
Automates Firefox through WebDriver BiDi, exposing browser control to Claude and other MCP clients. You get tools for page navigation, element interaction via snapshot UIDs, network request inspection, console monitoring, and screenshots. Supports both headless and headed modes, plus a connect-existing flag to attach to your running Firefox session with all your cookies and tabs intact. Ships with security guardrails: dedicated profiles recommended, optional flags for script evaluation and privileged context access. Useful for web scraping, automated testing, or any workflow where you need an AI to drive a real browser instead of just making HTTP requests. Requires local Firefox 100+ and Node 20.19+.
Model Context Protocol server for automating Firefox via WebDriver BiDi (through Selenium WebDriver). Works with Claude Code, Claude Desktop, Cursor, Cline and other MCP clients.
Repository: https://github.com/mozilla/firefox-devtools-mcp
Note: This MCP server requires a local Firefox browser installation and cannot run on cloud hosting services like glama.ai. Use
npx @mozilla/firefox-devtools-mcp@latestto run locally, or use Docker with the provided Dockerfile.
Browser MCP servers carry inherent risks. A few key practices:
basic preset already includes evaluate_script; --tool-preset slim drops it. Higher presets such as --tool-preset developer (debugging, network, console, profiler) and --tool-preset mozilla (privileged context) expand what the agent can do further.See SECURITY.md for a full breakdown of risks and how to report vulnerabilities.
--firefox-path)Recommended: use npx so you run the latest published version from npm.
claude mcp add firefox-devtools npx @mozilla/firefox-devtools-mcp@latest
# Headless + viewport via args
claude mcp add firefox-devtools npx @mozilla/firefox-devtools-mcp@latest -- --headless --viewport 1280x720
# Or via environment variables
claude mcp add firefox-devtools npx @mozilla/firefox-devtools-mcp@latest \
--env START_URL=https://example.com \
--env FIREFOX_HEADLESS=true
codex mcp add firefox-devtools -- npx @mozilla/firefox-devtools-mcp@latest
# Headless + viewport via args
codex mcp add firefox-devtools -- \
npx @mozilla/firefox-devtools-mcp@latest -- --headless --viewport 1280x720
# Or via environment variables
codex mcp add firefox-devtools \
--env START_URL=https://example.com \
--env FIREFOX_HEADLESS=true \
-- npx @mozilla/firefox-devtools-mcp@latest
Add to Claude Code’s mcp_settings.json:
{
"mcpServers": {
"firefox-devtools": {
"command": "npx",
"args": ["-y", "@mozilla/firefox-devtools-mcp@latest", "--headless", "--viewport", "1280x720"],
"env": {
"START_URL": "about:blank"
}
}
}
}
Add to ~/.codex/config.toml:
[mcp_servers.firefox-devtools]
command = "npx"
args = ["-y", "@mozilla/firefox-devtools-mcp@latest", "--headless", "--viewport", "1280x720"]
[mcp_servers.firefox-devtools.env]
START_URL = "about:blank"
npm run setup
# Choose Claude Code; the script saves JSON to the right path
npx @modelcontextprotocol/inspector npx @mozilla/firefox-devtools-mcp@latest --start-url https://example.com --headless
Then call tools like:
list_pages, select_page, navigate_pagetake_snapshot then click_by_uid / fill_by_uidlist_network_requests (always‑on capture), get_network_requestlist_downloads (always‑on capture), set_download_behaviorscreenshot_page, list_console_messagesYou can pass flags or environment variables (names on the right):
--firefox-path — absolute path to Firefox binary--headless — run without UI (FIREFOX_HEADLESS=true)--viewport 1280x720 — initial window size--profile-path — use a specific Firefox profile--firefox-arg — extra Firefox arguments (repeatable)--start-url — open this URL on start (START_URL)--accept-insecure-certs — ignore TLS errors (ACCEPT_INSECURE_CERTS=true)--connect-existing — attach to an already-running Firefox instead of launching a new one (CONNECT_EXISTING=true)--marionette-port — Marionette port for connect-existing mode, default 2828 (MARIONETTE_PORT)--pref name=value — set Firefox preference at startup via moz:firefoxOptions (repeatable)--tool-preset — select which tool modules to enable: slim, basic (default), developer, mozilla, or all. See Tool modules and presets. (TOOL_PRESET)--tools — explicit list of tool modules to enable, overriding --tool-preset entirely (e.g. --tools pages network script). See Tool modules and presets.