Free tools Windows power users keep installed
One-click scans. No signup required.
You can run Browser Use MCP in Docker in two different ways: as an HTTP service behind your own reverse proxy, or as a local stdio server launched through Docker MCP Gateway. The HTTP route suits a shared service; the Gateway route suits MCP clients such as desktop AI tools that start the server on demand. Both routes require persistent state, secrets supplied outside the image, and a Steel deployment for browser execution.
This guide follows the project documentation at the Browser Use MCP repository and Docker’s MCP Toolkit documentation. Commands are documentation-based; no build or deployment is claimed here.
Choose the Docker deployment that matches your client
| Route | Transport | Best fit | Important operational requirement |
|---|---|---|---|
| HTTP container | HTTP, normally through a reverse proxy | A service used by remote or multiple MCP clients | Persistent /data, private backend network, TLS termination and authentication |
| Docker MCP Gateway | stdio from docker mcp gateway run |
A local MCP client that launches or connects to Gateway | A longLived server entry and a persistent volume with the same encryption key |
Do not treat these as two flags for one deployment. HTTP exposes an application endpoint; Gateway presents a stdio MCP server to a selected client profile.
Prerequisites
- Python 3.12 through 3.14 and
uvare listed by the project quick start. They are needed when building or running from source; a published image already contains the application runtime. - A Steel deployment is required by the project. Steel Cloud use also requires its API key.
- Semantic actions require an OpenAI-compatible Chat Completions endpoint. Deterministic controls do not call a model.
- Docker Engine is needed for the container routes. Docker MCP Toolkit is currently documented as beta, with the current interface guidance tied to Docker Desktop 4.62 and later.
- Create a Base64-encoded 256-bit storage master key before first use. Keep it available: encrypted browser profile data cannot be reused if you replace the key.
Get the image
Pull the published image
Each successful main build publishes an Alpine-based, non-root image to GitHub Container Registry with latest and immutable sha-<commit> tags. The documented convenience command is:
#1 Best Overall
docker pull ghcr.io/s-block/browser-use-mcp:latest
Use latest when convenience matters. For reproducible deployments, replace it with the repository’s immutable sha-<commit> tag after selecting a specific commit. The documentation does not provide a digest in this guide, so do not invent one.
Build locally
Clone and install the source when you need a local image or want to inspect the exact revision:
git clone https://github.com/s-block/browser-use-mcp.git
cd browser-use-mcp
uv sync --frozen
docker build -t browser-use-mcp:local .
The same local image is used by the Gateway route below.
Run an HTTP container behind a reverse proxy
The project’s hardened example keeps the application off the host’s published ports. A trusted HTTPS reverse proxy should be the only component publishing a host port, and it should forward traffic over the private mcp-backend network.
docker run --rm --read-only --cap-drop=ALL
--security-opt=no-new-privileges
--tmpfs /tmp:rw,noexec,nosuid,size=16m
--mount type=volume,source=browser-use-mcp-data,target=/data
--network mcp-backend
--name browser-use-mcp
--env-file /etc/browser-use-mcp/runtime.env
ghcr.io/s-block/browser-use-mcp:latest
Prepare the network and persistent volume
docker network create mcp-backend
docker volume create browser-use-mcp-data
If those objects already exist, Docker reports that fact; reuse them rather than creating a second volume accidentally. The README identifies /data as the only required persistent writable path. The runtime runs as UID 10001, while the root filesystem is read-only in the example.
Rank #2
Supply configuration without putting secrets in the command
Point --env-file at a root-readable, untracked file when a secret manager cannot inject values directly. The project’s configuration covers:
- Non-loopback host and port settings, HTTP or stdio transport, and the persistent state directory.
- Bearer authentication mode and the client credential digest.
- The Base64-encoded 256-bit storage master key.
- Allowed hosts and origins, remote unauthenticated-access controls and the TLS-termination assertion.
- Steel proxy identity, deployment and API key.
- An OpenAI-compatible model endpoint, key and model for semantic actions.
- Private-network permission and request-scoped Steel or model options.
Use the repository’s configuration table for the exact variable names and defaults. Do not commit the file or paste live credentials into shell history.
Apply the transport security requirements
For a non-loopback bind, terminate TLS at a trusted reverse proxy and set BROWSER_USE_MCP_TLS_TERMINATED=true as documented. Bearer authentication protects access control, not transport confidentiality. Keep the container and proxy on a private network.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Enable the project’s public-only egress enforcement for the Steel proxy where appropriate. Docker network allowlisting alone is not a browser destination policy: the README warns that Gateway allowHosts governs traffic from the MCP container, not requests made by remote Chromium. The Steel proxy must enforce the public-only destination boundary.
Connect through Docker MCP Gateway
Gateway connects containerized MCP servers over stdio. Build the image locally first:
docker build -t browser-use-mcp:local .
