Overview
What Playwright MCP does
Playwright MCP exposes browser navigation, page inspection, input, screenshots, network activity, storage, and optional code execution to an MCP client. Its default interaction model is based on accessibility snapshots, giving the model stable element references rather than requiring a vision model for routine tasks. The server is configurable for isolated sessions, persistent profiles, existing browsers, origin controls, and several browser engines.
Best for
- Exploratory browser automation with an agent in the loop
- Reproducing user flows while inspecting page structure
- Long-running browser sessions that benefit from persistent state
Not ideal for
- High-volume deterministic test suites better expressed as Playwright code
- Untrusted browsing with broad filesystem or origin permissions
- Agents with very small context budgets
Capabilities
What an agent can do
- 01
Navigation and structured page snapshots
- 02
Clicks, keyboard input, forms, and file interaction
- 03
Screenshots and optional vision workflows
- 04
Network and console inspection
- 05
Browser storage and permission control
- 06
Chromium, Firefox, WebKit, and Edge selection
Representative tools and operations
browser_navigatebrowser_snapshotbrowser_clickbrowser_typebrowser_fill_formbrowser_take_screenshotbrowser_network_requestsbrowser_console_messages
Installation
Connect Playwright MCP
Use the publisher’s current instructions as the source of truth. The examples below were checked on .
Claude CodeAdd the local stdio server
claude mcp add playwright npx @playwright/mcp@latest
The default starts a headed browser with a reusable profile.
Generic MCP clientUse isolated headless sessions
npx -y @playwright/mcp@latest --headless --isolated
{"command":"npx","args":["-y","@playwright/mcp@latest","--headless","--isolated"]}
Trust and access
Authentication and security notes
Authentication: No service account is required for a local browser. Authentication to websites occurs inside the controlled browser profile or via supplied storage state; remote CDP endpoints may use configured headers.
Review before connecting
- A controlled browser can expose cookies, page content, and logged-in sessions to the connected agent.
- Keep filesystem access restricted to workspace roots unless broader file access is explicitly needed.
- Use origin restrictions as defense in depth, not as a complete security boundary.
- Avoid enabling arbitrary Playwright code execution for untrusted tasks because it is equivalent to code execution in the server process.
Known limitations
- Accessibility snapshots can be verbose on complex pages.
- Visual-only interfaces may require screenshots or the optional vision capability.
- The project notes that CLI-plus-skills can be more context-efficient for coding-agent test workflows.
Evidence
Sources used for this guide
Facts were checked against primary publisher material. Descriptions and guidance are original Graphify summaries.
FAQ
Questions about Playwright MCP
Does Playwright MCP require a vision model?
No. Routine interaction uses structured accessibility snapshots. Screenshots and vision-oriented capabilities remain available when page semantics are insufficient.
Can it attach to an existing browser?
Yes. It can connect through CDP or a supported browser extension, depending on the browser and client setup.