DEV Community

Hanzi Li
Hanzi Li

Posted on

I gave my AI agent access to my real browser. Here's what happened.

Your AI agent is great at writing code. But the moment it needs to check a dashboard, test a UI, or do anything in a browser — it stops and asks you to do it.

I built Hanzi to fix that. It's an open-source MCP server that gives your agent your real signed-in browser.

How it works

One command:

npx hanzi-in-chrome setup

This detects your AI agents (Claude Code, Cursor, Codex, Windsurf), installs the browser extension, and configures everything.

After that, your agent can just use the browser when it needs to. You don't have to tell it — it figures out when browser access would help.

Example: LinkedIn prospecting

I built a skill that automates the whole outreach workflow:

  • You give it a goal (networking, sales, hiring)
  • It searches LinkedIn in your real browser
  • Reads posts and profiles for personalization hooks
  • Drafts unique connection notes
  • Asks for your approval before sending

No scraping. No headless bot. LinkedIn sees normal user behavior because it is your real browser.

Why not Playwright MCP / Browser Use?

Those tools give your agent a new, empty browser. Every click is a separate tool call. Logging in is a nightmare.

Hanzi gives your agent your actual browser — already logged into everything. One tool call, entire task delegated.

Demo: https://www.youtube.com/watch?v=3tHzg2ps-9w
GitHub: https://github.com/hanzili/hanzi-in-chrome

Open source, free. Would love feedback.

Top comments (2)

Collapse
 
hronom profile image
Yevhen Tienkaiev •

Nice write-up. The trade-off I keep running into is not only “real browser vs empty browser,” but which state boundary should persist. Reusing a signed-in Chrome is convenient; I’d still bind each run to an explicit workspace/profile/account/origin/tab and keep a clear human gate for sign-in, 2FA, CAPTCHA and irreversible writes. After a reconnect, re-read the live origin/account/page and verify the authoritative result instead of trusting a cached tab handle.

I maintain Hronaut, a local visible Chromium/MCP workspace built around named isolated profiles and same-tab human takeover. It’s a complement when you want persistent project workspaces rather than granting an agent the whole personal browser. I’m curious whether Hanzi’s session scope can be narrowed per project, and how it reports stale or changed tabs after a long-running session: hronaut.dev/setup

Collapse
 
sleywill_45 profile image
Alex Serebriakov •

good write-up. the infra headaches with self-hosted headless browsers are real

snapapi.pics is worth knowing about — REST API that handles screenshots and PDF gen, no chromium to run