← Daniel Clark
08 / 08 open source localmcp

Sign in to edit

Get the deep dive

The full story behind localmcp: the research, the design decisions and how the team got there. Leave your details and I’ll send it to you.

Used only to send you the deep dive. Never shared.

Deep dive requests

    08 · Open source · MCP & agent security

    open source localmcp

    A secure local agent MCP where the agent gets what it needs from the page or the intranet wiki, never the API keys, and the data is never sent to servers.

    889×

    fewer tokens than raw HTML on Stripe’s API reference: 428,457 down to 482

    localmcp token benchmark, 1 October 2026
    16×

    smaller on GitHub’s Issues reference: 330,083 tokens of HTML to 20,228, or 4,002 at the default budget

    localmcp token benchmark, 1 October 2026
    0

    credentials handed to the agent. You sign in by hand, and it only ever gets the page

    localmcp: signed in as you, on your machine
    01

    User problem

    An engineer asks a coding agent why last night’s deploy failed. The answer sits in a build log behind a secure dashboard login in his orgs developer portal, and the agent can’t sign in. So it asks for an API token, and the engineer pastes one into the chat.2

    It works. It’s also how private data walks out the door.

    01

    Third-party servers

    Cloud scrapers and hosted browsers read private pages on their own machines, so they need your session to do it. Your internal wiki and the login that opens it pass through a company outside your security review.2

    02

    Credentials on the move

    Every workaround copies a key somewhere new: a session cookie into a scraper’s config, an API token into a chat. Each copy is one more place it can leak, from a vendor’s logs to your own shell history.2

    03

    Secrets next to strangers’ text

    Whatever the agent reads lands in the same context as those keys, and page text looks just like your instructions. One hidden line on any page can try to talk a key back out.2

    02

    My role

    Design and build to let an agent read what its person can see, on that person’s machine, without ever holding the keys or flooding its own context.

    03

    How I led

    I built it on one rule and one invention. The rule: the agent gets the page, never the keys. The invention: it reads only what it asked for.

    01

    focus, maxTokens and diff

    browse ranks the page’s sections against the agent’s question and caps the answer at a token budget the agent sets. On a second read, diff returns only what changed. That’s the invention. The rest is table stakes, done carefully.3

    02

    Sign in by hand, once

    localmcp login opens a visible browser on its own profile. You sign in the way you always do, passkeys and 2FA included, then close it. Later reads reuse that session, nothing is relayed, and the credentials never pass through the agent.4

    03

    Read-only while signed in

    I made clicking and typing default to off whenever a saved login is in use. The agent reads as you. It can’t act as you unless you switch that on.5

    04

    Every page is untrusted

    Page text comes back fenced as data, not instructions. Host allow and deny lists are checked on every request, redirects and iframes included.5

    05

    Claims you can check

    The site’s measured numbers come from a benchmark in the repo, and I published the pages where it barely helps too.6

    04

    Measured results

    On the benchmark’s pages, it’s the difference between an agent that can afford to read the web and one that can’t.6

    localmcp cuts tokens per page sharply versus Playwright MCP

    Savings of 68% to 98% across six pages, project benchmark, default budget

    • Playwright MCP
    • localmcp
    Show the numbers
    PagePlaywright MCPlocalmcpFewer tokensReads per 200k
    Stripe API reference30,72448298%6 → 414
    GitHub REST: Issues87,3504,00295%2 → 49
    Next.js docs19,72179996%10 → 250
    Wikipedia: MCP20,2883,99180%9 → 50
    Python: json module25,3813,99684%7 → 50
    Hacker News12,2073,94568%16 → 50

    One Playwright MCP snapshot against localmcp at its default 4,000-token budget. Tokens ≈ characters ÷ 4. Source: localmcp token benchmark, 1 October 2026

    01

    Stripe API reference

    428,457 tokens of rendered HTML. localmcp returns 482, because Stripe serves its own markdown and localmcp asks for it first.6

    02

    GitHub’s Issues reference

    One Playwright MCP snapshot of the page is 87,350 tokens. localmcp’s default read is 4,002, with the sections it left out listed by name.6

    03

    Where it barely helps

    Pages that are already mostly text shrink less: Python’s json docs 3×, the Hacker News front page 2×.6

    04

    Scoped by default

    Version 0.3.0 made “signed in, but scoped” the default. MIT licensed.7

    Give the agent the page, not the keys.Read only what the question needs.Publish the benchmark, not the claim.

    Sources

    1. localmcp2026
    2. localmcp: the problem
    3. localmcp: how it reads
    4. localmcp: signed in as you, on your machine
    5. localmcp: signed in, but scoped
    6. localmcp token benchmark1 October 2026
    7. localmcp changelog1 October 2026
    8. GitHub: NETWORK101/localmcp