--enable-script — deprecated, use --tool-preset developer or --tools ... script debugging. Selects the developer tool preset. (ENABLE_SCRIPT=true)--enable-privileged-context — deprecated, use --tool-preset mozilla or --tools ... privileged prefs. Selects the mozilla tool preset. Requires MOZ_REMOTE_ALLOW_SYSTEM_ACCESS=1 (ENABLE_PRIVILEGED_CONTEXT=true)--android-device — enable Firefox for Android mode; value is the ADB device serial (e.g. emulator-5554). Run adb devices to list connected devices. Omit the value or use auto to select the single connected device automatically.--android-wipe-app-data — confirm that Android mode wipes all data of the target app. Required together with --android-device. (ANDROID_WIPE_APP_DATA=true)--android-package — Android app package name, default org.mozilla.firefox. Other packages: org.mozilla.firefox_beta for Firefox Beta, org.mozilla.fenix for Firefox Nightly, org.mozilla.fenix.debug for Firefox Nightly Debug, org.mozilla.geckoview_example for geckoview (ANDROID_PACKAGE)--unrestricted-save-paths — let the saveTo parameter write anywhere on disk instead of the default roots. See Saving bulky output to disk and the security note in SECURITY.md. (UNRESTRICTED_SAVE_PATHS=true)--log-file — write MCP server logs to a file instead of stderr. Useful for debugging sessions with MCP clients that hide server output. Set DEBUG=* to also include verbose debug logs. Example: --log-file /tmp/firefox-mcp.logTools are grouped into modules. You choose which modules to expose either with a named preset
(--tool-preset) or with an explicit list (--tools). When both are given, --tools wins and
the preset is ignored.
Modules: pages, snapshot, input, network, console, screenshot, downloads,
utilities, management, webextension, profiler, screencast, script, debugging,
prefs, privileged.
Presets (each is a superset of the previous):
slim — pages, snapshot, input, screenshotbasic (default) — slim plus downloads, script, utilities, management, webextension, screencastdeveloper — basic plus debugging, network, console, profilermozilla — developer plus prefs, privilegedall — every moduleNote that basic, the default, includes script and therefore the evaluate_script tool.
See SECURITY.md for what that means for the attack
surface, and use --tool-preset slim or an explicit --tools list to drop it.
# Use the developer preset (adds network, console, debugging and profiler tools)
npx @mozilla/firefox-devtools-mcp --tool-preset developer
# Enable only the modules you need
npx @mozilla/firefox-devtools-mcp --tools pages network console
The prefs and privileged modules require MOZ_REMOTE_ALLOW_SYSTEM_ACCESS=1 and are only
available in the Mozilla-internal build. The public package skips them even if requested and
logs a warning naming the modules it dropped.
--pref)Use --android-device to automate Firefox running on an Android device. Requires adb on your PATH and geckodriver, which is managed automatically.
Warning: Android mode wipes all data of the target app before every session. Tabs, history, bookmarks, passwords, cookies and settings are all lost. geckodriver runs
adb shell pm clear <package>when creating the session and offers no way to skip it, then runs the session on its own temporary profile which is deleted afterwards. Because of this,--android-devicerequires--android-wipe-app-data, and you should install a build dedicated to automation rather than automating the browser you use. Bug 2064088 tracks adding an option to geckodriver to keep the existing app data.
# List connected devices
adb devices
# Launch Firefox for Android on the single connected device
npx @mozilla/firefox-devtools-mcp --android-device auto --android-wipe-app-data
# Target a specific device
npx @mozilla/firefox-devtools-mcp --android-device <serial> --android-wipe-app-data
# Use Firefox Nightly instead
npx @mozilla/firefox-devtools-mcp --android-device <serial> --android-package org.mozilla.fenix --android-wipe-app-data
Port forwarding between the host and device is handled automatically by geckodriver.
