🦁 Safari MCP

MCP serverWeb & browsing

Your AI can control the Safari browser and handle web tasks on your behalf. This community-built addition provides native Safari automation, so the work happens directly in Safari with no Chrome required.

Unavailable. This server has no hosted endpoint yet, so ahel can't serve it.

Once it is added, ask your AI to take care of a web task in Safari, such as opening a website and completing a task there for you.

What your AI can do with it

  • Browse websites and complete web tasks in Safari on your behalf
  • Automate browser steps you would normally do by hand
  • Work directly in Safari without needing Chrome
  • Use 97 built-in browser tools to handle different kinds of web tasks

From the project's README

As published by achiya-automation/safari-mcp in README.md.

The browser for your coding agent.

Your real Safari, logged in β€” no Chrome, no heat, no headless.

Install in VS Code Β· VS Code Insiders Β· Install in Cursor

97 tools Β· No Chrome/Puppeteer/Playwright needed Β· ~5ms per command Β· 60% less CPU than Chrome

Quick Start Β· All 97 Tools Β· Examples Β· Why Safari MCP? Β· Architecture Β· Changelog

❌ Without Safari MCP

Your AI agent needs to browse. So it either:

  • Spins up Chromium via Playwright β€” with no logins, no cookies, no sessions
  • Uses Chrome DevTools MCP β€” and melts your fan running a second browser
  • Relies on headless scrapers β€” blocked by Cloudflare, reCAPTCHA, and bot detection

βœ… With Safari MCP

Your AI drives the Safari you're already logged into β€” Gmail, GitHub, Ahrefs, Slack, banking.

Native WebKit. ~60% less CPU. Background operation. 97 tools. One npx command. macOS only.

πŸ“° Featured on freeCodeCamp: How to Connect Your AI Coding Agent to a Browser on macOS Β· HackerNoon: Reverse-Engineering React, Shadow DOM, and CSP

🍎 Apple shipped an official Safari MCP (July 2026 β€” Safari Technology Preview 247+ and the Safari 27 beta). It's built on safaridriver for isolated debugging sessions. safari-mcp drives the real Safari you're already logged into β€” on the stable Safari that ships with macOS today, with 97 tools. See the full comparison below.


Highlights

  • 97 tools β€” navigation, clicks, forms, screenshots, network, storage, accessibility, and more
  • Zero heat β€” native WebKit on Apple Silicon, ~60% less CPU than Chrome
  • Your real browser β€” keeps all logins, cookies, sessions (Gmail, GitHub, Ahrefs, etc.)
  • Background operation β€” Safari stays in the background, no window stealing
  • No browser dependencies β€” no Puppeteer, no Playwright, no WebDriver, no Chrome
  • Persistent process β€” reuses a single osascript process (~5ms per command vs ~80ms)
  • Framework-compatible β€” React, Vue, Angular, Svelte form filling via native setters

In users' own words

Not solicited testimonials β€” quotes lifted from the public issue tracker, each linked to the thread it came from.

"I run multiple Pi sessions/subagents against my normal Safari profile in parallel. Sharing its cookies and logins is intentional." β€” @maxim, on running concurrent agents against a real browser

"The server has a deliberate tab-ownership model … the code is careful about this, and for the default case that's the right safety posture." β€” @turner-moore, on why the guards refuse to touch your tabs

"Direct local validation from the package: Safari MCP doctor 6/6." β€” @jrepp, who found and fixed a queue-alignment bug in the focus helper


Quick Start

Prerequisites

  • macOS (any version with Safari)
  • Node.js 20+
  • Safari β†’ Settings β†’ Advanced β†’ Show features for web developers βœ“
  • Safari β†’ Develop β†’ Allow JavaScript from Apple Events βœ“

Install (one command)

npx safari-mcp

That's it β€” no global install needed. Or install permanently:

npm install -g safari-mcp

Configure your MCP client

All clients run Safari MCP the same way β€” npx safari-mcp. Pick your editor:

claude mcp add safari -- npx safari-mcp

Or edit ~/.mcp.json:

{
  "mcpServers": {
    "safari": {
      "command": "npx",
      "args": ["safari-mcp"]
    }
  }
}

Edit ~/Library/Application Support/Claude/claude_desktop_config.json:

{
  "mcpServers": {
    "safari": {
      "command": "npx",
      "args": ["safari-mcp"]
    }
  }
}

Restart Claude Desktop after saving.

