Playwright MCP Review 2026: 72 Tools, 19 Clients, One Deliberately Unsafe One
Playwright MCP is one of the most-used MCP servers on the internet right now — independently ranked #2 overall by PulseMCP's own usage leaderboard. It hands an AI agent a real browser through 72 documented tools, working from Claude Desktop, VS Code, Cursor, Windsurf and 15 other named clients. This review covers what those tools actually do, what "not a vision model" really buys you, and why one tool is officially labeled "RCE-equivalent."
| Free / open-source? | Yes — Apache-2.0 |
| Documented tools | 72 |
| Named client integrations | 19 |
| PulseMCP ranking | #2 overall, #1 this week |
| Best paired with | MCP-native, chat/IDE clients |
The most useful thing about this server is how honest its own risk labeling is.
"Most browser-automation tools bury the dangerous parts in a changelog nobody reads. Playwright MCP names its own most powerful tool browser_run_code_unsafe and describes it in the README as 'RCE-equivalent.' That's not a red flag — that's the correct amount of caution for a tool that can genuinely act inside a real, logged-in browser session on your behalf."
What earns this a high score isn't novelty — accessibility-tree-based browser control isn't a new idea. It's breadth and candor: 72 tools, 19 documented client integrations, an independent #2 ranking across the whole MCP ecosystem, and a security section that tells you exactly where the danger is instead of hiding it in generic disclaimers.
An MCP client asks; the server sees the page as structure, not pixels.
Playwright MCP sits between an MCP client (Claude Desktop, VS Code, Cursor, Windsurf, and 15 others) and a real Chromium/Firefox/WebKit browser it drives via Playwright. Instead of sending the model a screenshot and asking it to guess coordinates, it returns a structured accessibility snapshot — roles, labels, text — that a model can reason over directly and act on deterministically.
The asterisk worth flagging up front: this is still a pre-1.0 product. Current version is 0.0.82, published Sep 18, 2026 — 18+ months of active iteration without a 1.0 tag.
Independently ranked, not just self-described as popular.
microsoft/playwright-mcp, verified on GitHub, Sep 22, 2026.
@playwright/mcp, week of Sep 14-20, 2026.
Independent MCP directory, #1 this week specifically.
Direct count from the official README, Sep 22, 2026.
| When | What happened | Source |
|---|---|---|
| Mar 13, 2025 | @playwright/mcp first published to npm | npm registry timestamp |
| Ongoing 2025-2026 | Tool surface grows to 72 documented tools across core + opt-in capability groups (vision, pdf, devtools, network, storage, testing, config) | Official README, direct count |
| Jul 24, 2026 | Bundled into main Playwright package as npx playwright mcp, alongside the new sibling CLI | Playwright v1.62.0 release notes |
| Sep 2026 (this check) | Independently ranked #2 overall (#1 that week) on PulseMCP's global MCP usage leaderboard | pulsemcp.com/servers/microsoft-playwright |
The praise is about reach; the one real complaint is specific, not vague.
Ranked #2 overall (#1 that week) among all MCP servers by estimated traffic — one of the most broadly adopted browser-automation servers in the entire MCP ecosystem, not just a Microsoft-internal favorite.
On apps built with Shoelace, Lit, or other shadow-DOM component libraries, the server "will fail silently and report 'element not found' on buttons that are clearly visible."
"Playwright is in the business of driving a browser, and Chrome DevTools MCP is in the business of debugging one" — Playwright MCP's edge is cross-browser, deterministic action.
Same answer as its sibling: there's no plan, because there's no charge.
| Thing you might confuse with "pricing" | Actual status |
|---|---|
| @playwright/mcp itself | Free, open-source, Apache-2.0 — no seat, no cap |
| Playwright the test framework | Free, open-source, always has been |
| Playwright CLI (sibling) | Free, open-source — reviewed separately |
| Your MCP client (Claude, Cursor, etc.) | Each has its own separate pricing — unrelated to whether the MCP server itself costs anything |
| Microsoft Playwright Testing (Azure) | The one nearby paid Microsoft product — retired in 2026, folded into Azure App Testing at $0.01/Linux test-minute and $0.02/Windows test-minute after a free trial. Unrelated to the MCP server. |
Source: playwright.dev/mcp/introduction, registry.npmjs.org, azure.microsoft.com/en-us/products/playwright-testing — verified Sep 22, 2026.
Start from your client, not from the feature list.
