Human Browser ships a Model Context Protocol server that gives AI agents a hosted Chromium tab on a clean residential connection. The agent runs user-authorized tasks — research, monitoring, form-fill, public-data gathering — while the human watches a live viewer and can take over at any moment. Drop it into Claude Desktop, Cursor, or Cline with one config block.
HB_TOKEN
Email-only signup; try it for $1 by card. Same token authenticates both the MCP server and the A2A endpoint.
The MCP server is bundled inside the same npm package as the SDK. Two transports are supported: local stdio (recommended for Claude Desktop) and remote HTTP (recommended for Cursor and Cline, which support native HTTP transport).
npx -y @virixlabs/humanbrowser mcp
npm install -g @virixlabs/humanbrowser
https://agent.humanbrowser.cloud/mcp
Edit ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows). Local stdio works out of the box; for the hosted endpoint, wrap with mcp-remote until Claude Desktop ships native HTTP transport.
{
"mcpServers": {
"humanbrowser": {
"command": "npx",
"args": ["-y", "@virixlabs/humanbrowser", "mcp"],
"env": { "HB_TOKEN": "hb_live_..." }
}
}
}
Open Settings → Features → MCP Servers → Add new server. Cursor supports native HTTP transport.
{
"mcpServers": {
"humanbrowser": {
"url": "https://agent.humanbrowser.cloud/mcp",
"headers": { "Authorization": "Bearer hb_live_..." }
}
}
}
Open the Cline sidebar, click the MCP icon, then Configure MCP Servers. Cline supports both stdio and HTTP transports.
{
"mcpServers": {
"humanbrowser": {
"url": "https://agent.humanbrowser.cloud/mcp",
"headers": { "Authorization": "Bearer hb_live_..." }
}
}
}
Human Browser uses a single bearer token, passed either as the HB_TOKEN environment variable (stdio transport) or the Authorization: Bearer … header (HTTP transport). Tokens look like hb_live_… and carry a prepaid balance — there are no per-key seat fees or quotas to manage.
To obtain one:
hb_live_… token by email and add a first top-up of $1 (enough for about 4 typical tasks — the median task takes about 8 agent steps and costs $0.24 all-in).The legacy variable name HUMANBROWSER_API_TOKEN is still accepted as an alias for HB_TOKEN.
Each tool ships with MCP annotations (readOnlyHint, destructiveHint, openWorldHint) so MCP-aware clients can render the correct approval UI and so directory reviewers can assess scope at a glance.
| Tool | Description | Hints |
|---|---|---|
| humanbrowser_run | Start a user-authorized task from a natural-language goal (e.g. "find the top 5 Reddit threads about espresso 2026"). Opens a cloud Chrome on a residential connection and returns task_id + viewer_url immediately; the task keeps running. Optional country, profile and sensitive_data (a flat map such as {"email":"…","password":"…"}, referenced in the goal as <email> / <password> — typed into the page, never shown to the model). |
writeopen-world |
| humanbrowser_status | Poll a task by task_id (long-polls up to 60 s). Returns state, the answer when finished, and any input-required prompt waiting for the user. Remote HTTP server. |
read-only |
| humanbrowser_stream | Local stdio package only: follow a task's progress events until it finishes. | read-only |
| humanbrowser_viewer_url | Return just the live viewer URL for a task, to share with the person who should watch or take over. | read-only |
Human Browser is designed for tasks a person could reasonably do themselves in a browser, executed by an agent on their behalf and supervised in real time.
"Read the last 30 days of posts on r/MachineLearning and summarize the most-discussed papers." Public web, read-only.
"Check this product page every hour and ping me when the price drops below $300." Polite cadence, single tab.
"Fill out my visa renewal form with the data in this PDF, then stop before submit so I can review." Human approves the final click.
"Open these three SaaS pricing pages and extract their per-seat tier." Public marketing content, structured output.
"Pull the agenda + speaker list from this conference site." Read-only navigation of pages already meant for human visitors.
"Download my electricity bill PDFs from the utility portal." User is signed in to their own account; agent fetches what the user already has access to.
Every humanbrowser_run response includes a viewer_url — a real-time MJPEG stream of the Chromium tab the agent is driving. The human owner can:
The viewer renders the same pixels the agent sees, with a per-step timeline showing what was clicked, typed, or extracted. No black box.
The "Take control" button immediately pauses the agent and routes keyboard + mouse input from the human's browser into the remote Chromium. Hand back when ready.
If the agent hits an MFA prompt, a CAPTCHA, or any "I need a human here" moment, it surfaces an input-required event over MCP and pauses until the user responds. Clients that support MCP elicitation get the question as a native prompt; others get an error from humanbrowser_status that names the question and the viewer URL, where the user can answer. If the task has already ended, start a new humanbrowser_run whose goal carries the full context and the answer.
Authentication. Send Authorization: Bearer hb_live_…, or let your client run OAuth 2.1: the server's 401 carries resource_metadata pointing at /.well-known/oauth-protected-resource (authorization code + PKCE, dynamic client registration, scopes mcp:run mcp:read). Rate limit: 60 requests per minute per token. Finished tasks stay readable for 30 minutes.
Every session writes a JSON timeline (steps, URLs, screenshots on failure) the operator can review or hand to a compliance team.
Measured on production over 132 successful customer tasks (Sep 2026), re-priced at today's rates: the median task took about 8 agent steps and costs $0.24 all-in, a quarter cost $0.12 or less. Browser time is billed per second; sessions under 30 seconds and time under human control are not billed.
Human Browser is built to be reviewable by directory operators (Anthropic Connectors, Cline MCP Marketplace, OpenAI Apps) and safe for end users. Please read this carefully before deploying.
input-required) when it hits MFA, CAPTCHAs, or ambiguous prompts.Full Terms of Service and Privacy Policy. Abuse reports: [email protected].
Try it for $1 — about 4 typical tasks. Local stdio or hosted HTTP — your choice.
Try it for $1 → View on npmLoading secure checkout…