One-click: Install in Cursor

Or edit .cursor/mcp.json in your project:

{
  "mcpServers": {
    "safari": {
      "command": "npx",
      "args": ["safari-mcp"]
    }
  }
}

One-click: Install in VS Code

Or edit .vscode/mcp.json:

{
  "servers": {
    "safari": {
      "type": "stdio",
      "command": "npx",
      "args": ["safari-mcp"]
    }
  }
}

Edit .windsurf/mcp.json in your project (or ~/.codeium/windsurf/mcp_config.json globally):

{
  "mcpServers": {
    "safari": {
      "command": "npx",
      "args": ["safari-mcp"]
    }
  }
}

Open Cline in VS Code β†’ click the MCP icon β†’ Edit MCP Settings β†’ add:

{
  "mcpServers": {
    "safari": {
      "command": "npx",
      "args": ["safari-mcp"]
    }
  }
}

Edit ~/.continue/config.yaml (or .continue/config.yaml in workspace):

mcpServers:
  - name: safari
    command: npx
    args:
      - safari-mcp

Edit ~/.config/goose/config.yaml:

extensions:
  safari:
    name: safari
    type: stdio
    cmd: npx
    args:
      - safari-mcp
    enabled: true

Open LM Studio β†’ Settings β†’ MCP Servers β†’ Add Server:

  • Name: safari
  • Command: npx
  • Args: safari-mcp

Open Zed β†’ Settings β†’ search for "Context Servers" and add:

{
  "context_servers": {
    "safari": {
      "command": {
        "path": "npx",
        "args": ["safari-mcp"]
      }
    }
  }
}
brew install achiya-automation/tap/safari-mcp
git clone https://github.com/achiya-automation/safari-mcp.git
cd safari-mcp && npm install

Usage Workflow

The recommended pattern for AI agents using Safari MCP:

1. safari_snapshot        β†’ Get page state (accessibility tree)
2. safari_click/fill/...  β†’ Interact with elements by ref
3. safari_snapshot        β†’ Verify the result

Element targeting β€” tools accept multiple targeting strategies:

StrategyExampleBest for
CSS selector#login-btn, .submitUnique elements
Visible text"Sign In", "Submit"Buttons, links
Coordinatesx: 100, y: 200Canvas, custom widgets
Ref from snapshotref: "e42"Any element from accessibility tree

Tip: Start with safari_snapshot to get element refs, then use refs for precise targeting. This is faster and more reliable than CSS selectors.


Running several agents at once

Multiple agents or subagents driving one Safari at the same time will fight over the active tab β€” unless you run them against a shared HTTP daemon instead of one process per client:

SAFARI_MCP_HTTP=1 SAFARI_MCP_HTTP_PORT=9225 npx safari-mcp

Then point every client at it:

{ "mcpServers": { "safari-mcp": { "type": "http", "url": "http://127.0.0.1:9225/mcp" } } }

One daemon, many sessions β€” and each session gets its own tab state. The server keys activeTabIndex, the ownership flag and a unique tab marker off the MCP session id, so session A physically cannot read or steer session B's tab.

Two properties make this safe rather than merely tidy:

  • Tab identity is a marker, not an index. Each session stamps a unique id into the page it opens, so ownership survives navigation and survives the user reordering or closing other tabs. An index alone would silently drift onto the wrong tab.

  • It fails closed. If a session's marked tab can't be re-found, every tool refuses instead of falling back to whatever tab is in front β€” because that tab is usually yours:

    Tab tracking lost β€” refusing to fall back to "current tab of window"
    (would target the user's active tab). Call safari_new_tab to reopen.
    

