open source by Revitt

e17

Semantic browser control for agents.

brw runs a real, visible Chrome and exposes it over MCP and HTTP. Agents act from stable refs like e17 instead of CSS selectors or screenshots, and get a plain observation back after every action — so they know what actually happened.

control
MCP + HTTP
from
Revitt
licence
AGPL-3.0
source
GitHub

why brw

Built to win on real web work

Other agent browsers burn tokens re-reading pixels, lock you to one vendor, and stall at the login wall. brw takes the other path.

faster

Fewer turns, fewer tokens

Pre-release head-to-heads vs Claude-in-Chrome: same tasks, fewer turns and fewer tokens. Agents act from stable refs, not a fresh screenshot each turn. Public benchmark on the way.

agnostic

Any agent harness

Not tied to one vendor's browser. Claude Code, Codex, Cursor, opencode, pi, Gemini or your own client — anything that speaks MCP or HTTP drives the same brw.

whole web

The whole web, not a sandbox

A real browser on your profile reaches any page you can — gated dashboards, signed-in apps, content a locked-down agent browser can't.

what it is

A real browser agents can drive by ref

brw controls headed Chrome/Chromium through CDP and exposes it as MCP tools and an HTTP JSON API. It is the actual web — signed-in tabs, real clicks and forms — not a sandboxed copy or a stack of screenshots.

ref

Act from stable refs

Snapshots combine DOM and accessibility data into stable refs like e17. Agents click, type, fill, select, scroll, drag, upload, wait and assert by ref — not by brittle CSS selectors or by re-reading a screenshot every turn.

read

Read the page semantically

Pull prose, links, headings, forms, tables and structured product data straight from the page. Screenshots are kept as a visual fallback, with optional Set-of-Marks overlays.

observe

An observation after every action

Every action returns a post-action observation, so the agent knows what changed instead of guessing. Acting from refs and observations means fewer turns, less token spend and less wall time than re-interpreting pixels.

what's inside

Built for real, signed-in web work

The full MCP surface is large; run brwd --mcp --mcp-tools core to advertise just the common-flow tools while keeping everything callable.

01

Cross-harness

stdio MCP for agent harnesses and an HTTP JSON API for custom clients. The same real browser, reachable from wherever your agent runs.

02

SSH-first remote runtime

Remote control is a first-class path. The visible browser stays on the machine that owns the profile; SSH carries stdio MCP, so cookies, passkeys and downloads never leave home.

03

Installed-profile bridge

A Chrome extension bridges to an already-authenticated installed Chrome profile — the auth you already have, without copying cookies or fighting Chrome's remote-debug lockdown.

04

Semantic snapshot, read, find

Snapshots combine DOM and accessibility data. Read prose, links, headings, forms, tables and structured product data. Find elements and act on them by stable ref.

05

Tabs, downloads, network

Tabs and tab groups, downloads, console, network capture and request replay, plus cancellation. Organise visible Chrome work into named runs the human can watch.

06

Set-of-Marks overlays

Screenshots are a visual fallback, not the main channel — with optional Set-of-Marks overlays that label elements with the same refs the agent acts on.

quick start

Install, then run as MCP

Native installers put brwd, brwctl,brwcheck, and brw-devtools-mcp on your PATH. Pick the release asset for your platform, then run the daemon as stdio MCP or expose the HTTP API on loopback.

For remote and installed-Chrome setups, see the install docs.

recommendedNative installers from GitHub releases

  • Windows: .msi for amd64 or arm64.
  • macOS: universal .pkg.
  • Linux: .deb or .rpm for amd64 or arm64.
Open releases
# after installing from a release
# run as an MCP server over stdio
$ brwd --mcp --http off

# or expose the HTTP API on loopback
$ brwd --http 127.0.0.1:17310
# open a page and read its controls
$ curl -s 127.0.0.1:17310/api/browser/open \
    -H 'content-type: application/json' \
    -d '{"url":"https://example.com"}'

$ curl -s 127.0.0.1:17310/api/page/snapshot | jq
# source build if you need it
$ git clone https://github.com/Don-Works/brw.git
$ cd brw
$ make build
$ ./bin/brwd --mcp --http off

install

Daemon first, Chromium bridge when you need real profile auth

Start with a native brw installer from GitHub releases. The extension is only needed when you want the daemon to bridge into an already-signed-in Chrome or Chromium profile over ws://127.0.0.1.

brw is open source — and so is Chromium, so it's what we champion. On Chromium you force-install the extension and get auto-updates from a single policy file pointed at brw's own update server — no Chrome Web Store, no review queue, no gatekeeping. It works on Chrome too.

One permanent extension ID, trusted by the daemon with zero config:

amocjcgddnoakjijfggdpnefdnboilpe

daemonNative package installers

GitHub releases ship .msi for Windows, a universal macOS .pkg, and Linux .deb/ .rpm packages. They put the brw commands on PATH and install the extension, tests, README, and licence into the platform share directory.

Download from releases

recommendedChromium — force-install + auto-update

Point Chromium at brw's self-hosted update manifest. It installs the signed package and keeps it current automatically. Drop one policy file for your platform:

No policy at all? On Chromium, brwd can launch the browser with the extension already loaded — --load-extension still works on Chromium (Chrome 137+ dropped it), so there is nothing to click.

also worksChrome — load unpacked

  1. Run make install-extension (or open chrome://extensions).
  2. Turn on Developer mode, click Load unpacked, choose the extension/ folder.
  3. Run brwd --bridge and brw is on your real browser.

A one-click Chrome Web Store build is in review; until it lands, load-unpacked installs the exact same extension and ID.

safety

A normal browser, on a short leash

brw uses a normal visible browser and a persistent user profile. It does not add stealth code, CAPTCHA bypass, MFA bypass, fraud-check bypass, consent bypass or cookie extraction. Browser-control HTTP binds to loopback by default; for remote use, prefer stdio MCP over SSH so the profile stays on the machine that owns it. Released under AGPL-3.0 — free to use, change and build on, with improvements shared back. If that doesn't fit your business, talk to Revitt about a commercial licence.

Browse the code