HTTP endpoint
Best local compatibility for MCP AI clients running on the same computer as Social Browser.
http://127.0.0.1:60080/mcp- Streamable HTTP
- Local-only by default
- No certificate setup required
Model Context Protocol · MCP AI
Connect any MCP AI-compatible clients to a persistent Social Browser session. Search and read the web, control real logged-in Profiles, automate browser work, manage proxies and run long tasks from one endpoint.

See the product
Choose what AI can read, automate, and control through MCP AI permissions.
MCP AI connection
Both endpoints are local-only by default. Use HTTP for maximum local client compatibility, or HTTPS when your AI client requires an encrypted secure URL.
Best local compatibility for MCP AI clients running on the same computer as Social Browser.
http://127.0.0.1:60080/mcpEncrypted local MCP AI transport for clients and runtimes that require an HTTPS URL.
https://127.0.0.1:60081/mcpHTTPS certificate
Social Browser generates a unique local self-signed certificate for each installation. Open Settings → MCP AI Permissions, then use Download certificate (.crt) or Copy PEM. If your AI client performs strict TLS validation, import that public certificate into the client runtime trust store.
Why Social Browser MCP AI
Normal browser-control integrations often expose low-level actions and leave the AI to assemble everything itself. Social Browser MCP AI adds higher-level discovery, research, automation and verification on top of real persistent browser Profiles.
AI can work inside persistent Profiles with the browser state already used by the user, including cookies, local storage, settings and user-supplied proxy context.
Search engines, clean URL reading, semantic page snapshots, in-page find, structured extraction and concurrent multi-page research are first-class MCP AI operations.
Workflows, tasks, waits, verification, evidence, recovery and execution receipts help agents check what actually happened instead of trusting a toast message.
MCP AI operation settings can allow actions automatically, ask first or block them. This keeps unattended tasks practical while leaving the final policy with the device owner.
Capabilities
The catalog is discoverable by the AI, so clients do not need to memorize every operation name before they can work.
search.web structured web searchweb.read clean URL readingweb.snapshot, web.find and web.extractweb.readMany and searchAndReadbrowser.tabs.screenshot for managed tab contentbrowser.desktop.sources.list for monitors and app windowsbrowser.desktop.screenshot for a screen or selected windowCapability Truth
Social Browser separates tool discovery from implementation truth. An agent can check whether an operation is registered, implemented, executable under the current policy, blocked, waiting for approval or exposed only as a stable contract.
browser.agent.capability.truth browser.agent.capability.check browser.agent.runtime.verify browser.agent.unattended.check Is the operation exposed to MCP AI?
Does a real executor exist in this version?
Is it allowed now, approval-required or blocked?
Can the runtime preflight it without pretending an external result happened?
This prevents a schema or authorization result from being mistaken for proof that a host action actually executed.
Two-tier web reader
web.read starts with a fast direct HTTP reader for ordinary public pages. When JavaScript rendering, cookies, authenticated state, a Profile proxy, geographic context or other browser state is required, Social Browser can read the page through a real persistent Profile.
searchAndRead({ query: "browser automation MCP", maxResults: 5, read: { mode: "auto", profileId: "my-profile" } }) Search → choose result URLs → read pages concurrently → return structured content to the AI.
Quick setup
Social Browser exposes local Streamable HTTP and HTTPS MCP AI endpoints. HTTP is the recommended default for maximum compatibility; HTTPS is available when the client requires a secure URL.
Keep Social Browser open on the computer that owns the Profiles and browser state you want the AI to use.
Use HTTP for the simplest local setup, or HTTPS when the client requires TLS. Both expose the same MCP AI tools.
http://127.0.0.1:60080/mcphttps://127.0.0.1:60081/mcpReconnect after MCP AI updates so the client reloads the tool catalog, then describe the task in normal language. Agent Discovery can find the right tools and schemas automatically.
Add this to %USERPROFILE%\.codex\config.toml, then restart Codex.
