v1.0.1 · macOS & Windows

The browser your AI can actually use

BrAIn is a real desktop browser with an MCP server built into the same process. Your agent sees the real DOM, acts on the real page — and you can rewind it, pause it and audit every step.

Every page inspectable·every action verifiable·every moment rewindable

40+ MCP tools WebKit · WebView2 No telemetry Source on GitHub
browser_click role:button:Buy
Rewind ● 12 snapshots
CheckoutDocsNew tab
shop.example/checkout
Frozen · 2 min ago

USB-C Cable — 2 m

Braided, 240 W, e-marked.

$19.00incl. tax
● In stock — 14 left
agent · navigate
Live

Browsers haven’t changed in fifteen years.

Tabs, an address bar — and a prayer that your AI agent in another app isn’t hallucinating what it clicked.

The browser that remembers — and the first one your AI can actually use.

The AI isn’t a plugin.It shares the process and the DOM — no extensions, no screen-scraping, no relay server to hack.
Rewind doesn’t exist anywhere else.Other browsers can go Back. Only BrAIn can rewind the page itself.
Agents you can verify.Every call logged with stable locators, tagged on the Rewind timeline, pausable mid-flight, replayable as approved flows.
Dev-first instrumentation.The browser sees what the page does from the first byte — every listener, every call site.
40+
MCP tools — navigate, snapshot, click, type, tabs, network, cookies, rewind…
1
process — the browser is the MCP server. No extension, no relay.
174 MB
RAM with 25 live tabs on macOS, vs 14.1 GB in Chrome (how we measured)
0
telemetry. The app has no analytics or phone-home code.
What's inside

A browser first.
An agent platform second.

Everything you expect — tabs, bookmarks, history, passwords, import, private mode — plus the pieces that make an AI trustworthy in a browser.

An MCP server in the same process

Point Claude, Devin or any MCP client at the binary. Snapshots give the agent an accessibility tree with stable element refs (e5), then it clicks, types and verifies on the real page — same window you're looking at.

// claude_desktop_config.json { "mcpServers": { "brain": { "command": "/Applications/BrAIn.app/Contents/MacOS/BrAIn" } } }

Rewind

Drag a scrubber and the page goes back in time. In-memory, opt-in, searchable.

25 live tabs, agent-proof

Each tab is its own native view — the agent jumps between pages and nothing reloads: no lost drafts, dead sockets or re-verification. Still 81× lighter than Chrome doing it.

A kill switch you hold

Ctrl Shift . pauses every action tool. Reads keep working. Risky moments ask for OS auth.

DevTools, in the window

Elements, console, network, cookies — and a complete event-listener registry that sees delegated, anonymous and removed listeners with their call site.

Flows: the agent's work becomes reusable tools

After a task, the agent proposes a parameterised replay of what it did. Nothing runs until you review every step — then it appears as a real flow_* MCP tool.

proposereview each stepapproveflow_*

An audit trail for every call

Each tool call is logged with arguments, result, duration and stable locators (role:button:Save) because refs like e7 change per load. Passwords, card fields and cookie values are masked and never written.

Password vault

Encrypted, unlocked with Touch ID or Windows Hello. Generator and autofill built in.

Remap every shortcut

Click a row, press keys. Conflicts are caught, changes sync instantly. Try it →

Bring your stuff

Import bookmarks, history and passwords from Chrome and friends — the wizard pulls them straight from local profiles.

…and it’s a real browser

Everything the promo doesn’t need to brag about, done properly:

Tabs — drag, mute, reopenOmnibox autocomplete⌘K command palettePrivate tabsBookmarks & historySession restoreFind · zoom · print/PDFDownloads decisions logPicture-in-pictureLink-hover statusPassword vault · OS authAurora chrome
Rewind · the signature feature

Browsing finally has an undo.

The tweet that refreshed away. The price that changed mid-checkout. The form that ate itself. Rewind keeps a compressed timeline of what each tab showed — and lets you scrub, search and read it, byte-for-byte.

  • Opt-in, in memory only. Off until you turn it on. Nothing touches disk, nothing leaves the machine.
  • Search the past. “When did this page say ‘sold out’?” — find the snapshot and jump to it.
  • See what the agent did. Agent actions are tagged on the timeline (the mint ticks).
  • Cheap to run. Adaptive capture ≈ ≤2.5% of a core; age, size and count budgets live in the ⚙ menu.
  • Private by default. Private tabs, login pages and excluded sites are never recorded.

This is a simulation of the interaction, running entirely in your browser. Drag the scrubber, or type a search.

markets.example — live0 snapshots
Frozen · now
Live
MCP client ⇄ BrAIn (stdio)illustrative session
Agent running
Agent control

Powerful agents.
Human veto.

Agentic browsing is only useful if you can trust it. BrAIn makes the agent visible, interruptible and auditable — not a black box in another app.

  • One keystroke pauses all action tools. They return BLOCKED and tell the agent to wait; read-only tools keep working.
  • A live Agent indicator pulses while a tool runs, with a count of blocked attempts.
  • Hand-offs for human-only steps. Logins, 2FA and CAPTCHAs: browser_ask_human brings the tab forward and waits for you.
  • Sensitive moments need OS auth — the password vault never opens for an agent on its own.

