C

Claude in Chrome

Anthropic's experimental browser-control extension via MCP.

Works with: Claude DesktopClaude Code

Official server · details last checked

How to install the Claude in Chrome MCP server

Add this to your Claude Desktop MCP configuration:

Install Claude in Chrome extension and enable MCP integration.

Add this to your Claude Code MCP configuration:

Install Claude in Chrome extension and enable MCP integration.

Built by ContextBoltThis directory is built by ContextBolt: MCP-native memory and SEO tools that run alongside Claude in Chrome in the same client.

Explore ContextBolt

Claude in Chrome is Anthropic’s experimental extension for letting Claude see and act inside your actual browser. Rather than spinning up a clean automated browser, it works in the Chrome profile you already use, with the sessions you are already logged into. That is what makes it powerful and what makes it worth being careful with.

What it actually does

The extension gives Claude a view of the current page and the ability to act on it: read content, click, fill fields, and move between pages. Because it runs in your own profile, it can reach applications behind a login without you scripting an authentication flow, which is the step that usually kills browser automation for everyday tasks.

Practical patterns:

  • ‘Read this dashboard and summarise what changed since last week.’
  • ‘Fill this form using the details from the document we just discussed.’
  • ‘Go through these ten tabs and tell me which ones are worth keeping.‘

Why use it

Most browser automation tools are built for testing: deterministic, headless, starting from nothing. That is the wrong shape for “help me with the thing I am looking at”. Working inside a real session means the agent sees what you see, which suits research, admin and the sort of small repetitive web tasks nobody has ever bothered to script.

Gotchas

The authenticated session is the whole risk. An agent operating as you can do anything you can do, and a web page it reads can contain text written specifically to hijack an agent reading it. Prompt injection stops being theoretical the moment the browser is logged in. Enable it for a defined task, watch what it does, and turn it off afterwards. It has also been an experimental product with shifting behaviour, so verify current capability against Anthropic’s own docs rather than any third-party write-up, this one included.

Built by ContextBolt

This directory is built by ContextBolt

We build MCP-native tools that give your AI the context it cannot reach on its own. Bookmarks turns your saved posts into agent-queryable memory. SEO puts live keyword and ranking data inside Claude. Both run alongside Claude in Chrome in the same client.

Explore the products →

Claude in Chrome MCP server: FAQs

How is this different from Playwright or Puppeteer?

Those drive a fresh headless browser with no history. This acts inside your real Chrome profile, so it is already signed in to everything you are signed in to.

Is it safe to leave enabled?

Treat it with care. An agent acting in your logged-in session can reach anything you can reach, including email and banking tabs. Enable it deliberately for a task and turn it off after.

Is it generally available?

It has been an experimental release. Availability and behaviour have moved more than once, so check Anthropic's current documentation rather than trusting any third-party guide.

Does prompt injection matter here?

Very much. A page the agent reads can contain instructions aimed at the agent. That risk is far higher when the browser is authenticated as you.