Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
firefox-devtools-mcp — Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through WebDriver BiDi | Kitploit
Tools/GitHubGitHub/mozilla/firefox-devtools-mcp
Android SecurityDynamic Analysis (Sandboxing)Network MappingWeb Application ExploitationAPI Security TestingDebuggersInformation GatheringWeb SecurityPenetration TestingMobile Security
GitHub
34552337 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
mozilla/firefox-devtools-mcp

firefox-devtools-mcp

Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through WebDriver BiDi

View Repository

Firefox DevTools MCP

npm version CI codecov License: MIT License: Apache 2.0

Glama

Model Context Protocol server for automating Firefox via WebDriver BiDi (through Selenium WebDriver). Works with Claude Code, Claude Desktop, Cursor, Cline and other MCP clients.

Repository: https://github.com/mozilla/firefox-devtools-mcp

Note: This MCP server requires a local Firefox browser installation and cannot run on cloud hosting services like glama.ai. Use npx @mozilla/firefox-devtools-mcp@latest to run locally, or use Docker with the provided Dockerfile.

Security

Browser MCP servers carry inherent risks. A few key practices:

  • Use a dedicated Firefox profile. Never run the server against your regular profile — the agent has access to whatever the browser can reach, including cookies and saved sessions.
  • Be cautious about which sites you visit. Pages can return content designed to manipulate the agent (prompt injection). Stick to sites you control or trust.
  • Enable only the tool modules you need. The default basic preset already includes evaluate_script; --tool-preset slim drops it. Higher presets such as --tool-preset developer (debugging, network, console, profiler) and --tool-preset mozilla (privileged context) expand what the agent can do further.

See SECURITY.md for a full breakdown of risks and how to report vulnerabilities.

Requirements

  • Node.js ≥ 20.19.0
  • Firefox 100+ installed (auto‑detected, or pass --firefox-path)

Install and use with Claude Code or Codex (npx)

Recommended: use npx so you run the latest published version from npm.

Option A — CLI

Claude Code

claude mcp add firefox-devtools npx @mozilla/firefox-devtools-mcp@latest

# Headless + viewport via args
claude mcp add firefox-devtools npx @mozilla/firefox-devtools-mcp@latest -- --headless --viewport 1280x720

# Or via environment variables
claude mcp add firefox-devtools npx @mozilla/firefox-devtools-mcp@latest \
  --env START_URL=https://example.com \
  --env FIREFOX_HEADLESS=true

Codex

codex mcp add firefox-devtools -- npx @mozilla/firefox-devtools-mcp@latest

# Headless + viewport via args
codex mcp add firefox-devtools -- \
  npx @mozilla/firefox-devtools-mcp@latest -- --headless --viewport 1280x720

# Or via environment variables
codex mcp add firefox-devtools \
  --env START_URL=https://example.com \
  --env FIREFOX_HEADLESS=true \
  -- npx @mozilla/firefox-devtools-mcp@latest

Option B — Edit the configuration file

Claude Code

Add to Claude Code’s mcp_settings.json:

{
  "mcpServers": {
    "firefox-devtools": {
      "command": "npx",
      "args": ["-y", "@mozilla/firefox-devtools-mcp@latest", "--headless", "--viewport", "1280x720"],
      "env": {
        "START_URL": "about:blank"
      }
    }
  }
}

Codex

Add to ~/.codex/config.toml:

[mcp_servers.firefox-devtools]
command = "npx"
args = ["-y", "@mozilla/firefox-devtools-mcp@latest", "--headless", "--viewport", "1280x720"]

[mcp_servers.firefox-devtools.env]
START_URL = "about:blank"

Option C — Helper script (local dev build)

npm run setup
# Choose Claude Code; the script saves JSON to the right path

Try it with MCP Inspector

npx @modelcontextprotocol/inspector npx @mozilla/firefox-devtools-mcp@latest --start-url https://example.com --headless

Then call tools like:

  • list_pages, select_page, navigate_page
  • take_snapshot then click_by_uid / fill_by_uid
  • list_network_requests (always‑on capture), get_network_request
  • list_downloads (always‑on capture), set_download_behavior
  • screenshot_page, list_console_messages

CLI options

You can pass flags or environment variables (names on the right):

  • --firefox-path — absolute path to Firefox binary
  • --headless — run without UI (FIREFOX_HEADLESS=true)
  • --viewport 1280x720 — initial window size
  • --profile-path — use a specific Firefox profile
  • --firefox-arg — extra Firefox arguments (repeatable)
  • --start-url — open this URL on start (START_URL)
  • --accept-insecure-certs — ignore TLS errors (ACCEPT_INSECURE_CERTS=true)
  • --connect-existing — attach to an already-running Firefox instead of launching a new one (CONNECT_EXISTING=true)
  • --marionette-port — Marionette port for connect-existing mode, default 2828 (MARIONETTE_PORT)
  • --pref name=value — set Firefox preference at startup via moz:firefoxOptions (repeatable)
  • --tool-preset — select which tool modules to enable: slim, basic (default), developer, mozilla, or all. See Tool modules and presets. (TOOL_PRESET)
  • --tools — explicit list of tool modules to enable, overriding --tool-preset entirely (e.g. --tools pages network script). See Tool modules and presets.
  • --enable-script — deprecated, use --tool-preset developer or --tools ... script debugging. Selects the developer tool preset. (ENABLE_SCRIPT=true)
  • --enable-privileged-context — deprecated, use --tool-preset mozilla or --tools ... privileged prefs. Selects the mozilla tool preset. Requires MOZ_REMOTE_ALLOW_SYSTEM_ACCESS=1 (ENABLE_PRIVILEGED_CONTEXT=true)
  • --android-device — enable Firefox for Android mode; value is the ADB device serial (e.g. emulator-5554). Run adb devices to list connected devices. Omit the value or use auto to select the single connected device automatically.
  • --android-wipe-app-data — confirm that Android mode wipes all data of the target app. Required together with --android-device. (ANDROID_WIPE_APP_DATA=true)
  • --android-package — Android app package name, default org.mozilla.firefox. Other packages: org.mozilla.firefox_beta for Firefox Beta, org.mozilla.fenix for Firefox Nightly, org.mozilla.fenix.debug for Firefox Nightly Debug, org.mozilla.geckoview_example for geckoview (ANDROID_PACKAGE)
  • --unrestricted-save-paths — let the saveTo parameter write anywhere on disk instead of the default roots. See Saving bulky output to disk and the security note in SECURITY.md. (UNRESTRICTED_SAVE_PATHS=true)
  • --log-file — write MCP server logs to a file instead of stderr. Useful for debugging sessions with MCP clients that hide server output. Set DEBUG=* to also include verbose debug logs. Example: --log-file /tmp/firefox-mcp.log

Tool modules and presets

Tools are grouped into modules. You choose which modules to expose either with a named preset (--tool-preset) or with an explicit list (--tools). When both are given, --tools wins and the preset is ignored.

Modules: pages, snapshot, input, network, console, screenshot, downloads, utilities, management, webextension, profiler, screencast, script, debugging, prefs, privileged.

Presets (each is a superset of the previous):

Download Tool