BrAIn is a real desktop browser with an MCP server built into the same process. Your agent sees the real DOM, acts on the real page — and you can rewind it, pause it and audit every step.
Every page inspectable·every action verifiable·every moment rewindable
Braided, 240 W, e-marked.
Browsers haven’t changed in fifteen years.
Tabs, an address bar — and a prayer that your AI agent in another app isn’t hallucinating what it clicked.
The browser that remembers — and the first one your AI can actually use.
Everything you expect — tabs, bookmarks, history, passwords, import, private mode — plus the pieces that make an AI trustworthy in a browser.
Point Claude, Devin or any MCP client at the binary. Snapshots give the agent an accessibility tree with stable element refs (e5), then it clicks, types and verifies on the real page — same window you're looking at.
Drag a scrubber and the page goes back in time. In-memory, opt-in, searchable.
Each tab is its own native view — the agent jumps between pages and nothing reloads: no lost drafts, dead sockets or re-verification. Still 81× lighter than Chrome doing it.
Ctrl Shift . pauses every action tool. Reads keep working. Risky moments ask for OS auth.
Elements, console, network, cookies — and a complete event-listener registry that sees delegated, anonymous and removed listeners with their call site.
After a task, the agent proposes a parameterised replay of what it did. Nothing runs until you review every step — then it appears as a real flow_* MCP tool.
Each tool call is logged with arguments, result, duration and stable locators (role:button:Save) because refs like e7 change per load. Passwords, card fields and cookie values are masked and never written.
Encrypted, unlocked with Touch ID or Windows Hello. Generator and autofill built in.
Click a row, press keys. Conflicts are caught, changes sync instantly. Try it →
Import bookmarks, history and passwords from Chrome and friends — the wizard pulls them straight from local profiles.
Everything the promo doesn’t need to brag about, done properly:
The tweet that refreshed away. The price that changed mid-checkout. The form that ate itself. Rewind keeps a compressed timeline of what each tab showed — and lets you scrub, search and read it, byte-for-byte.
This is a simulation of the interaction, running entirely in your browser. Drag the scrubber, or type a search.
Agentic browsing is only useful if you can trust it. BrAIn makes the agent visible, interruptible and auditable — not a black box in another app.
BLOCKED and tell the agent to wait; read-only tools keep working.browser_ask_human brings the tab forward and waits for you.Try it: press Pause agent while the session is running.
Over 50 actions have default bindings that follow each platform's conventions — and every one is remappable from about:shortcuts, with live conflict detection.
Each site opened as a new tab in one window, load time from the page's own loadEventEnd, memory as the browser's whole process tree after every tab.
| Site | Chrome (ms) | BrAIn (ms) | Δ |
|---|
Other setups drive a browser from the outside. BrAIn is built the other way round: the browser exposes itself.
BrAIn speaks MCP over stdio. Point your client at the executable and it opens a browser window and serves tools until the client disconnects.
browser_navigate → browser_snapshot → browser_click / browser_type → browser_state to verify.e5, css:#id, text:Sign in, role:button:Submit, xpath:…"args": ["https://example.com"].Free. Installers are hosted right here, with SHA-256 checksums you can verify in your browser before you run anything.
%LOCALAPPDATA%\BrAIn\brain.logThose drive a browser from the outside — a debug connection, a throwaway profile or an extension sandbox. BrAIn is the MCP server: your real profile and sessions, no setup, and the agent can use things that exist only inside the browser (Rewind, the activity log, flows, the pause switch, the listener registry).
The trade-off: BrAIn only automates itself. If your workflow spans other desktop apps, a computer-use agent can still do that — and can control BrAIn too.
BrAIn doesn't try to defeat them. browser_ask_human brings the tab to the front, shows you a card, waits while you do the step, then the agent carries on. Passwords are never typed by the agent from memory — the vault needs your OS authentication.
No. It is off by default and asks before it starts. When on, it keeps compressed DOM snapshots in memory only (never on disk), skips private tabs, login pages and sites you exclude, drops a tab's history when the tab closes, and enforces age and size budgets. The agent can only read it if you separately allow that.
There is no telemetry, analytics or update-check code in the app. It talks to the sites you visit and to your MCP client over stdio. Whatever your AI client does with tool results is governed by that client.
On macOS each tab is a WKWebView; WebKit shares a process pool and throttles background pages hard. Windows uses WebView2, which is Chromium: expect Chromium-class memory per live tab, though it shares one browser process and our views avoid Chrome's extra helpers. I haven't measured Windows yet, so I won't quote a number.
The builds are not code-signed yet (that needs a paid certificate on each platform). Verify the SHA-256 on this page, then: on macOS right-click the app → Open (or xattr -dr com.apple.quarantine /Applications/BrAIn.app); on Windows choose More info → Run anyway in SmartScreen.
It has the daily-driver basics — tabs, bookmarks, history, autocomplete, downloads, private tabs, password vault, import, PiP, find, zoom, print, session restore. It does not have an extension store or sync. Try it for a week and tell us what's missing.