Skip to content

Solutions · Cursor

A browser for Cursor's agent.

Add one entry to .cursor/mcp.json. Cursor's agent can then read docs behind your login, check the page it just built and fill in forms, in a browser that remembers you.

.cursor/mcp.json

{
  "mcpServers": {
    "webpilot": {
      "url": "https://api.webpilot.si/mcp",
      "headers": { "Authorization": "Bearer ${env:WEBPILOT_TOKEN}" }
    }
  }
}

How it works

01

What Cursor gets

Over 50 browser_* tools over MCP. Cursor opens a tab, takes a snapshot (a list of the page's interactive elements with refs like e12) and acts by ref: click, type, fill a form, choose an option, upload a file. Most pages need no screenshot at all.

Tabs are opened in read mode or act mode. A read tab blocks every write at the network level, so looking around can never submit anything. The agent asks for an act tab only when it has to change something.

  • Snapshots with element refs; read_text for the rendered text
  • Click, type, fill, select, upload, hover, scroll, keys
  • Downloads as text, rows or files; extract tables and links
  • browser_read: a page as Markdown without opening a tab

02

A real browser, not a fetch

The browser is a headed Chromium on its own virtual screen, with no automation flags. Sites see a normal browser with your cookies, so pages that block headless clients usually load as they would for you.

It is yours alone: the user comes from the token, never from what the client sends, and every account runs its own Chromium process and profile.

03

You stay in the loop

When a site asks for something only you can give (an SMS code, a CAPTCHA the agent cannot solve), the agent hands the step to you with a link. You see the browser live, do the step and press Done; the agent carries on.

FAQ

Questions people ask

Where do I get the token?

Sign up, then create one in the console under Settings → Tokens. It starts with cbu_ and is shown once; we keep only a hash. Put it in an environment variable (WEBPILOT_TOKEN), not in a file you commit.

Where does the configuration go?

In .cursor/mcp.json in the project, or in Cursor's global MCP settings. The URL is https://api.webpilot.si/mcp (Streamable HTTP) and the header is Authorization: Bearer <token>. ${env:WEBPILOT_TOKEN} reads the token from your environment.

Do I need to restart Cursor?

Cursor loads MCP servers when it starts or when you refresh them in its MCP settings. After that, the browser_* tools appear in the agent's tool list.

Does the browser keep my logins between sessions?

Yes. Each account has its own Chromium profile on our servers: cookies, local storage and the open tabs survive disconnects and restarts. The browser stops after 20 minutes without activity; the profile and tab list stay on disk and come back on the next request.

Does the agent see my passwords?

No. Logins, card fields and authenticator (TOTP) keys live in your vault, encrypted with AES-256-GCM. The agent names an entry (browser_login{site}) and the server types the values into the page. No API returns a stored value.

Can I watch what the agent does?

Ask the agent for a viewer link (the browser_viewer tool), or open the live view in the console. Links expire after 10 minutes and are view-only unless your settings allow taking over; the server's relay enforces that, not the page.

Give your agent a browser that remembers.

Start with the free trial. Connect Claude Code, Cursor, Codex or your own code in a minute.