Skip to content
Graphify
First-party publisher Registry listed

Playwright MCP

Let agents navigate and operate web pages through Playwright's structured accessibility snapshots and persistent browser state.

Overview

What Playwright MCP does

Playwright MCP exposes browser navigation, page inspection, input, screenshots, network activity, storage, and optional code execution to an MCP client. Its default interaction model is based on accessibility snapshots, giving the model stable element references rather than requiring a vision model for routine tasks. The server is configurable for isolated sessions, persistent profiles, existing browsers, origin controls, and several browser engines.

Best for

  • Exploratory browser automation with an agent in the loop
  • Reproducing user flows while inspecting page structure
  • Long-running browser sessions that benefit from persistent state

Not ideal for

  • High-volume deterministic test suites better expressed as Playwright code
  • Untrusted browsing with broad filesystem or origin permissions
  • Agents with very small context budgets

Capabilities

What an agent can do

  1. 01

    Navigation and structured page snapshots

  2. 02

    Clicks, keyboard input, forms, and file interaction

  3. 03

    Screenshots and optional vision workflows

  4. 04

    Network and console inspection

  5. 05

    Browser storage and permission control

  6. 06

    Chromium, Firefox, WebKit, and Edge selection

Representative tools and operations

browser_navigatebrowser_snapshotbrowser_clickbrowser_typebrowser_fill_formbrowser_take_screenshotbrowser_network_requestsbrowser_console_messages

Installation

Connect Playwright MCP

Use the publisher’s current instructions as the source of truth. The examples below were checked on .

Claude CodeAdd the local stdio server
Command
claude mcp add playwright npx @playwright/mcp@latest
Configuration
The default starts a headed browser with a reusable profile.
Generic MCP clientUse isolated headless sessions
Command
npx -y @playwright/mcp@latest --headless --isolated
Configuration
{"command":"npx","args":["-y","@playwright/mcp@latest","--headless","--isolated"]}

Trust and access

Authentication and security notes

Authentication: No service account is required for a local browser. Authentication to websites occurs inside the controlled browser profile or via supplied storage state; remote CDP endpoints may use configured headers.

Review before connecting

  • A controlled browser can expose cookies, page content, and logged-in sessions to the connected agent.
  • Keep filesystem access restricted to workspace roots unless broader file access is explicitly needed.
  • Use origin restrictions as defense in depth, not as a complete security boundary.
  • Avoid enabling arbitrary Playwright code execution for untrusted tasks because it is equivalent to code execution in the server process.

Known limitations

  • Accessibility snapshots can be verbose on complex pages.
  • Visual-only interfaces may require screenshots or the optional vision capability.
  • The project notes that CLI-plus-skills can be more context-efficient for coding-agent test workflows.

Evidence

Sources used for this guide

Facts were checked against primary publisher material. Descriptions and guidance are original Graphify summaries.

FAQ

Questions about Playwright MCP

Does Playwright MCP require a vision model?

No. Routine interaction uses structured accessibility snapshots. Screenshots and vision-oriented capabilities remain available when page semantics are insufficient.

Can it attach to an existing browser?

Yes. It can connect through CDP or a supported browser extension, depending on the browser and client setup.

Editorial review · MCP server

What this page is based on

Server capabilities and operational notes are tied to the recorded source set and review date.

Review basis
MCP server record and linked primary evidence
Last checked
Jul 11, 2026
Evidence links
3 recorded in the page data

Source snapshot is 91 days old; verify upstream details before relying on pricing, availability, or security claims.