Docs · MCP Server

Connect Human Browser to your MCP-aware client

Human Browser ships a Model Context Protocol server that gives AI agents a hosted Chromium tab on a clean residential connection. The agent runs user-authorized tasks — research, monitoring, form-fill, public-data gathering — while the human watches a live viewer and can take over at any moment. Drop it into Claude Desktop, Cursor, or Cline with one config block.

Step 1 — Get your HB_TOKEN Email-only signup; try it for $1 by card. Same token authenticates both the MCP server and the A2A endpoint.
Get Token →

Install

The MCP server is bundled inside the same npm package as the SDK. Two transports are supported: local stdio (recommended for Claude Desktop) and remote HTTP (recommended for Cursor and Cline, which support native HTTP transport).

★ Local · stdio

npx (no install)

npx -y @virixlabs/humanbrowser mcp
Global install

npm

npm install -g @virixlabs/humanbrowser
Remote · HTTP

Hosted endpoint

https://agent.humanbrowser.cloud/mcp

Claude Desktop

Edit ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows). Local stdio works out of the box; for the hosted endpoint, wrap with mcp-remote until Claude Desktop ships native HTTP transport.

{
  "mcpServers": {
    "humanbrowser": {
      "command": "npx",
      "args": ["-y", "@virixlabs/humanbrowser", "mcp"],
      "env": { "HB_TOKEN": "hb_live_..." }
    }
  }
}

Cursor

Open Settings → Features → MCP Servers → Add new server. Cursor supports native HTTP transport.

{
  "mcpServers": {
    "humanbrowser": {
      "url": "https://agent.humanbrowser.cloud/mcp",
      "headers": { "Authorization": "Bearer hb_live_..." }
    }
  }
}

Cline (VS Code extension)

Open the Cline sidebar, click the MCP icon, then Configure MCP Servers. Cline supports both stdio and HTTP transports.

{
  "mcpServers": {
    "humanbrowser": {
      "url": "https://agent.humanbrowser.cloud/mcp",
      "headers": { "Authorization": "Bearer hb_live_..." }
    }
  }
}

Authentication

Human Browser uses a single bearer token, passed either as the HB_TOKEN environment variable (stdio transport) or the Authorization: Bearer … header (HTTP transport). Tokens look like hb_live_… and carry a prepaid balance — there are no per-key seat fees or quotas to manage.

To obtain one:

  1. Visit humanbrowser.cloud and enter your email.
  2. Receive your hb_live_… token by email and add a first top-up of $1 (enough for about 4 typical tasks — the median task takes about 8 agent steps and costs $0.24 all-in).
  3. Top up later via Stripe or crypto when you want to keep going. Prepaid, no auto-renew.

The legacy variable name HUMANBROWSER_API_TOKEN is still accepted as an alias for HB_TOKEN.

Tools exposed

Each tool ships with MCP annotations (readOnlyHint, destructiveHint, openWorldHint) so MCP-aware clients can render the correct approval UI and so directory reviewers can assess scope at a glance.

ToolDescriptionHints
humanbrowser_run Start a user-authorized task from a natural-language goal (e.g. "find the top 5 Reddit threads about espresso 2026"). Opens a cloud Chrome on a residential connection and returns task_id + viewer_url immediately; the task keeps running. Optional country, profile and sensitive_data (a flat map such as {"email":"…","password":"…"}, referenced in the goal as <email> / <password> — typed into the page, never shown to the model). writeopen-world
humanbrowser_status Poll a task by task_id (long-polls up to 60 s). Returns state, the answer when finished, and any input-required prompt waiting for the user. Remote HTTP server. read-only
humanbrowser_stream Local stdio package only: follow a task's progress events until it finishes. read-only
humanbrowser_viewer_url Return just the live viewer URL for a task, to share with the person who should watch or take over. read-only

Use cases — legitimate web access

Human Browser is designed for tasks a person could reasonably do themselves in a browser, executed by an agent on their behalf and supervised in real time.

User-authorized research

"Read the last 30 days of posts on r/MachineLearning and summarize the most-discussed papers." Public web, read-only.

Monitoring & alerts

"Check this product page every hour and ping me when the price drops below $300." Polite cadence, single tab.

