Back to Browse

Capmonster Mcp Patchright Captcha Solver MCP Server

Developer ToolsLow Risk9.4MCP RegistryLocal
Free

Server data from the Official MCP Registry

Browser automation MCP for solving captchas with CapMonster Cloud via Patchright.

About

Browser automation MCP for solving captchas with CapMonster Cloud via Patchright.

Security Report

9.4
Low Risk9.4Low Risk

Valid MCP server (1 strong, 1 medium validity signals). 1 code issue detected. 1 known CVE in dependencies โš ๏ธ Package registry links to a different repository than scanned source. Imported from the Official MCP Registry. 2 finding(s) downgraded by scanner intelligence.

4 files analyzed ยท 3 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

file_system

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-capmonstercloud-capmonster-mcp-patchright-captcha-solver": {
      "args": [
        "-y",
        "capmonster-mcp-patchright"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

capmonster-mcp-patchright

๐Ÿ›ก๏ธ Undetectable browser MCP server โ€” 66 tools, Patchright-powered, zero CDP fingerprint.

![npm] ![MCP]

Passes Cloudflare / Akamai / Kasada / Datadome.

Fork of mcp-patchright that adds a per-call world: "main" option to browser_evaluate / browser_run_code_unsafe, so page-defined window globals are visible and callable. Defaults to Patchright's isolated stealth world (matching upstream); opt into main only when a page's own script needs to see or be called by your evaluated code. Everything else matches upstream mcp-patchright.

Why Patchright, not Playwright?

PlaywrightPatchright
Runtime.enableโœ… sends (detectable)โŒ removed
Console.enableโœ… sendsโŒ removed
--enable-automation flagโœ… presentโŒ removed
navigator.webdrivertruefalse / undefined
Anti-bot evasionโŒโœ…

See the full comparison for details.

Quick start

npm i -g capmonster-mcp-patchright
capmonster-mcp-patchright --port 9321 --host 127.0.0.1

With Claude / GPT / agents

{
  "mcpServers": {
    "patchright": {
      "command": "npx",
      "args": ["capmonster-mcp-patchright", "--port", "9321", "--host", "127.0.0.1"]
    }
  }
}

Features

  • 66 MCP tools โ€” full browser automation surface
  • world: "main" opt-in โ€” browser_evaluate / browser_run_code_unsafe can run in the page's real world to see/call page-defined globals (default stays isolated/stealth)
  • browser_find โ€” search the current aria snapshot for text/regex, cheaper than a full browser_snapshot
  • browser_save_blob โ€” save a Blob/data URL produced by page code to disk
  • 3 transports โ€” stdio, SSE, Streamable HTTP (/mcp)
  • Persistent profiles โ€” real Chrome profile, reuse across sessions
  • Multi-page โ€” tab management (new, list, switch, close)
  • Owner-scoped HTTP sessions โ€” isolate tabs per caller with owner query/header
  • CDP attach โ€” control an already-running Chrome
  • Network tracking + interception โ€” request list/detail, offline toggle, block/mock routes
  • Session import/export โ€” browser_storage_save / browser_storage_load (cookies + localStorage)
  • Granular storage โ€” per-key cookie / localStorage / sessionStorage CRUD (browser_cookie_*, browser_localstorage_*, browser_sessionstorage_*)
  • Authenticated API requests โ€” browser_api_request reuses session cookies (hybrid scraping)
  • Text/HTML extraction โ€” browser_get_visible_text / _html (token-light)
  • Iframe-aware โ€” pass frameSelector to any element tool (click/fill/type/hover/press/wait_for/select/drag) to act inside an iframe
  • PDF export โ€” browser_save_pdf via CDP (works in headed/stealth mode)
  • Video recording โ€” browser_start with recordVideo, browser_video_save; .webm flushed on browser_close
  • Element highlight โ€” browser_highlight / browser_hide_highlight overlays for screenshots & recordings
  • Stealth profiles โ€” proxy / geolocation / locale / timezone / colorScheme
  • Console capture โ€” real-time console message stream
  • Fingerprint check โ€” browser_fingerprint_check diagnostics
  • Virtual passkeys โ€” create, import, list, and delete WebAuthn credentials with private keys redacted by default

Tools

Full comparison HTML in /docs/tool-comparison.html.