This also drops process count sharply: ~17 node processes for 17 concurrent sessions becomes 1.

SAFARI_PROFILE stays optional β€” leave it unset and sessions bind to your ordinary Safari windows, cookies and logins intact. Details in docs/http-transport-design.md.

Prefer stdio (one process per agent) over a persistent daemon? That works too β€” isolation then comes from the process boundary itself. One caveat: if your client multiplexes agents through mcporter, mcporter caches a single MCP client for all of them β€” whichever transport you pick β€” so the server never sees distinct sessions and per-session isolation can't engage. mcporter-lanes (a pi extension by @maxim, born out of #76) fixes this upstream: each agent session gets its own daemon dir β€” and therefore its own safari-mcp β€” with an idle timeout so processes don't pile up.


Acting on a tab you already have open

By default the server touches only tabs it opened itself. Point it at one of yours and it refuses:

Tab safety: refusing "click" β€” current tab (https://mail.example.com/inbox) was not
opened by this MCP session. Use safari_new_tab or safari_switch_tab to target your own tab.

That default exists because early versions did click into and close people's tabs. But "read the article I'm looking at" and "fill in the form on my screen" are real, and reopening the page loses the session state that made your tab worth using. Set SAFARI_MCP_ALLOW_USER_TABS=1 and an explicit safari_switch_tab adopts the tab instead of refusing it; from then on the session works in it like one of its own, and says so:

{ "tabIndex": 3, "safeUrl": "https://mail.example.com/inbox", "note": "(user tab, opted-in)" }

What the flag deliberately does not do:

  • It unlocks adoption, not the guards. Only safari_switch_tab adopts, and only the tab you named. An ordinary click or navigate still never lands on whatever tab happens to be in front β€” the server acts on the tab you pointed it at, not the one you wandered to.
  • safari_close_tab still refuses. Closing is the one action whose cost you cannot undo, so an adopted tab is writable, never disposable. Close it yourself.
  • Adoption is session-local. Nothing is written to the shared ownership file, so it ends with the session rather than leaking to the next process on the machine.

safari_doctor prints the flag's state, and every operation on an adopted tab logs (user tab, opted-in) β€” so "why did it touch my tab" has an answer instead of being a mystery. Default off; set it only for agents you want working inside your own browsing session. Designed in #92.


Environment variables

VariableDefaultWhat it does
SAFARI_MCP_HTTPoffRun one shared HTTP daemon instead of a process per client (see above).
SAFARI_MCP_HTTP_PORT9225Port for that daemon.
SAFARI_PROFILEunsetBind sessions to a named Safari profile. Unset = your ordinary windows.
SAFARI_MCP_ALLOW_USER_TABSoffLet safari_switch_tab adopt a tab you already had open, instead of refusing it (see below).
SAFARI_MCP_RAISE_ON_NAVIGATEoffLet navigation bring Safari to the front, and stop the focus guard from putting your previous app back.
SAFARI_MCP_SCREENSHOT_MAX_WIDTHunsetDownscale every safari_screenshot to this pixel width (Retina captures are 2Γ— the viewport). Per-call maxWidth overrides it.
SAFARI_MCP_KEEPALIVE_TABoffKeep one daemon-served page open in the profile window so Safari never parks the extension worker between commands.
SAFARI_MCP_OPEN_WINDOW_CMDunsetCommand run with the profile name when the profile window is absent (e.g. after a reboot). Must open the window without focusing Safari.

SAFARI_MCP_RAISE_ON_NAVIGATE=1 is for agents whose whole point is showing you a page β€” a voice assistant answering "open YouTube", a demo driver. Everything else should leave it off: by default Safari MCP works in the background and hands focus back to whatever app you were using, so an agent can drive a page while you keep typing somewhere else.


