Open-Source MCP Routers for Browser and Screenshot Tools
Compare open-source MCP routers, browser gateways and screenshot servers, then build a secure architecture for browser automation.
For local aggregation, use mcp-router or Moor. For zero-trust remote access, use OpenZiti MCP Gateway. For routing browser capacity across providers, use browser-gateway. Add a screenshot-capable backend such as agent-browser-mcp, blink-new/browser-mcp, or mcp-browser-screenshot.
The key distinction is scope: a general MCP router exposes several different servers through one endpoint, while a browser gateway manages browser sessions and provider capacity. ScreenshotNeo is the alternative to try first when you need a production screenshot API: it removes consent banners, popups and chat widgets before capture, bills only clean shots, and has the lowest paid plan.
What an MCP router does
Model Context Protocol (MCP) lets an AI client call tools exposed by a server. A router sits between the client and multiple MCP servers:
- The agent connects to one MCP endpoint.
- The router selects an enabled backend and namespaces its tools.
- The backend performs browser navigation, interaction, evaluation or capture.
- The result returns through the same endpoint.
This removes per-client configuration, but it also makes the router part of your security boundary. It can reach authenticated pages, execute JavaScript and store screenshots or session data.
Router types and when to use each
| Project | Best fit | Capabilities described in the research |
|---|---|---|
| mcp-router | Local multi-server aggregation | Installs servers from registries or npm, lazily spawns local stdio processes, proxies remote Streamable HTTP servers, and exposes per-server or aggregate routes. Workspaces can expose selected subsets. |
| Moor | Local control plane | Proxies stdio and HTTP/SSE servers. Profiles select enabled servers and disabled tools; documentation covers hot switching and audit logging. |
| OpenZiti MCP Gateway | Remote access with policy enforcement | Aggregates local and remote backends over stdio, HTTP, zrok or Agora. Adds cryptographic identity, mTLS, client isolation and tool-level permissions. |
| browser-gateway | Multiple cloud-browser providers | Routes by health, capacity and strategy, with automatic failover. Provides MCP tools, REST screenshot/content/scrape endpoints, persistent profiles, isolated concurrent sessions, a dashboard and frame-accurate replay. |
| OpenBrowser | Leased persistent browser slots | Persistent Chrome profiles, isolated slots, remote API, MCP tools, human-auth handoff, telemetry, audits, leases and heartbeats. |
Screenshot-capable MCP backends
- agent-browser-mcp: a Docker-native server wrapping the agent-browser CLI. It exposes more than 70 tools for navigation, clicking, filling, snapshots, screenshots, JavaScript, tabs, cookies, network blocking and sessions.
- blink-new/browser-mcp: a Puppeteer server for navigation, history, reload, viewport or full-page screenshots, extraction, interaction, waits and JavaScript. It documents Node.js 18 or newer.
- mcp-browser-screenshot: a Playwright server supporting viewport dimensions, full-page and CSS-selector capture, waits, clicks, typing and browser evaluation. Its setup requires installing Playwright Chromium.
- Universal Screenshot MCP: combines public web-page screenshots through Puppeteer with native desktop screenshots on macOS, Linux and Windows. Its documentation covers SSRF, path traversal, DNS rebinding, command injection and denial-of-service controls.
Choose an architecture
Local development
Use mcp-router or Moor with a local Playwright or Puppeteer backend. stdio keeps the attack surface small and is convenient when the agent and browser run on one machine.
Remote team or service
Put OpenZiti MCP Gateway in front of the backends when clients are remote or when you need cryptographic identity, mTLS, client isolation and per-tool permissions. Streamable HTTP or HTTP/SSE makes the service reachable by multiple clients.
Multiple browser providers
Use browser-gateway when browser capacity, provider health and failover matter. Register Browserless, Steel, Browserbase, Lightpanda or self-hosted Chrome as providers, then let the gateway select a healthy route.
Build a local screenshot router
The exact installation command depends on the selected repository. The following configuration pattern applies to any router that can register local stdio servers:
- Install Node.js 18 or newer and the router.
- Install the browser backend and its browser binary. Playwright users must install Chromium after installing the package.
- Register the backend as a named server.
- Expose only screenshot, navigation and wait tools needed by your workflow.
- Connect your MCP client to the router’s aggregate endpoint.
{
"servers": {
"screenshots": {
"command": "npx",
"args": ["mcp-browser-screenshot"]
}
},
"policy": {
"enabled_tools": [
"screenshots.screenshot",
"screenshots.wait",
"screenshots.navigate"
]
}
}
Use the equivalent profile or workspace mechanism in Moor or mcp-router. Keep browser evaluation disabled unless the workflow requires it.
Capture patterns
Viewport screenshot
Set a fixed viewport, navigate to the URL, wait for a stable selector, then capture. Fixed dimensions make visual comparisons reproducible.
Full-page screenshot
Use full-page mode after waiting for lazy content. Long pages can consume substantial memory; split very long documents or capture a selected element.
