open source localmcp
A secure local agent MCP where the agent gets what it needs from the page or the intranet wiki, never the API keys, and the data is never sent to servers.
TL;DR
- The user problem
Agents can’t read the pages behind your login. So people paste tokens into chats and hand sessions to third-party servers, and private data ends up outside anyone’s security review.2
- How I led
One rule: the agent gets the page, never the keys. One invention: browse returns only the sections the agent asked for, inside a token budget it sets.53
- Where it went
On public documentation pages it returns up to 889× fewer tokens than raw HTML, and the benchmark is in the repo for anyone to rerun.6
fewer tokens than raw HTML on Stripe’s API reference: 428,457 down to 482
localmcp token benchmark, 1 October 2026smaller on GitHub’s Issues reference: 330,083 tokens of HTML to 20,228, or 4,002 at the default budget
localmcp token benchmark, 1 October 2026credentials handed to the agent. You sign in by hand, and it only ever gets the page
localmcp: signed in as you, on your machineUser problem
An engineer asks a coding agent why last night’s deploy failed. The answer sits in a build log behind a secure dashboard login in his orgs developer portal, and the agent can’t sign in. So it asks for an API token, and the engineer pastes one into the chat.2
It works. It’s also how private data walks out the door.
Third-party servers
Cloud scrapers and hosted browsers read private pages on their own machines, so they need your session to do it. Your internal wiki and the login that opens it pass through a company outside your security review.2
Credentials on the move
Every workaround copies a key somewhere new: a session cookie into a scraper’s config, an API token into a chat. Each copy is one more place it can leak, from a vendor’s logs to your own shell history.2
Secrets next to strangers’ text
Whatever the agent reads lands in the same context as those keys, and page text looks just like your instructions. One hidden line on any page can try to talk a key back out.2
My role
Design and build to let an agent read what its person can see, on that person’s machine, without ever holding the keys or flooding its own context.
How I led
I built it on one rule and one invention. The rule: the agent gets the page, never the keys. The invention: it reads only what it asked for.
focus, maxTokens and diff
browse ranks the page’s sections against the agent’s question and caps the answer at a token budget the agent sets. On a second read, diff returns only what changed. That’s the invention. The rest is table stakes, done carefully.3
Sign in by hand, once
localmcp login opens a visible browser on its own profile. You sign in the way you always do, passkeys and 2FA included, then close it. Later reads reuse that session, nothing is relayed, and the credentials never pass through the agent.4
Read-only while signed in
I made clicking and typing default to off whenever a saved login is in use. The agent reads as you. It can’t act as you unless you switch that on.5
Every page is untrusted
Page text comes back fenced as data, not instructions. Host allow and deny lists are checked on every request, redirects and iframes included.5
Claims you can check
The site’s measured numbers come from a benchmark in the repo, and I published the pages where it barely helps too.6
Measured results
On the benchmark’s pages, it’s the difference between an agent that can afford to read the web and one that can’t.6
localmcp cuts tokens per page sharply versus Playwright MCP
Savings of 68% to 98% across six pages, project benchmark, default budget
- Playwright MCP
- localmcp
Show the numbers
| Page | Playwright MCP | localmcp | Fewer tokens | Reads per 200k |
|---|---|---|---|---|
| Stripe API reference | 30,724 | 482 | 98% | 6 → 414 |
| GitHub REST: Issues | 87,350 | 4,002 | 95% | 2 → 49 |
| Next.js docs | 19,721 | 799 | 96% | 10 → 250 |
| Wikipedia: MCP | 20,288 | 3,991 | 80% | 9 → 50 |
| Python: json module | 25,381 | 3,996 | 84% | 7 → 50 |
| Hacker News | 12,207 | 3,945 | 68% | 16 → 50 |
One Playwright MCP snapshot against localmcp at its default 4,000-token budget. Tokens ≈ characters ÷ 4. Source: localmcp token benchmark, 1 October 2026
Stripe API reference
428,457 tokens of rendered HTML. localmcp returns 482, because Stripe serves its own markdown and localmcp asks for it first.6
GitHub’s Issues reference
One Playwright MCP snapshot of the page is 87,350 tokens. localmcp’s default read is 4,002, with the sections it left out listed by name.6
Where it barely helps
Pages that are already mostly text shrink less: Python’s json docs 3×, the Hacker News front page 2×.6
Scoped by default
Version 0.3.0 made “signed in, but scoped” the default. MIT licensed.7