DEV Community

ScriptMasterLabs
ScriptMasterLabs

Posted on Originally published at scriptmasterlabs.com

Safari 27's Built-in MCP Server: The Complete Setup (17 Tools, Exact Commands, Honest Limits)

Safari 27 (released September 17, 2026) is the first major browser with a built-in Model Context Protocol server. Apple announced it on the WebKit blog (Saron Yitbarek) after debuting it in Safari Technology Preview 247 on July 1, 2026.

Setup

  1. Safari > Settings > Advanced > check "Show features for web developers"
  2. Safari > Settings > Developer > check "Allow remote automation and external agents"
  3. Connect:
    • Claude Code: claude mcp add safari-mcp -- "/usr/bin/safaridriver" --mcp
    • Codex: codex mcp add safari-mcp -- "/usr/bin/safaridriver" --mcp
    • Any client: mcp.json → command /usr/bin/safaridriver, args ["--mcp"]
  4. Prompt like "Find bugs on my site in Safari" — Apple says the agent discovers the server on its own.

All 17 tools

browser_console_messages, browser_dialogs, close_tab, create_tab, evaluate_javascript, get_network_request, get_page_content (markdown/HTML/JSON), list_network_requests, list_tabs, navigate_to_url, page_info, page_interactions (click/type/scroll/hover/keyPress in sequence), screenshot (PNG), set_emulated_media, set_viewport_size, switch_tab, wait_for_navigation.

Apple's use cases

See how code renders in Safari; Safari-compat style/layout inspection; performance (navigation timing, resource load times); accessibility (missing labels, ARIA, contrast); verify user states (forms, checkout flows, selections).

Privacy model

Fully local, no network calls of its own, no AutoFill or personal Safari data access. Captured content goes to your agent — not Apple. Caveat: what your agent's model does with the data afterward depends on the agent. Trust accordingly.

Honest limits

Local-only; no remote plane. Cannot use saved logins (by design). iOS/mobile session handling undocumented. browser_dialogs can dismiss JS dialogs autonomously. Full disclosure: I reproduced all commands and tool names from Apple's WebKit blog — no Mac in my environment, so no hands-on verification.

Why it matters for the agent economy

Hands (MCP) + wallet (x402's HTTP 402 handshake) = the debugging loop and the commerce loop converging. When an agent can verify a checkout flow and pay the 402 challenge itself, agents become customers. If you bill per tool call on an MCP server, the money side is the hard part — I've written up per-call x402 billing with live receipts at scriptmasterlabs.com/monetize-mcp-server.

Full canonical version with every receipt: https://scriptmasterlabs.com/safari-mcp-server

Top comments (0)