Try it: press Pause agent while the session is running.

Shortcuts

Your keys. Your browser.

Over 50 actions have default bindings that follow each platform's conventions — and every one is remappable from about:shortcuts, with live conflict detection.

  • Click, press, done. Capture mode never fires the shortcut you're recording.
  • Conflicts are explained and you choose whether to steal the key.
  • Unbind with ⌫, reset one or all. Changes persist and sync everywhere.
about:shortcuts
Click a row, then press the new shortcut. Esc cancels · ⌫ unbinds.
Benchmarks

25 real sites. 25 tabs. None closed.

Each site opened as a new tab in one window, load time from the page's own loadEventEnd, memory as the browser's whole process tree after every tab.

Memory after 25 tabs

Chrome14,102 MB
BrAIn174 MB
81×less memory at the end — and BrAIn idles at 156 MB vs Chrome's 1,211 MB.
ChromeBrAInRAM (MB) as each tab opens — hover
Read this before quoting it. macOS on Apple Silicon, one sample per site, same machine and network, Chrome with a fresh profile and no extensions. BrAIn's number is real process-tree memory but reflects WebKit's shared process pool — it is a different engine, not a smaller Chrome. Load speed is a near tie (BrAIn faster on 11 sites, Chrome on 13; differences under ~200 ms are noise). Windows has not been benchmarked yet and will use more memory than macOS: WebView2 is Chromium. Full method and raw data in BENCHMARK.md.
Per-site load times click a column to sort
SiteChrome (ms)BrAIn (ms)Δ
How it works

No bridge. No extension. One process.

Other setups drive a browser from the outside. BrAIn is built the other way round: the browser exposes itself.

Your AI client Claude · Devin any MCP client stdio JSON-RPC BrAIn PROCESS MCP host40+ tools Controllertabs · state · trust Rewindin-memory timeline Activity + Flowsaudit · approvals DriverWKWebView (macOS) · WebView2 + CDP (Windows) Tab 1 · own view Tab 2 · own view Tab 3 · own view … every tab
Connect your AI

Two lines of config.

BrAIn speaks MCP over stdio. Point your client at the executable and it opens a browser window and serves tools until the client disconnects.

  • Typical loop: browser_navigate → browser_snapshot → browser_click / browser_type → browser_state to verify.
  • Elements by ref or intent: e5, css:#id, text:Sign in, role:button:Submit, xpath:…
  • Open on a page: add "args": ["https://example.com"].
Download

Get BrAIn v1.0.1

Free. Installers are hosted right here, with SHA-256 checksums you can verify in your browser before you run anything.

macOS · Apple SiliconTested every release — per-tab views, Rewind, MCP tools and the benchmark ran here.
Windows · x64First public build. Per-tab WebView2 views are new — expect rough edges and please report them. Logs: %LOCALAPPDATA%\BrAIn\brain.log
Not yetIntel Macs, Linux and ARM Windows. Builds are unsigned for now (see steps above).
FAQ

Straight answers.

How is this different from Playwright MCP or an MCP browser extension?

Those drive a browser from the outside — a debug connection, a throwaway profile or an extension sandbox. BrAIn is the MCP server: your real profile and sessions, no setup, and the agent can use things that exist only inside the browser (Rewind, the activity log, flows, the pause switch, the listener registry).

The trade-off: BrAIn only automates itself. If your workflow spans other desktop apps, a computer-use agent can still do that — and can control BrAIn too.

What about CAPTCHAs and logins?

BrAIn doesn't try to defeat them. browser_ask_human brings the tab to the front, shows you a card, waits while you do the step, then the agent carries on. Passwords are never typed by the agent from memory — the vault needs your OS authentication.

Is Rewind recording everything I do?

No. It is off by default and asks before it starts. When on, it keeps compressed DOM snapshots in memory only (never on disk), skips private tabs, login pages and sites you exclude, drops a tab's history when the tab closes, and enforces age and size budgets. The agent can only read it if you separately allow that.

Does BrAIn send data anywhere?

There is no telemetry, analytics or update-check code in the app. It talks to the sites you visit and to your MCP client over stdio. Whatever your AI client does with tool results is governed by that client.

Why is the RAM so low on macOS — and will Windows match it?

On macOS each tab is a WKWebView; WebKit shares a process pool and throttles background pages hard. Windows uses WebView2, which is Chromium: expect Chromium-class memory per live tab, though it shares one browser process and our views avoid Chrome's extra helpers. I haven't measured Windows yet, so I won't quote a number.

Why does my OS warn me about the installer?

The builds are not code-signed yet (that needs a paid certificate on each platform). Verify the SHA-256 on this page, then: on macOS right-click the app → Open (or xattr -dr com.apple.quarantine /Applications/BrAIn.app); on Windows choose More info → Run anyway in SmartScreen.

Can I use it as my daily browser?

It has the daily-driver basics — tabs, bookmarks, history, autocomplete, downloads, private tabs, password vault, import, PiP, find, zoom, print, session restore. It does not have an extension store or sync. Try it for a week and tell us what's missing.