  • browser_start
  • browser_status
  • browser_navigate
  • browser_new_page
  • browser_pages
  • browser_switch_page
  • browser_close_page
  • browser_snapshot
  • browser_find
  • browser_take_screenshot
  • browser_click
  • browser_fill
  • browser_type
  • browser_hover
  • browser_press_key
  • browser_wait_for
  • browser_evaluate
  • browser_fingerprint_check
  • browser_navigate_back
  • browser_select_option
  • browser_handle_dialog
  • browser_file_upload
  • browser_network_requests
  • browser_network_request
  • browser_console_messages
  • browser_resize
  • browser_drag
  • browser_fill_form
  • browser_run_code_unsafe
  • browser_add_init_script
  • browser_network_state_set
  • browser_api_request
  • browser_get_visible_text
  • browser_get_visible_html
  • browser_iframe_click
  • browser_iframe_fill
  • browser_route_block
  • browser_route_mock
  • browser_route_clear
  • browser_storage_save
  • browser_storage_load
  • browser_cookie_list
  • browser_cookie_get
  • browser_cookie_set
  • browser_cookie_delete
  • browser_cookie_clear
  • browser_localstorage_list
  • browser_localstorage_get
  • browser_localstorage_set
  • browser_localstorage_delete
  • browser_localstorage_clear
  • browser_sessionstorage_list
  • browser_sessionstorage_get
  • browser_sessionstorage_set
  • browser_sessionstorage_delete
  • browser_sessionstorage_clear
  • browser_passkey_install
  • browser_passkey_create
  • browser_passkey_list
  • browser_passkey_delete
  • browser_video_save
  • browser_highlight
  • browser_hide_highlight
  • browser_save_blob
  • browser_save_pdf
  • browser_close

Development

Owner-scoped HTTP sessions

HTTP mode requires a stable owner on the MCP URL (?owner=<id>) or with the X-Browser-Owner header. Page listing, switching, navigation, and closing are restricted to that owner's tabs. Delete /owners?owner=<id> to close all tabs owned by one caller without stopping the browser or clearing the profile.

npm install
npm run build
node dist/index.js

Release

Install the matching Chromium build once, then prepare a release from the exact dependency versions in package-lock.json, run the full verification suite, and inspect the package without publishing it:

npx patchright install chromium
npm run release:check
npm publish

By default, browser_start launches Chromium via patchright as headed real Chrome with a persistent profile at:

~/.maestro/stealth-playwright-mcp/profiles/default

You can override it with the userDataDir tool argument or STEALTH_PLAYWRIGHT_USER_DATA_DIR.

To attach to an already-running Chrome instead of launching one, start Chrome with remote debugging and pass cdpEndpoint to browser_start:

google-chrome --remote-debugging-port=9222 --user-data-dir=$HOME/.maestro/stealth-playwright-mcp/profiles/cdp
{ "cdpEndpoint": "http://127.0.0.1:9222" }

browser_snapshot returns Playwright's AI aria snapshot. Use [ref=eN] values from that snapshot with browser_click, browser_fill, browser_type, browser_hover, browser_press, and browser_wait_for by passing { "ref": "eN" }. CSS selectors remain supported via { "selector": "..." }.

MCP config example:

{
  "mcpServers": {
    "patchright": {
      "command": "node",
      "args": ["/path/to/capmonster-mcp-patchright/dist/index.js"]
    }
  }
}

Direction

Shipped:

  • โœ… persistent user data dirs
  • โœ… CDP attach to real Chrome
  • โœ… proxy / timezone / locale / geolocation profiles
  • โœ… accessibility snapshots for LLM-friendly page control
  • โœ… fingerprint diagnostics
  • โœ… network interception (block / mock)
  • โœ… session import/export (storageState)
  • โœ… PDF export
  • โœ… authenticated API requests (reuse browser cookies)
  • โœ… lightweight text/HTML extraction
  • โœ… iframe actions
  • โœ… world: "main" opt-in for browser_evaluate / browser_run_code_unsafe
  • โœ… aria-snapshot search (browser_find)
  • โœ… save Blob/data URL output to disk (browser_save_blob)

Next:

  • rebrowser-playwright backend
  • codegen sessions
  • coordinate-based (vision) clicks
  • tracing / video recording

Reviews

No reviews yet

Be the first to review this server!