Playwright MCP is the officially documented, tested path — one of 19 named integrations.
Consider the sibling Playwright CLI instead — reviewed separately, generally lower token overhead.
That's Chrome DevTools MCP's specialty, not this server's.
See the Browser Use review instead.
The whole reliability argument rests on one design choice.
Instead of feeding a vision model a picture and hoping it clicks the right pixel, browser_snapshot returns a structured tree of roles, labels and short element references. The model reasons over that structure directly — no vision model required, and no coordinate-guessing ambiguity.
- 72 documented tools spanning navigation, input, storage (cookies/local/session), network mocking, tracing, PDF export and test assertions.
- Opt-in
--capsflags (vision, pdf, devtools, network, storage, testing, config) keep the default tool surface lean until you need more. - 19 named, individually documented client setup guides in the README.
- Shadow-DOM-heavy component libraries can produce snapshot gaps per independent reports.
- Pre-1.0 versioning (0.0.82) despite 18+ months of development.
Snapshot, decide, act, re-snapshot — the agent stays in the loop the whole time.
Official Playwright video: how AI agents use Playwright MCP to control a real browser.
Published by the official "Playwright" YouTube channel (youtube.com/@Playwrightdev).
Nineteen clients get their own setup instructions — not just a generic JSON blob.
Every client below has its own dedicated, tested setup section in the official README, not just a shared "standard config" snippet. That level of per-client documentation is unusual and is part of why this server shows up wired into so many different tools.
| Category | Documented clients |
|---|---|
| Chat / desktop assistants | Claude Desktop, Claude Code, Grok, Junie |
| IDEs / editors | VS Code (+ Insiders), Cursor, Windsurf, Antigravity, opencode |
| Coding-agent CLIs | Codex, Copilot (CLI), Gemini CLI, Amp, Warp, Factory |
| Autonomous agent frameworks | Goose, Kiro, Cline, Qodo Gen |
| Local model tooling | LM Studio |
Most agents only ever touch a fraction of this surface — by design.
The default tool set covers navigation, input and page inspection. Everything else is opt-in via --caps, so a client only loads the tool schemas it actually needs — directly relevant to the token-overhead conversation the CLI sibling exists to solve.
| Group | Enabled by | Example tools |
|---|---|---|
| Core interaction | Always on | browser_navigate, browser_click, browser_type, browser_snapshot, browser_fill_form |
| Storage | --caps=storage | browser_cookie_set, browser_localstorage_list, browser_set_storage_state |
| Network | --caps=network | browser_network_request, browser_route, browser_network_state_set |
| DevTools | --caps=devtools | browser_start_tracing, browser_stop_tracing |
| Vision | --caps=vision | browser_mouse_click_xy, browser_mouse_drag_xy (coordinate-based, for edge cases the accessibility tree misses) |
--caps=pdf | browser_pdf_save | |
| Testing | --caps=testing | browser_verify_element_visible, browser_verify_text_visible |
| Unsafe execution | Always available, explicitly labeled | browser_run_code_unsafe — see Security section |
Official Playwright video: generating Playwright tests through MCP inside GitHub Copilot.
Published by the official "Playwright" YouTube channel (youtube.com/@Playwrightdev).
The server is free. The tokens your client spends reasoning over its output aren't.
| What you're actually paying for | Approx. cost |
|---|---|
| playwright-mcp itself | $0 — Apache-2.0 |
| Your MCP client's own subscription (Claude, Cursor, etc.) | Set by that vendor, not by Microsoft |
| Tokens spent on accessibility-snapshot tool schemas + results | Your model provider's own rate; this is exactly the overhead the sibling CLI's disk-state design targets reducing |
| Azure App Testing (optional, managed cloud execution) | $0.01/Linux test-minute, $0.02/Windows test-minute, after a free trial |
Read the one line in the README that matters most: this is not a security boundary.
People whose agent lives inside a chat client or IDE, not a terminal.
| Situation | Why Playwright MCP fits | What to reach for instead |
|---|---|---|
| Using Claude Desktop, VS Code, Cursor, Windsurf, or another MCP-native client | One of 19 explicitly documented, tested integrations | — |
| Long-running, exploratory or self-healing test workflows | Official guidance names this as MCP's specific strength over the CLI | — |
| Coding agent already has filesystem/shell access | Lower per-step token overhead available | Playwright CLI |
| Deep Chrome performance/Web-Vitals profiling | Not this server's focus | Chrome DevTools MCP |
| Fully autonomous agent that plans its own multi-step browsing | MCP is a tool surface, not a planner | Browser Use |
Four real gaps, not manufactured ones.
browser_run_code_unsafe is officially "RCE-equivalent." Powerful and clearly labeled -- but it changes the blast radius of a misconfigured or over-permissioned deployment.
