Skip to main content
AgentsUse

MCP server, by Microsoft

Playwright MCP Server

Microsoft MCP server that automates a real browser through Playwright using accessibility snapshots instead of screenshots.

stdio (local process)SSE (remote, legacy)Checked 2026-10-07Config checked

Quick facts

Transport
stdio (local process); SSE (remote, legacy)
Runs as
npx (@playwright/mcp)
Review state
Config checked against the official source. Facts checked 2026-10-07. Not locally tested by AgentsUse.

What it does

Playwright MCP gives a model browser automation through Playwright. It works from structured accessibility snapshots, so a vision model is not required, and tool actions target elements deterministically from the page structure. The README contrasts MCP for persistent, stateful agentic loops with the Playwright CLI for token efficient coding agent workflows.

The standard install runs with npx @playwright/mcp@latest and needs Node.js 18 or newer. The server can run headed or headless, pick chrome, firefox, webkit or msedge, emulate devices, and connect to an existing browser through CDP or the Playwright extension.

Browser state can persist in a user data directory, run isolated in memory, or start from a storage state file. A JSON config file can set browser, server, capabilities and context options.

Configuration

Run with npx @playwright/mcp@latest. Node.js 18 or newer is required, and a browser can be installed through Playwright if one is missing.

MCP config (placeholders)
{
  "mcpServers": {
    "playwright": {
      "command": "npx",
      "args": ["@playwright/mcp@latest"]
    }
  }
}

Source: https://github.com/microsoft/playwright-mcp. Placeholders only. Replace them in your own environment, and never commit real keys to a repository.

Environment variableRequiredPurpose
PLAYWRIGHT_MCP_BROWSEROptionalBrowser or chrome channel to use, such as chrome, firefox, webkit or msedge.
PLAYWRIGHT_MCP_HEADLESSOptionalRuns the browser in headless mode when set through the environment form of the --headless option.
PLAYWRIGHT_MCP_PORTOptionalPort to listen on for SSE transport.
PLAYWRIGHT_MCP_CONFIGOptionalPath to the JSON configuration file.
PLAYWRIGHT_MCP_ALLOWED_HOSTSOptionalComma separated list of hosts the server is allowed to serve from. Pass * to disable the host check.
PLAYWRIGHT_MCP_USER_DATA_DIROptionalPath to the user data directory for browser profile persistence.

Verified tools and features

  • browser_navigate Config checked

    Navigates the browser to a URL.

  • browser_snapshot Config checked

    Returns the page accessibility tree with element references for later actions.

  • browser_click and browser_type Config checked

    Clicks an element and types text using accessibility references.

  • browser_fill_form Config checked

    Fills multiple form fields in one call.

  • browser_take_screenshot Config checked

    Captures a screenshot of the current page.

  • browser_evaluate Config checked

    Executes JavaScript in the page context.

Security notes

Security notes
  • The server controls a real browser and can reach pages the browser can reach, including logged in sessions when a persistent profile or extension connection is used.
  • File access is restricted to workspace roots by default. --allow-unrestricted-file-access removes that restriction and also allows file:// URLs, so avoid it unless required.
  • Allowed hosts and blocked or allowed origins shape network reach. The README states origin allow and block lists do not serve as a security boundary and do not affect redirects.
  • Persistent profiles store login state on disk. Use --isolated or a separate --user-data-dir for parallel or sensitive sessions.

An MCP server runs with the permissions of the process you start it from. Scope credentials to the narrowest access the job needs, and review what the client will send before connecting anything sensitive.

Stacks featuring this server

Sources and freshness

Last checked 2026-10-07. Verification label: config checked, which means the configuration and feature list trace to the official source above. It does not mean AgentsUse ran the server. Spotted an error? Send a correction. Back to the MCP server index.