Tools (97)

Navigation (4)

ToolDescription
safari_navigateNavigate to URL (auto HTTPS, wait for load)
safari_go_backGo back in history
safari_go_forwardGo forward in history
safari_reloadReload page (optional hard reload)

Page Reading (3)

ToolDescription
safari_read_pageGet title, URL, and text content
safari_get_sourceGet full HTML source
safari_navigate_and_readNavigate + read in one call

Click & Interaction (6)

ToolDescription
safari_clickClick by CSS selector, visible text, or coordinates
safari_double_clickDouble-click (select word, etc.)
safari_right_clickRight-click (context menu)
safari_hoverHover over element
safari_click_and_waitClick + wait for navigation
safari_click_and_readClick then return the updated page β€” saves a round-trip (React Router + full loads)

Form Input (11)

ToolDescription
safari_fillFill input (React/Vue/Angular compatible)
safari_clear_fieldClear input field
safari_select_optionSelect dropdown option
safari_fill_formBatch fill multiple fields
safari_fill_and_submitFill form + submit in one call
safari_type_textType real keystrokes (JS-based, no System Events)
safari_press_keyPress key with modifiers
safari_react_select_setSet a react-select v5 value via React fiber β€” bypasses the menu UI
safari_react_select_list_optionsList a react-select v5 dropdown's options without opening it
safari_replace_editorReplace all content in a code editor (Monaco, CodeMirror, Ace, ProseMirror)
safari_verify_stateVerify an editor's framework-level state matches expected β€” catch stale DOM before Submit

Screenshots & PDF (3)

ToolDescription
safari_screenshotScreenshot as PNG (viewport or full page)
safari_screenshot_elementScreenshot a specific element
safari_save_pdfExport page as PDF

Scroll (3)

ToolDescription
safari_scrollScroll up/down by pixels
safari_scroll_toScroll to exact position
safari_scroll_to_elementSmooth scroll to element

Tab Management (5)

ToolDescription
safari_list_tabsList all tabs (index, title, URL)
safari_new_tabOpen new tab (background, no focus steal)
safari_close_tabClose tab
safari_switch_tabSwitch to tab by index
safari_wait_for_new_tabWait for a new tab (e.g. OAuth popup) and auto-switch to it

Wait (2)

ToolDescription
safari_wait_forWait for element, text, or URL change
safari_waitWait for specified milliseconds

JavaScript (1)

ToolDescription
safari_evaluateExecute arbitrary JavaScript, return result
safari_eval_fileExecute JavaScript read from a file path (avoids huge inline scripts)

Element Inspection (4)

ToolDescription
safari_get_elementElement details (tag, rect, attrs, visibility)
safari_query_allFind all matching elements
safari_get_computed_styleComputed CSS styles
safari_detect_formsAuto-detect all forms with field selectors

Accessibility (2)

ToolDescription
safari_accessibility_snapshotFull a11y tree: roles, ARIA, focusable elements
safari_snapshotAccessibility tree with ref IDs for every interactive element β€” preferred way to see page state

Drag & Drop (1)

ToolDescription
safari_dragDrag between elements or coordinates

File Operations (2)

ToolDescription
safari_upload_fileUpload file via JS DataTransfer (no file dialog!)
safari_paste_imagePaste image into editor (no clipboard touch!)

Dialog & Window (2)

ToolDescription
safari_handle_dialogHandle alert/confirm/prompt
safari_resizeResize browser window

Device Emulation (2)

ToolDescription
safari_emulateEmulate device (iPhone, iPad, Pixel, Galaxy)
safari_reset_emulationReset to desktop

Cookies & Storage (11)

ToolDescription
safari_get_cookiesGet all cookies
safari_set_cookieSet cookie with all options
safari_delete_cookiesDelete one or all cookies
safari_local_storageRead localStorage
safari_set_local_storageWrite localStorage
safari_delete_local_storageDelete/clear localStorage
safari_session_storageRead sessionStorage
safari_set_session_storageWrite sessionStorage
safari_delete_session_storageDelete/clear sessionStorage
safari_export_storageExport all storage as JSON (backup/restore sessions)
safari_import_storageImport storage state from JSON

