Playwright's MCP server gives your AI agent a real browser to use. It opens pages, clicks, types and fills in forms, and reads each page as an accessibility tree rather than as pixels, so any model can use it. It is the one to add when you want your agent to check its own work in the running app, reproduce a bug by clicking through it, or draft an end-to-end test from what it did.
Prompts to try
- "Open localhost:3000, sign up with a test email, and tell me what breaks."
- "Go through the checkout on localhost:3000 and list every console error you see."
- "Check the contact form rejects an invalid email, then write a Playwright test for what you just did."
- "Open the pricing page on mobile width and describe anything that overflows."
Gotchas
- Every tool can change something in the browser. There is no read-only mode: navigating and clicking are how it works. Only point it at sites where a stray click costs nothing, like your local app or a staging copy.
- It is logged in as you, if you log in. The default profile keeps cookies on
disk, so a site you sign in to stays signed in next time. Use
--isolatedfor throwaway sessions, and never let it browse your email or banking with the agent in control. - Pages are untrusted input. Text on a page can hold instructions aimed at your agent. Keep it on sites you control, and read the MCP safety guide before letting it roam.
- Origin filters are not a sandbox.
--allowed-originsand--blocked-originsnarrow where the browser goes, but the README says plainly they are not a security boundary and do not affect redirects. - Snapshots are big. A long page's snapshot can eat context fast. Ask for a search of the page, or a snapshot of one element, when you know what you need.
When not to use it
For a quick look at a page's text, a fetch tool is cheaper. For running your existing tests, run Playwright Test itself. And when you need console, network and performance detail rather than clicking, the Chrome DevTools MCP server goes deeper.