
Jet Browser Verifier
io.github.masakaaiv0.8.0Updated Oct 10, 2026
Verify an isolated WPE WebKit runtime with native-input, DOM, PNG, and cleanup evidence.
Overview
Lets an assistant run one bounded verification of an isolated WPE WebKit runtime and return native-input, DOM, PNG and cleanup evidence.
- What it does
- The server exposes two tools. jet_browser_capabilities returns the pinned image, platform, evidence contract and explicit non-capabilities without starting Docker (R25). jet_browser_verify runs one bounded verification: it starts the immutable public linux/amd64 image, disables browser networking, opens the image's local fixture, types through native input, checks the DOM, captures a fresh PNG and cleans up (R3, R26). Only one verification runs at a time, and failures come back as MCP tool errors (R27, R29).
- When to use it
- Use it when you need a repeatable, isolated check that a WPE WebKit runtime starts, accepts native input, renders the expected DOM and produces a valid screenshot. It is a runtime verifier, not a general browsing server, and does not offer public-web navigation, CDP, personal browser profiles, credentials, a hosted service or telemetry (R4, R5).
- Requirements
- Node.js 24+ and Docker (R7), on an x86_64 host or with Docker amd64 emulation (R8). The MCP image is started with the Docker socket mounted (R14); the first verification may pull the public image from GHCR (R9). No authentication, environment variables or headers are declared.
Installation
In SourceWeft
- Open Jet Browser Verifier in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
Jet Browser MCP verifier
This local stdio server gives an MCP client one narrow way to verify Jet Browser. It starts the immutable public linux/amd64 image, disables browser networking, opens the image's local fixture, types through native input, checks the DOM, captures a fresh PNG, and cleans up.
It is a runtime verifier, not a general browsing server. It does not expose public-web navigation, CDP, personal browser profiles, credentials, a hosted service, or telemetry.
Requirements
- Node.js 24+
- Docker
- An x86_64 host, or Docker amd64 emulation
The first verification may pull the public image from GHCR. Browser execution itself uses Docker's --network=none boundary. The image is pinned by digest in server.mjs.
Install from the OCI package
The versioned MCP image starts the stdio server directly. It needs the Docker socket only when jet_browser_verify launches the separately isolated WPE WebKit runtime:
Docker socket grants host-level control. Configure this local server only for a trusted MCP client. The outer MCP container has networking disabled, and the browser container it launches independently uses --network=none, resource limits, reduced capabilities, and deterministic cleanup.
The package metadata for the official MCP Registry is server.json. The OCI image carries the matching io.modelcontextprotocol.server.name ownership annotation.
Install from source
Add the server to an MCP client with an absolute checkout path:
The process speaks MCP on stdout and writes operational errors only to stderr. It exits when the client closes stdin.
Tools
Only one verification can run at a time. A client-side cancellation aborts the child process. The server caps child output and total runtime; failures are returned as MCP tool errors rather than protocol failures.
A successful call returns structured content like:
The screenshot byte count varies. A pass requires at least 1,000 decoded PNG bytes and exact agreement among the expected page title, native text input, and DOM state.
Verify the integration
The protocol test starts the real stdio server, performs an MCP handshake, lists its tools, and calls the capability tool without requiring Docker:
The repository's standalone CI remains the end-to-end runtime proof. To execute that same Docker acceptance locally:
Security boundary
- The MCP call accepts no command, URL, image, profile, or path argument.
- The child process receives only the Docker connection variables it needs; application secrets are not forwarded.
- The container has browser networking disabled, bounded CPU, memory, PIDs, shared memory, and capabilities, and is removed after the check.
- The verifier never attaches to a running personal browser.
- Treat Docker access as privileged host access. Only configure this server for trusted local MCP clients.
For a broader embedding boundary, use Jet Browser's versioned tool declarations in sdk/tools.mjs and supervise each isolated container from your own harness.
Source: integrations/mcp/README.md at commit 5114d06
Tools
0Version history
1- v0.8.0LatestOct 10, 2026


