runtime and MCP server identity remains opencode-browser-plugin for client compatibility; the current release version is defined in package.json.
Run the four-tool server over stdio:
bun run mcp
Or use the packaged binary:
opencode-chromium-mcp
Loopback Streamable HTTP is available with:
bun run mcp:http
Non-loopback HTTP requires a bearer token in AGENT_BROWSER_AUTH_TOKEN (or the variable selected with --auth-token-env). The default server name is opencode-browser-plugin. Origin and file-root safety configuration is server-level: pass --allowed-origin / --blocked-origin globs, or set AGENT_BROWSER_ALLOWED_ORIGINS, AGENT_BROWSER_BLOCKED_ORIGINS, and AGENT_BROWSER_ALLOWED_FILE_ROOTS (see docs/mcp.md).
The package root exports the native adapter using OpenCode 1.18.x's official { id, server() } path-plugin module shape, alongside the V2 setup contract:
{
"$schema": "https://opencode.ai/config.json",
"plugin": ["opencode-chromium"]
}
For a local build, point the client at dist/adapters/opencode/index.js or
use the opencode-chromium install --client opencode command. The adapter
registers exactly four tools, sets codemode: false, and returns a cleanup
function for reloads.
The same browser runtime is available through MCP compatibility mode; do not enable both surfaces in one client session unless duplicate tools are intentional.
Register the MCP server from the npm package:
codex mcp add opencode-browser-plugin -- npx -y opencode-chromium-mcp
codex mcp list
From a local checkout, register dist/adapters/mcp/server.js with Bun:
codex mcp add opencode-browser-plugin -- bun C:\absolute\path\to\dist\adapters\mcp\server.js
The bundled skill is skills/opencode-browser-plugin/SKILL.md. It follows the open Agent Skills standard and covers connector-first routing, profile selection, action batching, Snowflake-default search, approval tokens, artifacts, and finalization. It ships with agents/openai.yaml for the ChatGPT/Codex desktop Skills picker and MCP dependency metadata.
Install it for every skills-compatible client at once:
opencode-chromium install --client skills
opencode-chromium install --client skills --dry-run
opencode-chromium uninstall --client skills
This copies the skill to ~/.codex/skills/, ~/.claude/skills/, and ~/.agents/skills/ (under opencode-browser-plugin/), and registers an enabled [[skills.config]] entry in ~/.codex/config.toml while removing any stale opencode-browser-adapter entry.
Load extension/ as an unpacked extension, then install the host:
bun run build:extension
bun run install:native-host -- --extension-id <extension-id> --browsers chrome
bun run check:native-host -- --json
The extension source lives in extension-src/: WXT owns the entrypoints, entrypoints/popup/App.tsx is the shared UI root, and static files live under public/. Use bun run extension:dev for development, bun run typecheck:extension for TypeScript checks, and bun run build:extension for the Chrome Web Store-ready package.
Use AGENT_BROWSER_* environment variables for new configuration. The older OPENCODE_BROWSER_* names remain lower-priority aliases through the 1.x compatibility window.
opencode-chromium doctor --json
opencode-chromium verify
opencode-chromium install --client opencode --dry-run
opencode-chromium install --client opencode-mcp --dry-run
opencode-chromium install --client codex --dry-run
opencode-chromium install --client skills --dry-run
opencode-chromium uninstall --client codex --dry-run
opencode-chromium uninstall --client skills --dry-run
Install and uninstall back up the named configuration before changing it, touch only the canonical entry, support dry runs, and report changed files.
The default tool schemas stay small. Request advanced descriptions through:
{"mode":"capabilities","pack":"downloads"}
Execute advanced work through browser_run without adding top-level tools:
{
"steps": [{
"action": "capability",
"capability": "downloads.events",
"input": {}
}]
}
For deep request/response debugging, request the lazy network pack only when needed:
{"mode":"capabilities","pack":"network"}
Then execute network.inspect in browser_run with the target tabId. It follows the tab's CDP request/response lifecycle, supports URL/method/type/status/requestId filters, and returns redacted headers only when includeHeaders is requested. Bodies remain disabled unless explicitly requested and approved; bodyDelivery: "artifact" spills opted-in bodies to the artifact store instead of inline previews. browser_observe mode inspect with target.requestId returns a single request's lifecycle detail.
Large results and screenshots are artifact-first. Screenshot captures are additionally delivered inline as images to OpenCode (tool attachments) and MCP clients (image content), so the model sees the page; MCP clients can also retrieve the original bytes through browser://sessions/<session-id>/artifacts/<artifact-id>, and OpenCode can request the same URI with browser_observe mode artifact.
src/core/ shared runtime, schemas, safety, artifacts, versions
src/browser/ profile-aware IPC client, policies, and operation engine
src/adapters/mcp/ universal MCP server and transports
src/adapters/opencode/ native OpenCode V2 adapter
src/adapters/sdk/ provider schema adapters and direct agent API
src/cli/ install, configure, uninstall, doctor, verify
extension/ Manifest V3 browser integration
native-host/ native messaging host and semantic workers
skills/ provider-neutral browser skill
tests/ unit, contract, browser, and adapter regression tests
docs/ architecture, compatibility, security, and migration guides
bun run build
bun run check:schemas
bun run check:package
bun run check:mcp
bun run test:contracts
bun run test:opencode
bun run pack
bun run test:tarball
bun run check:release
The release check rejects stale V1 paths, personal state, duplicate legacy package surfaces, schema growth beyond budget, and tarballs missing the built adapters.
Contributors run the verification suite locally before review. GitHub Actions reserves the complete release gate for a forward SemVer change to package.json on master; that workflow validates the matching extension manifest, publishes npm through Trusted Publishing, submits the extension to the Chrome Web Store, and creates the matching GitHub tag and generated release notes. GitHub's native secret scanning and push protection guard remote pushes without consuming Actions minutes. No npm token is stored in the repository or workflow, and maintainers do not create release tags manually.
Browser content is untrusted. Consequential actions require short-lived immutable approval tokens; writes are never automatically repeated after uncertain execution. Artifacts are session scoped, expire, reject traversal, and are not written to logs. MCP protocol data stays on stdout and diagnostics stay on stderr.
See docs/architecture.md, docs/security.md, docs/compatibility.md, and docs/migration-1.0.md.
MIT
JavaScript
91.0%
TypeScript
5.7%
CSS
2.2%
PowerShell
1.0%