[mcp_servers.social_browser] enabled = true url = "http://127.0.0.1:60080/mcp"
If Codex or another client requires HTTPS, use https://127.0.0.1:60081/mcp and trust the public certificate from Social Browser MCP AI Settings if the runtime validates local certificates strictly.
Choose a Streamable HTTP MCP AI server and use the same endpoint. Client UI and configuration file names differ between products.
http://127.0.0.1:60080/mcphttps://127.0.0.1:60081/mcpRemote connections require explicit server binding and network security configuration. They are not enabled by changing the endpoint IP alone.
Recommended agent flow
The AI does not need to guess operation names or assume an action worked.
browser.agent.guide and capability discovery.browser.agent.tools.search to find the best operation for the goal.browser.agent.tools.get before calling unfamiliar tools.MCP AI operation policies
Social Browser uses operation-level policies. You decide which operation categories run automatically, which require approval and which are blocked. That means repetitive trusted tasks do not need to stop only because the user is not sitting at the computer.
Policies belong to the Social Browser user. An AI client cannot silently rewrite its own approval policy.
What can I ask it to do?
“Open my Client A Profile, go to the dashboard, export the current report and confirm the download finished.”
“Search the web for changes in these five competitors, read the most relevant pages and summarize only what changed this week.”
“Test every proxy in the list in parallel, keep the healthy and slow ones, and bulk-delete the failed results.”
“Create a Workflow that opens this page, fills the form, waits for the result, extracts the confirmation ID and verifies it was saved.”
“Find every Profile tagged Marketing, open the same URL in each one and run this approved workflow.”
“Inspect the current tab, find the correct submit button by role or label, click it, then verify the page state changed.”
“Capture the current tab, then capture the application window if needed, inspect what is visible and tell me what changed.”
FAQ
No. Low-level page actions are available, but MCP AI also exposes Profiles, automation, tasks, proxy management, bulk operations, semantic page understanding, web search, clean URL reading, extraction, verification, recovery and diagnostics.
Yes. Profile-backed operations can use persistent Social Browser Profile state. This is useful when a page depends on cookies, an authenticated session, JavaScript rendering, Profile settings or user-supplied proxy context.
Yes. Operation-level MCP AI policies are designed for unattended tasks. You choose what runs automatically, what asks first and what is blocked.
No. Social Browser lets you add and manage your own proxies. The Proxy Manager can also work with editable public free-proxy list sources, but public proxies can be unstable and should be tested before use.
The Agent Discovery layer provides a guide, searchable tool catalog, schemas, capability truth and plan validation so compatible agents can discover operations instead of relying on a hard-coded list.
Restart or reconnect the MCP AI client if it still shows an old tool catalog. Many clients cache tool definitions for the lifetime of the connection.
Yes. Use https://127.0.0.1:60081/mcp. Social Browser creates a unique local certificate for the installation and lets you download the public .crt file or copy its PEM from MCP AI Settings.
No. HTTP and HTTPS expose the same MCP AI operation catalog. HTTPS encrypts the local transport; it does not unlock additional tools or change your operation policies.
The default HTTPS endpoint uses a per-installation self-signed local certificate. Clients with strict certificate validation may need that public certificate imported into their runtime trust store. The private key is never exported.
No. Remote access is disabled by default and requires explicit server binding plus appropriate network security. The default local HTTPS certificate is intended for localhost and loopback addresses.
No. Capability Truth distinguishes registered tools from implemented executors and current policy state. Agents can check capability truth and runtime readiness before claiming that an operation can execute.
Browser control for AI
Download Social Browser, connect your MCP AI client and let your automation work with the same Profiles and browser state you already use.
MCP reference
Use the capability catalog for tool domains and contract rules, then use the client setup guide to connect a compatible MCP client.
Capability truth, stable resource identity, executor truth, and runtime discovery.
Open MCP Tools →Connect Streamable HTTP clients to the local Social Browser MCP endpoint.
Open MCP Clients →