VisibleTab connects local AI agents to a tab in your existing Chrome, Edge, or Brave profile. It keeps the browser visible, reuses your signed-in session, serializes all agent input, asks before site access and external side effects, and stops for CAPTCHA or security challenges.
AI client -> MCP or CLI -> persistent localhost daemon -> extension -> focused browser tab
Focus requirement: while VisibleTab is connected and an agent is acting, leave that browser window visible and focused. Do not use that browser at the same time. Pause or disconnect VisibleTab before taking control yourself.
VisibleTab is a supervision and compatibility tool. It does not hide automation, spoof a fingerprint, solve CAPTCHA, bypass access controls, or guarantee that a site will treat the session as human.
- Uses your existing Chromium profile and signed-in tabs.
- Keeps one daemon and extension session alive instead of reconnecting for every action.
- Gives agents compact structured observations instead of full HTML/page dumps.
- Batches deterministic actions to reduce model/tool round trips.
- Requests browser permission for specific site origins when first approved.
- Requires visible foreground focus for mutating actions and fails closed otherwise.
- Stops and releases browser input when a CAPTCHA or security challenge appears.
- Redacts typed text, credentials, email addresses, URL secrets, and sensitive field values.
- Keeps a size-bounded, rotating local audit log with per-stage timing.
- Has no runtime npm dependencies and sends no telemetry.
See the comparison for a factual tradeoff analysis against BrowserMCP, the Playwright extension, and Chrome DevTools MCP.
VisibleTab works inside the browser profile and tab the user already opened instead of creating a disposable automation-only profile. This preserves the session context that ordinary browsing depends on while keeping the user visibly in control.
- Reuses existing signed-in tabs, cookies, local storage, and page state without exporting them to the agent.
- Keeps one extension and localhost daemon session alive, so a workflow does not reconnect to the browser before every click or field.
- Requires the target tab to be visible, active, and focused before mutating the page.
- Sends browser-level pointer and keyboard input at actual viewport coordinates. In the default supervised mode, it fails closed when trusted input or exact coordinates are unavailable.
- Serializes clicks, typing, scrolling, and navigation so concurrent agent calls cannot race for focus or reorder browser input.
- Uses direct pointer movement and fixed, positive keyboard and scroll pacing for UI stability. Pacing is deterministic, not randomized to imitate a person.
- Waits for navigation, DOM changes, visible text, selectors, and status messages instead of using long fixed sleeps.
- Batches deterministic form steps, then returns compact verification data so the agent observes at meaningful checkpoints rather than after every keystroke.
- Uses DOM and accessibility information first and reserves screenshots for overlays, ambiguous layouts, challenge pages, and debugging.
- Pauses actions and releases browser input when it detects CAPTCHA, human verification, or another security challenge, allowing the user to take over manually.
These choices preserve a normal signed-in browsing context and familiar interaction order. They do not make the agent human, conceal automation, alter browser fingerprints, bypass site controls, or guarantee that a website will accept an automated workflow.
- Windows 10 or 11
- Chrome, Microsoft Edge, or Brave
- Node.js 22 or newer; Node.js 24 LTS is recommended
- Permission to create a per-user Windows Scheduled Task
- An MCP-compatible AI client, or any tool that can call the included CLI
Node's release page currently lists both Node 24 and Node 22 as supported LTS lines: Node.js releases.
Download and install Node.js 24 LTS from nodejs.org. Keep the
installer option that adds Node to PATH, then open a new PowerShell window and verify:
node --versionThe reported Node major version must be 22 or newer.
Download the latest source ZIP from this repository's Releases page, extract it, open PowerShell in the extracted directory, and run:
powershell -NoProfile -ExecutionPolicy Bypass -File .\scripts\setup.ps1Setup copies VisibleTab to %LOCALAPPDATA%\VisibleTab Agent Bridge, creates a pairing token
without printing it, locks the token/config files to your Windows account, installs a hidden
per-user daemon task, and prints the extension directory.
Open the correct extensions page:
| Browser | Address |
|---|---|
| Chrome | chrome://extensions |
| Edge | edge://extensions |
| Brave | brave://extensions |
Then:
- Enable Developer mode.
- Select Load unpacked.
- Choose
%LOCALAPPDATA%\VisibleTab Agent Bridge\extension. - Pin VisibleTab Agent Bridge.
