Browserbase MCP server and Dome
Give agents a real browser. Decide where it goes.
Browserbase runs cloud browsers that agents drive with Stagehand: navigate, act, observe and extract. Connect its hosted MCP server to Dome once, and rules decide every navigation on its URL. Every session, page and action lands in one audit trail.
How Dome helps
Dome provides a governed gateway for Browserbase
Every navigation decided
Rules read the URL of each navigate call. A carrier portal on the list opens, and a lookalike domain is refused.
One list per agent
Each agent's sites live in its own rule bundle. The release checker reaches staging, and a wider list for another agent doesn't touch it.
Each step on the record
Sessions, pages, clicks and extractions are each a tool call. The audit trail shows what the agent did, in order.
Get started
Browserbase behind the Gateway in three steps
Add the Browserbase server, sync its six tools, then give each agent its list of sites.
01
Add the Browserbase MCP server
Dome keeps the Browserbase API key and sends it as a Bearer token. Sessions run on your Browserbase account.
$ dome tools add --name browserbase \--url https://mcp.browserbase.com/mcp \--auth-method api-key \--credential-type shared \--authorization "Bearer $BROWSERBASE_API_KEY" \--gateway prod-gateway02
Sync the catalog
Browserbase lists its six tools without a session. The key is spent only when an agent calls one.
$ dome tools catalog sync browserbase03
Apply the rules
The portal list is scoped to shipment-tracker. Simulate a lookalike domain, then deploy.
$ dome rules apply browserbase-permit.cedar browserbase-sites.cedar \--agent shipment-tracker --name browserbase-sites
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Browserbase itself, see Browserbase's documentation.
Rules
Browse two carrier portals, nothing else
The permit opens the session tools to the agent. The forbid refuses any navigation whose URL isn't on one of two carrier portals, including lookalike domains and plain http.
permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "browserbase" && ["start", "navigate", "observe", "extract", "act", "end"].contains(resource.tool_name)}; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "browserbase" && resource.tool_name == "navigate" && !(resource has arguments && resource.arguments has url && (resource.arguments.url like "https://carrier.meridian-freight.com/*" || resource.arguments.url like "https://track.atlas-logistics.com/*"))};Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Site
- Agentshipment-tracker is registered and active
- Callerk.osei verified through Okta
- Rulecarrier.meridian-freight.com is on the list
Example agents
Three agents on Browserbase
Each one gets its own list of sites. A bundle per agent keeps one agent's list from widening another's.
shipment-tracker
Track shipments on carrier portals
Opens two carrier portals each morning and reads the status of open shipments. Any other site is refused.
- browserbase/start
- browserbase/navigate
- browserbase/extract
- browserbase/end
rate-sheet-reader
Read published rate sheets
Observes and extracts fuel surcharge tables from three carrier sites. It never fills a form.
- browserbase/navigate
- browserbase/observe
- browserbase/extract
release-checker
Smoke-test your own site
Clicks through checkout on staging after each deploy and reports what broke. Its list holds only your staging host.
- browserbase/navigate
- browserbase/act
- browserbase/observe
Agent workflow
Bringing it together
Connecting Browserbase to registered agents, models, and identity in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Tools
Agent service
Browserbase
This page
FAQ
Common questions
Does Browserbase have a hosted MCP server?
Yes, at mcp.browserbase.com/mcp. Dome adds it by URL with your Browserbase API key.
Can I limit which websites an agent opens in Browserbase?
Yes. Rules read the URL argument of every navigate call, so a listed site opens and any other host is refused.
Does a URL rule stop lookalike domains?
Yes, when the pattern ends at the host's slash. https://carrier.meridian-freight.com/* refuses carrier.meridian-freight.com.login-verify.net.
Why write rules against connection_name and not the tool's full name?
Dome rewrites connection names to ids when rules deploy. A pattern on the full tool name isn't rewritten, so a forbid written that way deploys and matches nothing.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreMCP server
GitHub
The GitHub MCP server behind the Tool Gateway, with rules that decide each call on its owner and repository.
Read moreIdentity
Microsoft Entra ID
Entra access tokens verified on every agent call, so rules read app roles and audit names the person.
Read moreRuntime
LangGraph
LangGraph agents with their model calls on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
Agent services: web, research, payments, voice and sandboxes
Web actions, research, payments, phone calls and code execution are where agents reach past your walls. Put each service behind the Gateway, and every call is authorized, metered and audited.
See them all