Use --connect-existing to automate your real browsing session, with cookies, logins, and open tabs intact:
# Start Firefox with Marionette and the Remote Agent (BiDi)
firefox --marionette --remote-debugging-port
# Run the MCP server
npx @mozilla/firefox-devtools-mcp --connect-existing --marionette-port 2828
Both flags are required because the MCP uses both WebDriver Classic (--marionette) and WebDriver BiDi (--remote-debugging-port). If Firefox is only started with --marionette, the MCP server fails to connect and asks you to restart Firefox with both flags.
Warning: Do not leave Marionette enabled during normal browsing. It sets
navigator.webdriver = trueand changes other browser fingerprint signals, which can trigger bot detection on sites protected by Cloudflare, Akamai, etc. Only enable Marionette when you need MCP automation, then restart Firefox normally afterward.
saveTo)saveTo)saveTo)saveTo)saveTo for CLI environments)sandbox for an isolated realm; optional saveTo for bulky results)MOZ_REMOTE_ALLOW_SYSTEM_ACCESS=1)MOZ_REMOTE_ALLOW_SYSTEM_ACCESS=1)MOZ_REMOTE_ALLOW_SYSTEM_ACCESS=1)Large tool output can consume significant context in CLI clients like Claude Code. The
screenshot_page, screenshot_by_uid, take_snapshot, list_console_messages,
list_network_requests, get_network_request, get_page_text,
evaluate_script, and
evaluate_privileged_script tools accept an optional saveTo parameter that writes the
result to a file instead of returning it inline. saveTo takes one of three forms:
~/.firefox-devtools-mcp; parent directories are created)true (a timestamped file is generated under ~/.firefox-devtools-mcp/output/)The response returns the path and byte size. The saved file always holds the full, untruncated data: the inline size safeguards (console message caps, network header truncation, snapshot line caps) never apply to it.
The text-producing tools (everything except the screenshots) also accept preview, a number
of characters of the saved output to echo back inline as a short excerpt. Screenshots have no
preview.
screenshot_page({ saveTo: "page.png" })
take_snapshot({ saveTo: true })
list_network_requests({ urlContains: "api", saveTo: "network.json" })
evaluate_script({ function: "() => performance.getEntries()", saveTo: true, preview: 2000 })
By default, save paths are restricted: relative paths resolve against the current working
directory, and absolute paths are only allowed within ~/.firefox-devtools-mcp. Paths that
escape these locations are rejected. Start the server with --unrestricted-save-paths to
write to arbitrary locations, including absolute paths outside that directory.
Saved files can then be viewed for instance with Claude Code's Read tool without impacting context size.
npm install
npm run build
# Run with Inspector against local build
npx @modelcontextprotocol/inspector node dist/index.js --headless --viewport 1280x720
# Or run in dev with hot reload
npm run inspector:dev
See CONTRIBUTING.md for more details on local development, testing, and CI.
--firefox-path "/Applications/Firefox.app/Contents/MacOS/firefox" (macOS) or the correct path on your OS.take_snapshot) when a UID tool reports one is gone.Solution 1 Wrap with cmd /c (details):
"mcpServers": {
"firefox-devtools": {
"command": "cmd",
"args": ["/c", "npx", "-y", "@mozilla/firefox-devtools-mcp@latest"]
}
}
Solution 2 Use the absolute path to npx (adjust extension — .cmd, .bat, .exe, or .ps1 — to match your setup):
"mcpServers": {
"firefox-devtools": {
"command": "C:\\nvm4w\\nodejs\\npx.ps1",
"args": ["-y", "@mozilla/firefox-devtools-mcp@latest"]
}
}
0.x. Use @latest with npx for the newest release.See CONTRIBUTING.md for how to file issues, run tests, and work on the project locally.
Maintained by Mozilla.
Licensed under either of MIT or Apache 2.0 at your option.