- Open its popup and select Connect.
Setup placed defaults.json in that installed extension directory, so manual token copying
is not required.
Claude Code:
claude mcp add visibletab --scope user -- visibletab-mcpCodex CLI, in %USERPROFILE%\.codex\config.toml:
[mcp_servers.visibletab]
command = "visibletab-mcp"Generic MCP clients:
{
"mcpServers": {
"visibletab": {
"command": "visibletab-mcp"
}
}
}Open a new terminal after setup if the command is not found. Absolute-path configurations and additional clients are documented in AI agent setup.
visibletab doctor
visibletab statusdoctor does not print the pairing token. The overall result becomes healthy after the
extension is loaded and connected.
For expanded screenshots and troubleshooting, read the installation guide.
The efficient loop is:
- Call
browser_status, thenbrowser_list_tabs. - Activate the target tab and ask the user to leave the browser focused.
- Call
browser_preflightto skip paid, broken, unsuitable, or challenge-blocked sites. - Call
browser_observefor compact forms, fields, links, buttons, blockers, and refs. - Use
browser_submit_formorbrowser_batchfor deterministic grouped actions. - Re-observe after navigation or a major DOM change.
- Use screenshots only for visual ambiguity, overlays, or debugging.
The reusable instructions for AI clients live in skill/SKILL.md.
| Tool | Purpose |
|---|---|
browser_status |
Connection, policy, capabilities, and recent redacted timings |
browser_list_tabs |
Find exact tab IDs |
browser_activate_tab |
Focus the target tab/window before mutation |
browser_preflight |
Classify a target before spending time on it |
browser_observe |
Compact JSON forms, fields, controls, messages, and blockers |
browser_batch |
Run up to 25 checked actions in one round trip |
browser_submit_form |
Fill many fields and optionally submit in one call |
browser_snapshot |
Accessibility-style outline with stable refs |
browser_wait_for |
Event-based wait for text/selector presence or absence |
browser_screenshot |
Visual fallback; not the default observer |
browser_eval, history search, and bookmark search are absent by default. They appear only
after their daemon capability is explicitly enabled; history/bookmarks also need extension
permission.
- The daemon binds to
127.0.0.1unless a developer explicitly changes the source policy. - HTTP calls require a 256-bit pairing token.
- The extension token is carried in a WebSocket subprotocol header, not a URL or log line.
- WebSocket
Originis restricted to Chromium extension origins when present. - Browser-internal URLs and default financial, government, and account-management hosts are denied.
- First use of a domain requires both VisibleTab approval and Chromium origin permission.
- Send, submit, post, publish, purchase, delete, upload, and similar actions require approval.
- Mutations require the active tab, focused browser window, exact coordinates, and trusted browser input.
- CAPTCHA/access-denied/security pages pause the bridge and detach controlled tabs.
- Arbitrary page JavaScript, history, bookmarks, and cookies are disabled by default.
- Audit files rotate and redact typed text, credentials, tokens, email addresses, and sensitive URLs.
- Pause, Disconnect, and Release tabs are always available in the extension popup.
Read the security model before enabling broader capabilities.
VisibleTab works well for ordinary signed-in forms, navigation, CRUD-style web apps, content review, dashboards, uploads, and repeatable workflows whose controls are represented in the DOM or accessibility tree.
It cannot reliably operate browser-internal pages, hidden/background tabs, OS-native dialogs, DRM/protected surfaces, another extension's pages, or controls unavailable to both the DOM and browser-level coordinates. It deliberately stops at CAPTCHA and security verification. Sites may still detect, throttle, challenge, or prohibit automation; their terms and policies remain the user's responsibility.
visibletab doctor
visibletab rotate-token
npm testTo update, extract a newer release and run scripts\setup.ps1 again, then reload the unpacked
extension. To uninstall:
powershell -NoProfile -ExecutionPolicy Bypass -File `
"$env:LOCALAPPDATA\VisibleTab Agent Bridge\scripts\uninstall.ps1"Add -PurgeData to remove configuration and audit logs too.
git clone <repository-url>
cd visibletab-agent-bridge
npm test
node daemon/server.jsThere is no dependency install step. See CONTRIBUTING.md and architecture notes.
Apache License 2.0. See LICENSE.