Independent reports show the accessibility snapshot can silently miss real, visible elements on component libraries like Shoelace or Lit.
Still 0.0.82. The tool surface has grown a lot in that time, which is good, but the API has not been declared stable.
--allowed-origins and similar flags are explicitly documented as not being real access control -- they filter, they don't contain.
If this server's assumptions don't match your setup, here's how to think about it.
| If you mostly need... | Compare Playwright MCP with... |
|---|---|
| A shell-based coding agent, lower token overhead | Playwright CLI — reviewed separately |
| A fully autonomous agent that plans its own browsing | Browser Use — reviewed separately |
| Chrome performance profiling, Web Vitals, Lighthouse audits | Chrome DevTools MCP (developer.chrome.com) |
| Hybrid hand-written flows with AI filling in the flexible parts | Stagehand (stagehand.dev) |
No affiliate relationship shapes this review.
JAVIS has not established a publisher affiliate program with Microsoft or the Playwright project. Every CTA here points to the official documentation or the open-source repository.
Go to the official docs.
Open Playwright MCP docsRead the alternative that matches your real question.
Choose the next articlePlaywright MCP makes the most sense next to the tools it's directly answering.
Questions people are actually searching right now
Is Playwright MCP free?
Yes. It's Apache-2.0 licensed with no seat, subscription, or usage cap of its own.
Is Playwright MCP safe to use?
The core tool set is scoped and the profile can be kept in-memory only (--isolated), but the server itself says plainly that flags like --allowed-origins are "not a security boundary," and one opt-in tool (browser_run_code_unsafe) is explicitly "RCE-equivalent." Treat any session it drives like an unlocked browser tab with your real cookies in it.
What clients support Playwright MCP?
19 are individually documented in the official README as of this check, including Claude Desktop, Claude Code, VS Code, Cursor, Windsurf, Cline, Goose, Kiro, Gemini CLI and Copilot.
Is Playwright MCP better than Playwright CLI?
Not "better" — different. Official guidance says MCP suits persistent, stateful, exploratory agentic loops and MCP-native clients; CLI suits token-conscious, shell-based coding agents.
Does it use screenshots or vision models?
Not by default. It reads the page's accessibility tree and returns structured data. Coordinate-based "vision" mode exists as an opt-in capability group (--caps=vision) for the cases the accessibility tree doesn't cover.
Why does it fail on some modern web apps?
Independent reports document snapshot gaps on component libraries using shadow DOM (e.g. Shoelace, Lit), where visible elements can be missed by the accessibility tree.
Is there a hosted/cloud version?
Not of the MCP server itself. The adjacent paid Microsoft product (Microsoft Playwright Testing) was retired in 2026 and folded into Azure App Testing, a separate managed test-execution service.
Where this came from, and when it was checked.
GitHub stats (stars/forks/license/issues): GitHub data for github.com/microsoft/playwright-mcp, Sep 22, 2026.
npm package history/version/downloads: registry.npmjs.org/@playwright/mcp and api.npmjs.org, read directly, Sep 22, 2026.
Tool list (72), client list (19), security-flag language: raw.githubusercontent.com/microsoft/playwright-mcp/main/README.md, official, counted directly.
Bundling into Playwright core: official GitHub release notes for v1.62.0.
PulseMCP ranking: pulsemcp.com/servers/microsoft-playwright, independent directory, read directly.
Azure App Testing pricing / Playwright Testing retirement: azure.microsoft.com/en-us/products/playwright-testing, official, quoted verbatim.
Security precedent: github.com/microsoft/playwright-mcp/issues/1651, verified closed 2026-06-15 via GitHub.
Real screenshots/media: opengraph.githubassets.com repo cards, repository-images.githubusercontent.com Playwright social-preview image.
Official videos: youtube.com/watch?v=2716IUeCIQo and youtube.com/watch?v=AaCj939XIQ4, authorship confirmed on YouTube (author "Playwright", channel @Playwrightdev).
Independent commentary: bug0.com, mcp.directory, trackingplan.com.