Create a long-lived server entry
In your Docker MCP Toolkit or Gateway configuration, add the local image as a stdio server. Set the entry’s equivalent of longLived: true. A browser session starts in one tool call and is used by later calls; a short-lived process would lose that session between calls.
Mount a named volume for encrypted profile state and configure all declared secrets through Docker MCP Toolkit or Gateway secret storage. Keep the same storage master key whenever that volume is reused. For separate trust boundaries, create separate Gateway profiles, server entries and data volumes rather than sharing browser profiles.
Expose the Gateway profile to an MCP client
Docker’s Toolkit documentation shows the client-side pattern below. Replace my_profile with your profile name:
{
"mcpServers": {
"docker-gateway": {
"command": "docker",
"args": ["mcp", "gateway", "run", "--profile", "my_profile"]
}
}
}
Save this in the MCP client’s documented server configuration location, restart or reload the client, and select the configured server. The exact UI and file location vary by client and Docker Desktop version.
Allow the required destinations
If Gateway network blocking is enabled, allow the configured Steel deployment, its browser WebSocket endpoint and the model endpoint. If your hostnames differ from local defaults, set matching allowed-host patterns. Browser-based clients that send an Origin header may also require a matching allowed origin.
Rank #4
Verify the connection without assuming success
- Check the MCP client’s server list or status using that client’s documented method.
- Confirm the Gateway profile is the one containing the Browser Use entry.
- Invoke a harmless installed tool and inspect the client’s returned result and logs.
- For HTTP, check the reverse proxy’s upstream connection and the container logs; do not publish the application port directly if following the documented topology.
- After a restart, invoke a follow-up browser tool call to confirm that the long-lived process and persistent profile volume are being reused.
The official pages describe this verification approach but do not claim a successful run for a particular machine.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteCommon failures and fixes
The image cannot be pulled
Check the image name and registry access, then retry docker pull ghcr.io/s-block/browser-use-mcp:latest. For a local build, run the command from the cloned repository and confirm the Dockerfile is present.
Gateway starts, then the browser session disappears
The server entry is probably short-lived. Set longLived: true and mount the named data volume. Ensure the client launches the intended Gateway profile.
Encrypted profiles cannot be opened after a restart
The storage master key does not match the key used to create the volume, or the volume was replaced. Restore the original key and volume; do not generate a new key for existing data.
HTTP requests fail through a proxy
Check that the proxy and container share mcp-backend, the proxy forwards to the container’s configured port, and the non-loopback deployment sets BROWSER_USE_MCP_TLS_TERMINATED=true. Confirm bearer credentials and allowed-host/origin patterns.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Best Value
Gateway reports blocked network access
Add the Steel deployment, browser WebSocket endpoint and model endpoint to the configured policy. Remember that this policy does not restrict remote Chromium’s destinations; retain Steel’s public-only egress enforcement.
Semantic actions fail while deterministic actions work
Configure a reachable OpenAI-compatible Chat Completions endpoint, model and key. Deterministic controls do not require a model, so this symptom points to model configuration rather than basic browser transport.
Origin or hostname is rejected
Set allowed-host patterns for the actual hostname. If the client sends an Origin header, add the matching allowed origin as well.
Operational checklist
- Pin an immutable image tag for controlled releases instead of relying on mutable
latest. - Back up the named
/datavolume and its master key together. - Keep secrets in Toolkit/Gateway secret storage or an untracked protected environment file.
- Use a dedicated profile, entry and volume for each trust boundary.
- Keep HTTP behind a TLS-terminating reverse proxy on a private network.
- Review Steel egress controls separately from Docker host allowlists.
- Watch container and proxy logs for startup, authentication and upstream errors.
Or skip the browser setup
If your goal is simply to obtain clean website screenshots rather than run browser automation tools, ScreenshotNeo provides a one-request screenshot API and an MCP server for AI clients. It accepts consent banners before capture and removes more than 60 known consent platforms, newsletter popups and chat widgets. Bot checks, blank pages, timeouts, failed loads and cache hits are not billed, and response headers identify the page verdict and billing result.
Use the API directly (see the ScreenshotNeo documentation):
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
It also offers take_screenshot, get_page_info and capture_pdf through MCP, so Claude, Cursor or another MCP client can request captures without your maintaining a browser container. The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.
Frequently Asked Questions
Can I use the published image with Docker MCP Gateway?
The documented Gateway path builds browser-use-mcp:local locally. The published registry image is documented for the container route; use the image form your Gateway configuration supports.
What survives a container restart?
State stored in the mounted /data volume survives. Gateway profile data additionally depends on retaining the same master key.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Is Docker Gateway’s allowHosts a complete SSRF boundary?
No. The project states that it covers traffic from the MCP container, not remote Chromium. Use the Steel proxy’s public-only destination enforcement as the browser-side boundary.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