Form-fill on the user's behalf

"Fill out my visa renewal form with the data in this PDF, then stop before submit so I can review." Human approves the final click.

Side-by-side comparison

"Open these three SaaS pricing pages and extract their per-seat tier." Public marketing content, structured output.

Public-data gathering

"Pull the agenda + speaker list from this conference site." Read-only navigation of pages already meant for human visitors.

Long-tail UI that has no API

"Download my electricity bill PDFs from the utility portal." User is signed in to their own account; agent fetches what the user already has access to.

Live viewer & human takeover

Every humanbrowser_run response includes a viewer_url — a real-time MJPEG stream of the Chromium tab the agent is driving. The human owner can:

Watch every action

The viewer renders the same pixels the agent sees, with a per-step timeline showing what was clicked, typed, or extracted. No black box.

Take over with one click

The "Take control" button immediately pauses the agent and routes keyboard + mouse input from the human's browser into the remote Chromium. Hand back when ready.

Agent asks for help

If the agent hits an MFA prompt, a CAPTCHA, or any "I need a human here" moment, it surfaces an input-required event over MCP and pauses until the user responds. Clients that support MCP elicitation get the question as a native prompt; others get an error from humanbrowser_status that names the question and the viewer URL, where the user can answer. If the task has already ended, start a new humanbrowser_run whose goal carries the full context and the answer.

Authentication. Send Authorization: Bearer hb_live_…, or let your client run OAuth 2.1: the server's 401 carries resource_metadata pointing at /.well-known/oauth-protected-resource (authorization code + PKCE, dynamic client registration, scopes mcp:run mcp:read). Rate limit: 60 requests per minute per token. Finished tasks stay readable for 30 minutes.

Full audit trail

Every session writes a JSON timeline (steps, URLs, screenshots on failure) the operator can review or hand to a compliance team.

Pricing

$0.02 / agent step, AI included
Pay-as-you-go, prepaid balance, no subscription, no auto-renew. Browser time is $0.10 an hour. Residential bandwidth bills at $4/GB, metered per session, and CAPTCHA solves at $0.005 each only when the agent uses them. Your first top-up can be $1; later top-ups start at $5. Full breakdown on the pricing page.

Measured on production over 132 successful customer tasks (Sep 2026), re-priced at today's rates: the median task took about 8 agent steps and costs $0.24 all-in, a quarter cost $0.12 or less. Browser time is billed per second; sessions under 30 seconds and time under human control are not billed.

Compliance & acceptable use

Human Browser is built to be reviewable by directory operators (Anthropic Connectors, Cline MCP Marketplace, OpenAI Apps) and safe for end users. Please read this carefully before deploying.

What Human Browser is for

  • User-authorized web tasks. The human operator owns the goal, watches the run, and can interrupt at any time.
  • Public web navigation. Pages that are meant to be visited by humans without authentication.
  • The user's own authenticated accounts. Agent signs in with credentials the user supplied — same access the user already has.
  • Human-in-the-loop workflows. The agent asks for help (input-required) when it hits MFA, CAPTCHAs, or ambiguous prompts.
  • Clean residential connection. Requests come from a real residential IP so legitimate sites don't reflexively block legitimate browser sessions originated by AI agents.

What Human Browser is not for

  • Scraping behind paywalls or auth walls without the data subject's authorization. Don't point it at someone else's logged-in account or paid content you don't have rights to.
  • Circumventing access controls or Terms-of-Service prohibitions. If a site's ToS forbids automated access for your use case, do not use Human Browser to do it anyway.
  • Bot-evasion as a primary purpose. CAPTCHA solving and residential IPs exist so user-authorized agent sessions look like the human sessions they are — not as a service for defeating anti-abuse systems on sites that have not consented to your activity.
  • Mass scraping, credential stuffing, account creation at scale, fraud, harassment, or any criminal activity. Sessions doing this will be terminated and tokens revoked. We cooperate with law-enforcement requests.
  • Operating without a human owner. Every session is associated with a token tied to a real billing account. No anonymous use.

Full Terms of Service and Privacy Policy. Abuse reports: [email protected].

Wire it into your MCP client in under 5 minutes

Try it for $1 — about 4 typical tasks. Local stdio or hosted HTTP — your choice.

Try it for $1 → View on npm
Top up — $20

Loading secure checkout…

More coins →