Element screenshot
Capture a CSS selector when you need a component rather than the entire page. Fail the job if the selector does not appear instead of silently returning a blank image.
Authenticated pages
Use isolated sessions, short-lived credentials and a dedicated profile per user or job. Never share a persistent profile between tenants.
Secure the router before exposing it
- Bind local servers to trusted interfaces and protect remote endpoints with authentication.
- Use bearer authentication where supported and unique session headers for concurrent users.
- Apply outbound firewall rules and allowlist destinations where possible.
- Block private IP ranges and validate redirects to prevent SSRF.
- Protect screenshot storage from path traversal and cross-session reads.
- Limit JavaScript evaluation; it runs arbitrary code in the loaded page context.
- Apply navigation, page-size, concurrency and execution-time limits to reduce denial-of-service risk.
- Namespace tools and expose only the minimum required surface.
- Log calls, destination URLs, session identifiers and failures without recording secrets.
Reliability, performance and cost
| Concern | Practical choice |
|---|---|
| Startup time | Keep browser workers warm for repeated jobs; use isolated contexts rather than launching a new process for every capture. |
| Concurrency | Use a queue and bounded worker pool. Browser-gateway can route around saturated providers; local routers need their own capacity limits. |
| Consistency | Pin viewport, device scale, timezone, locale, user agent and wait conditions. Disable animations with CSS when doing visual diffs. |
| Failure handling | Retry navigation and provider allocation with backoff, but do not blindly retry non-idempotent page actions. |
| Observability | Keep router audit logs and browser telemetry. Replay is useful when a screenshot differs from the expected result. |
| Cost | Self-hosting shifts cost to compute, browser maintenance and operations. Hosted providers charge for browser capacity or usage; measure queue time, memory and failure rates before selecting a plan. |
Common errors and fixes
| Error | Likely cause | Fix |
|---|---|---|
| Tool is missing | The server is not enabled in the router profile or workspace. | Enable the namespaced tool and reconnect the MCP client. |
| Browser executable not found | Chrome or Chromium was not installed, or the executable path is wrong. | Install the documented browser binary or set the backend’s executable path. |
| Timeout while loading | The page is slow, blocked, or waiting for a selector that never appears. | Check the URL directly, increase the timeout carefully, and use a selector that exists on the target page. |
| Blank screenshot | Navigation failed, content is lazy-loaded, or the page requires authentication. | Inspect the page result, wait for content, verify the session and capture a known public URL. |
| CAPTCHA or bot check | The target is challenging automated browsers. | Do not attempt to bypass access controls; use an authorized session or an API supplied by the site. |
| Requests leak between users | Contexts or persistent profiles are shared. | Create one isolated context/profile per job and clear cookies and storage afterward. |
| Remote MCP connection rejected | Authentication, mTLS, network policy or transport settings do not match. | Verify credentials, certificates, allowed origins and whether the client expects HTTP/SSE or Streamable HTTP. |
Or skip the browser setup
ScreenshotNeo is a website screenshot API and MCP server. One GET request returns PNG, JPEG, WebP or PDF. Before capture it accepts consent banners and removes more than 60 known consent platforms, newsletter popups and chat widgets; each step can be turned off. Bot checks, blank pages, timeouts, failed loads and cache hits cost nothing, and the response identifies the result with X-Page-Verdict and X-Billed headers. Its MCP server provides take_screenshot, get_page_info and capture_pdf for Claude, Cursor and other MCP clients.
See the ScreenshotNeo API documentation for all options. cURL:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python:
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
Every plan includes full-page capture with lazy images, CSS-selector capture, dark mode, 12 device presets or any viewport, retina scale, PDF controls, custom CSS and JavaScript, clicks, selector or network-idle waits, request blocking, headers, cookies, user agents, Authorization, timezone, geolocation, transparent backgrounds, resizing, configurable caching, signed links, async jobs with signed webhooks, bulk capture for 100 URLs per call, a usage API and an OpenAPI specification. Existing parameter names used by other screenshot APIs also work, which helps when switching.
The free plan includes 1,000 screenshots each month with no card. Paid plans start at $5 for 3,000 shots; yearly billing gives two months free. Create a free ScreenshotNeo account.
FAQ
Is a browser gateway the same as an MCP router?
No. A router aggregates MCP tools; a browser gateway additionally manages browser providers, sessions and capacity.
Which transport should I choose?
Use stdio for a local process. Use Streamable HTTP or HTTP/SSE for a remote service, with authentication and network controls.
Should screenshots use persistent profiles?
Only when a workflow needs durable login state. Otherwise use isolated temporary contexts to prevent cookie and tab leakage.
Can an MCP server capture desktop windows?
Universal Screenshot MCP documents native desktop capture on macOS, Linux and Windows; browser-only servers capture web pages.
How do I handle provider outages?
Use health-based routing and automatic failover in browser-gateway, or implement retries and a queue around local backends.