Clipboard (2)

ToolDescription
safari_clipboard_readRead clipboard text
safari_clipboard_writeWrite text to clipboard

Network (6)

ToolDescription
safari_networkQuick network requests via Performance API
safari_start_network_captureStart detailed capture (fetch + XHR)
safari_network_detailsGet captured requests with headers/timing
safari_clear_networkClear captured requests
safari_mock_routeMock network responses (intercept fetch/XHR)
safari_clear_mocksRemove all network mocks

Console (4)

ToolDescription
safari_start_consoleStart capturing console messages
safari_get_consoleGet all captured messages
safari_clear_consoleClear captured messages
safari_console_filterFilter by level (log/warn/error)

Performance (2)

ToolDescription
safari_performance_metricsNavigation timing, Web Vitals, memory
safari_throttle_networkSimulate slow-3g/fast-3g/4g/offline

Data Extraction (4)

ToolDescription
safari_extract_tablesTables as structured JSON
safari_extract_metaAll meta: OG, Twitter, JSON-LD, canonical
safari_extract_imagesImages with dimensions and loading info
safari_extract_linksLinks with rel, external/nofollow detection

Advanced (7)

ToolDescription
safari_override_geolocationOverride browser geolocation
safari_list_indexed_dbsList IndexedDB databases
safari_get_indexed_dbRead IndexedDB records
safari_css_coverageFind unused CSS rules
safari_analyze_pageFull page analysis in one call
safari_doctorDiagnose the macOS permission + daemon chain (Apple Events, Accessibility, Screen Recording, codesign) with per-failure fixes
safari_reload_extensionHot-reload the Safari MCP Bridge extension without a manual toggle

Automation (1)

ToolDescription
safari_run_scriptRun multiple actions in a single call (batch)

Native Input β€” CGEvent (4)

ToolDescription
safari_native_clickOS-level mouse click (CGEvent, isTrusted: true) β€” bypasses WAF/bot detection when safari_click is blocked (405/403)
safari_native_hoverOS-level cursor hover β€” triggers real :hover/mouseenter for tooltips and obfuscated UIs
safari_native_typeInsert text via the real paste pipeline β€” ProseMirror/Slate/Draft.js process it natively so Submit sends real data
safari_native_keyboardOS-level keypress + modifiers to Safari, no focus steal β€” reaches React trust-gated handlers (Discord/Slack send)

iOS & WebKit Validation (4)

ToolDescription
safari_inspect_viewportValidate the <meta name=viewport> tag for iOS Safari (device-width, zoom/WCAG, viewport-fit)
safari_safe_area_insetsRead live safe-area-inset values + viewport-fit / env() usage (notch / Dynamic Island)
safari_check_pwaAudit iOS "Add to Home Screen" / PWA readiness (apple-touch-icon, manifest, theme-color, splash)
safari_webkit_compatCheck page CSS against this Safari via CSS.supports() β€” unsupported props, missing -webkit- prefixes, known quirks

Security

Safari MCP runs locally on your Mac with minimal attack surface:

AspectDetail
NetworkNo remote connections β€” all communication is local (stdio + localhost)
PermissionsmacOS system permissions required (Screen Recording for screenshots)
DataNo telemetry, no analytics, no data sent anywhere
ExtensionCommunicates only with the local profile bridges (localhost:9224/9228/9232/9236), validated by Safari
CodeFully open source (MIT) β€” audit every line

Safari MCP vs Alternatives

Shortened here. Read the whole README on GitHub.

Signals

GitHub stars
183
Forks
26
Last commit
Sep 2026
Weekly downloads
2k
Advanced
Delivery
safari-mcp MCP server β†’ your ahel gateway (mcp.ahel.ai) β†’ every connected AI client.
Catalog kind
mcp-server
Gateway key
io-github-achiya-automation-safari-mcp
Source
github.com/achiya-automation/safari-mcp