The holy grail of agentic browsing isn't accessing the public web; it's accessing your private data. LMCP, a free Model Context Protocol server for macOS, just shipped 14 browser tools designed to let Claude Code interact with sites you are already logged into, without touching your primary Safari or Chrome profiles.
The Isolated WebKit Architecture
LMCP operates on a strict isolation model. It spawns its own WebKit browser window that starts completely signed out, ensuring your real browser's cookies remain untouched. Sessions are persisted to disk under custom names, surviving restarts. The initial authentication flow requires human intervention: the agent calls web_login with a session name and URL, opens a window, and the user enters passwords and 2FA manually. The credentials never pass through the AI or the tool, maintaining security while enabling persistent access.
Structured Extraction Over Raw HTML
Once authenticated, the agent utilizes web_navigate to access pages within the saved session. Crucially, it employs web_read with mode: "a11y" to generate a compact accessibility tree of links, buttons, and fields. This approach is significantly cheaper in token usage than parsing raw HTML. For data extraction, web_extract maps CSS selectors to structured fields, allowing Claude Code to pull tablesβsuch as weekly analytics reportsβand save them directly to CSV files. Interaction is handled via web_click, web_type, and web_find, while web_wait_for prevents blind sleeps by polling for element visibility.
Safety Guardrails and Known Limitations
The tool includes robust guardrails to prevent accidental state changes. Form submissions are gated: web_click on a submit button returns a preview and requires a confirm: true flag to proceed. A LMCP_READ_ONLY=1 environment variable blocks all mutating actions, including web_eval, for unattended jobs. However, the solution has friction points. Google's "Sign in with Google" flow is blocked in the embedded browser, forcing email and one-time code alternatives. Captchas and 2FA challenges require the user to bring the window to the front via web_show. Additionally, each session is limited to one tab, and the LMCP menu bar app must remain active.
Key Takeaways
- LMCP uses an isolated WebKit window, ensuring agent actions do not interfere with user's primary browser sessions.
- Authentication is manual and secure; passwords are never exposed to the LLM, and sessions persist across restarts.
- The
a11yread mode optimizes token efficiency by parsing accessibility trees rather than raw HTML. - Write operations are gated behind explicit confirmation flags, with a global read-only mode available for safety.
- Google SSO is incompatible with the embedded browser, and captchas still require human resolution.
The Bottom Line
This is the pragmatic bridge between LLM reasoning and enterprise reality. While API-first is ideal, the majority of business data is trapped behind legacy login walls; LMCP acknowledges that the browser is the universal API, provided you respect its security boundaries and state limitations.