Browser MCP serverOfficialLocal

Playwright MCP Server

Microsoft's Playwright MCP server lets your AI agent drive a real browser: open pages, click, fill in forms and read each page as an accessibility tree.

By Microsoft · Last updated

Set up

Terminal
claude mcp add --transport stdio playwright -- npx -y @playwright/mcp@0.0.82

Needs Node.js. Adds it for you in this project. Add --scope user to have it in every project.

Or share it with your team in .mcp.json

.mcp.json
{
  "mcpServers": {
    "playwright": {
      "command": "npx",
      "args": [
        "-y",
        "@playwright/mcp@0.0.82"
      ]
    }
  }
}

This file is meant to be committed, so secrets are ${NAME}: Claude Code fills them in from each person's environment.

Claude Code MCP docs

What it can do

Reads only look. Writes change something on your account, and read-only mode turns them off.

Reading the page

Reads

  • Take an accessibility snapshot of the page, or search it for text
  • Take a screenshot of the page or one element
  • Read the console messages and the network requests, headers and bodies included
  • Wait for text to appear or disappear

Driving the browser

Writes

  • Open a URL, go back, and open, switch or close tabs
  • Click, hover, drag, type, press keys and pick from dropdowns
  • Fill in a whole form in one go, and accept or dismiss dialogs
  • Upload or drop files from your computer onto the page
  • Resize the window and emulate dark mode, reduced motion and similar

Running code

Writes

  • Run JavaScript in the page
  • Run a Playwright script in the server itself, which its own description calls RCE-equivalent

What it can touch

Official
Yes. Published by Microsoft, who make the product it connects to.
Sign-in
None. It needs no account.
Read-only mode
No. It can do anything your credentials allow.
What leaves your machine
Nothing goes to Microsoft. The browser visits whatever pages your agent opens, and what it reads on them goes to your AI tool's model.
Pinned version
@playwright/mcp@0.0.82 when you run it locally. The remote server is whatever version the publisher is running.
Licence
Apache-2.0
Last reviewed
How we check an MCP server is safe
Check it yourself

MCP servers checklist

0 of 11 checked

Who made it

Before reading a line of it, know whose code you are about to run.

What's inside

The part people skip. Read what your agent will read.

What it can reach

Give it the least access that still does the job.

Keeping it that way

What you checked today is only what runs tomorrow if you pin it.

Your ticks are saved in this browser only.

Playwright's MCP server gives your AI agent a real browser to use. It opens pages, clicks, types and fills in forms, and reads each page as an accessibility tree rather than as pixels, so any model can use it. It is the one to add when you want your agent to check its own work in the running app, reproduce a bug by clicking through it, or draft an end-to-end test from what it did.

Prompts to try

  • "Open localhost:3000, sign up with a test email, and tell me what breaks."
  • "Go through the checkout on localhost:3000 and list every console error you see."
  • "Check the contact form rejects an invalid email, then write a Playwright test for what you just did."
  • "Open the pricing page on mobile width and describe anything that overflows."

Gotchas

  • Every tool can change something in the browser. There is no read-only mode: navigating and clicking are how it works. Only point it at sites where a stray click costs nothing, like your local app or a staging copy.
  • It is logged in as you, if you log in. The default profile keeps cookies on disk, so a site you sign in to stays signed in next time. Use --isolated for throwaway sessions, and never let it browse your email or banking with the agent in control.
  • Pages are untrusted input. Text on a page can hold instructions aimed at your agent. Keep it on sites you control, and read the MCP safety guide before letting it roam.
  • Origin filters are not a sandbox. --allowed-origins and --blocked-origins narrow where the browser goes, but the README says plainly they are not a security boundary and do not affect redirects.
  • Snapshots are big. A long page's snapshot can eat context fast. Ask for a search of the page, or a snapshot of one element, when you know what you need.

When not to use it

For a quick look at a page's text, a fetch tool is cheaper. For running your existing tests, run Playwright Test itself. And when you need console, network and performance detail rather than clicking, the Chrome DevTools MCP server goes deeper.

FAQ

Does the Playwright MCP server use screenshots?

Not to act. It reads the page as an accessibility tree, a text outline of the buttons, links and fields with a reference for each, and clicks by reference. That works with models that cannot read images at all. It can still take screenshots when you ask for one.

Does it keep me logged in between sessions?

By default, yes. It uses a persistent browser profile per project, so cookies and logins stay on disk between runs. Add --isolated to keep the profile in memory and start clean every time.

Should I use the MCP server or the Playwright CLI?

Microsoft's own README says a coding agent may do better with the Playwright CLI and its skills, because a command costs fewer tokens than MCP's tool schemas and page snapshots. The MCP server suits longer loops where the agent keeps one browser open and reasons over the page as it goes.

Is it the same as Playwright Test?

No. Playwright Test runs test files you wrote. The MCP server hands a live browser to your agent, which decides what to click as it goes. It is useful for exploring an app or drafting a test, not for running your suite.

See all MCP servers