HNHacker News
TopNewBestAskShowJobs

pitiflautico

7 karma · joined August 14, 2026

submissionscomments
pitiflautico··on NeoBrowser: An MCP server that drives real Chrome with your logged-in sessions
Domain allowlist is in: NEOBROWSER_DOMAIN_ALLOWLIST=github.com,.docs.rs — navigate rejects anything not listed with an error that names the allowed hosts. Exact hosts or .suffix, opt-in (unset = no restriction). Appreciate the push on this one.
pitiflautico··on NeoBrowser: An MCP server that drives real Chrome with your logged-in sessions
Fair challenge. The README's claims are the verifiable kind, though: CI installs real Chrome and runs the stealth checks on every push, the bot.sannysoft run is one cargo test away, and the benchmark vs Playwright MCP is in bench/ with the full methodology. If you find a claim that doesn't hold, open an issue — I'd rather fix it than defend it.
pitiflautico··on NeoBrowser: An MCP server that drives real Chrome with your logged-in sessions
Not quite — the usual browser/computer-use options launch a fresh, cookie-less Chromium, so you hit login walls and bot checks constantly. NeoBrowser drives the real Chrome binary with your actual logged-in profile. That's the part that changes the failure mode.
pitiflautico··on NeoBrowser: An MCP server that drives real Chrome with your logged-in sessions
That's supported as a first-class mode: NEOBROWSER_ATTACH_PORT=9222 attaches to your running Chrome and never patches or kills it. The cookie-import path exists for when you'd rather not keep a debug port open.
pitiflautico··on NeoBrowser: An MCP server that drives real Chrome with your logged-in sessions
I built NeoBrowser because every browser MCP I tried had the same failure mode: it launches a fresh, fingerprintable headless browser with no cookies, so the model hits login walls and bot checks constantly.

NeoBrowser drives the real Google Chrome binary over CDP and can reuse your actual logged-in profile, so the model lands already authenticated and looks like a genuine user — because it is one.

What's different:

- Real sessions: optionally decrypts + injects cookies from your real Chrome profile (macOS Keychain / Linux secret-service / Windows DPAPI). Opt-in; session-identity cookies are excluded so your real browser isn't logged out. - Genuine stealth, not spoofing: real UA matching its Client Hints, real GPU WebGL, navigator.webdriver gone. Passes bot.sannysoft live in CI. It doesn't pretend to beat interactive challenges — reCAPTCHA/Turnstile can still wall you — instead it detects the wall and tells the model how to react. - Human-like input: clicks travel along an eased, jittered path; typing can be per-key with realistic timing. - One ~5 MB static Rust binary, 43 tools (multi-tab, forms, upload/download, search, playbooks), zero runtime deps.

I also ran a neutral benchmark against Playwright MCP with a shared task matrix, nothing tuned to make either win. Honest results: Playwright MCP is faster (my headless frame-forcing costs ~2x latency); NeoBrowser passes upload + session persistence tasks Playwright MCP can't, and on adversarial pages both get walled equally. Full methodology in bench/ if you want to poke holes in it — I'd rather be called out than overclaim.

Repo: https://github.com/pitiflautico/neobrowser