What this proves

The MCP surface covers more than clicks and screenshots.

An agent can keep task-owned browser state, address pages through semantic refs, collect bounded debugging evidence, reproduce defects, and hand control back to a person. The catalog describes capability, not blanket permission: workspace ownership, input validation, authentication, interaction locks, and explicit confirmations still apply.

Complete catalog

Find the tool group your workflow needs.

Names below are the exact MCP names advertised by Hronaut. Compatible clients also receive human-readable titles and explicit read-only, destructive, idempotent, and open-world hints.

18 tools

Workspaces, tabs, and browser state

Create or resume isolated workspaces, select visible tabs, inspect origin storage, and manage browser-owned records.

browser_workspacesbrowser_saved_workspacesbrowser_statusbrowser_showbrowser_request_user_attentionbrowser_tabsbrowser_new_tabbrowser_select_tabbrowser_close_tabbrowser_bookmarksbrowser_visit_historybrowser_site_databrowser_storagebrowser_storage_changesbrowser_storage_usagebrowser_indexeddbbrowser_pwabrowser_downloads

17 tools

Navigation and semantic interaction

Prefer bounded snapshots and semantic refs, then navigate, wait, inspect, or act on the same visible page.

browser_navigatebrowser_historybrowser_snapshotbrowser_findbrowser_element_inspectbrowser_generate_locatorbrowser_clickbrowser_dialogbrowser_typebrowser_selectbrowser_fill_formbrowser_hoverbrowser_dragbrowser_scrollbrowser_pressbrowser_file_uploadbrowser_wait

7 tools

Environment and capture

Change reproducible page conditions, capture visual or PDF evidence, or run explicitly requested JavaScript.

browser_emulatebrowser_resizebrowser_zoombrowser_audiobrowser_screenshotbrowser_pdf_savebrowser_evaluate

16 tools

QA, audits, and reproduction

Collect bounded accessibility, quality, performance, memory, DOM, console, and reproduction evidence in the active session.

browser_accessibility_auditbrowser_quality_auditbrowser_performancebrowser_design_overviewbrowser_page_metadatabrowser_securitybrowser_code_coveragebrowser_cpu_profilebrowser_memorybrowser_debug_reportbrowser_reprobrowser_dom_changesbrowser_visual_comparebrowser_issuesbrowser_consolebrowser_diagnostic_logs

7 tools

Network diagnosis

Observe request timing and bounded content, export HAR evidence, or deliberately replay and route traffic.

browser_networkbrowser_network_waitbrowser_network_searchbrowser_network_requestbrowser_network_replaybrowser_network_harbrowser_network_routes

6 tools

Mediated local wallets

Inspect attached wallets and ask Hronaut to prepare, approve, submit, track, or cancel a scoped request without returning private keys.

wallet_listwallet_balancewallet_prepare_transactionwallet_requestwallet_request_statuswallet_cancel_request

Safety boundary

Tool hints help clients. Hronaut still enforces the boundary.

Safety annotations are advisory metadata for compatible clients and approval interfaces. Hronaut only marks a tool read-only when every supported mode is observational; combined list/edit/clear tools remain non-read-only. Browser-facing reads stay open-world because sanitized page and network evidence still originates outside Hronaut.

Those hints do not replace owner-token authentication, task-owned workspace authorization, tab validation, input bounds, human interaction locks, wallet policy checks, or side-effect confirmations. Review the security and release trust page before granting an agent access to valuable signed-in sessions.

Primary sources

Audit the implementation, not the headline.

Try the visible workflow

Start with an isolated workspace and a semantic snapshot.

Install Hronaut, copy the current profile-specific MCP setup from Home, then run the observable first task. No hosted browser account is required.