Large Language ModelsGenerate imagesGenerate videos
Playwright MCP Token Usage: Setup Tips and Is It Safe?
Playwright MCP feeds a full accessibility snapshot back to your agent after every action, and that is where the tokens go. See the flags that trim usage, a lean config to paste, the CLI alternative, and an honest verdict on whether it is safe.
Playwright MCP gives an AI agent real browser hands, and it bills you for every look at the page. One typical task has been reported at roughly 114,000 tokens through the MCP server, before the agent even finishes clicking. The same server can also sit inside a browser that holds your logged-in sessions. So the two questions in the search box are fair: how do you keep Playwright MCP token usage under control, and is it safe to run? Below you get the exact flags, a config you can paste, a comparison with the Playwright CLI, and a straight verdict on risk.
💡 Short answer: Turn screenshots off, leave optional capabilities disabled, run an isolated profile, and never aim the agent at accounts you cannot afford to lose. For long coding sessions, the Playwright CLI is the cheaper path.
Why Playwright MCP Eats Tokens
Microsoft's Playwright MCP server does not rely on screenshots by default. It returns an accessibility snapshot: a text tree of every heading, link, button, and input on the page, each tagged with a reference ID the model uses to click or type. That is a smarter way to drive a browser than guessing at pixels, because the model knows a button is a button without a vision pass. It is also a long block of text on any busy page, and you pay for it every time it arrives.
Snapshots arrive after every action
Each action tool, such as browser_click or browser_type, comes back with the new page state. The snapshot lands in your context window again and again. A ten-step task on a content-heavy site stacks ten trees in the window, and none of them leave until you clear the session.
The Playwright team's own comparison, as reported in several write-ups, put a typical task at about 114,000 tokens with MCP versus about 27,000 tokens with the CLI, a gap of roughly 4x. Treat those as ballpark figures, because page weight changes everything.
A public bug report on the related Chrome DevTools MCP shows the same failure mode: context jumping from about 31,000 to 242,000 tokens after a single click on a heavy page. Different server, same culprit. The page tree is the cost driver, not the click.
Tool definitions load before you type
Every MCP server ships tool schemas, and your host loads them into context when the session starts. One practitioner measured 28.1k tokens, 14.1 percent of the window, for tool definitions across several servers in Claude Code. Playwright MCP has a long tool list, and each optional capability adds more. Hosts push back too: Cursor limits you to 40 tools across all servers.
💡 Tip: If you are not browsing in this session, disable the Playwright server. An idle server still costs schema tokens.
Setup That Keeps Context Small
The default config
This is the standard block for any host that reads an mcpServers section:
It works, but the defaults favor convenience: a visible browser, a persistent profile, screenshots allowed, snapshots on, and every origin reachable. Most of that can be tightened in one line each.
Add it to Claude Code
claude mcp add playwright -- npx @playwright/mcp@latest --headless --isolated
Everything after the double dash is the server command. Run /mcp inside Claude Code to confirm it connected. If it fails to start, check that Node.js is installed and that npx is on your PATH.
Loads cookies and localStorage into an isolated context
Skips login steps, so fewer actions
Carries real session data, so use a test account
--blocked-origins
Blocks requests to the listed origins
Lighter pages and smaller trees
Convenience, not a wall
Drop images first
--image-responses accepts allow, omit, or only, and the default is allow. For text-heavy jobs such as reading a pricing table or filling a form, omit is free savings. It trims the bill rather than fixing it, though. The accessibility snapshot stays the biggest cost.
--snapshot-mode none is the blunt instrument. Use it only when the agent drives the page through scripts, because a model that cannot see the page will guess.
Gate capabilities with caps
The --caps flag turns on optional toolsets: vision for coordinate-based mouse actions, pdf, devtools, config, network, storage, and testing. Keep them off until a task needs them. The testing set enables the verification tools, so switch it on only for sessions where you are writing tests.
3 Common Mistakes
Marathon sessions. Snapshots pile up and never leave. Start a fresh session for each task.
Screenshots for text jobs. If the answer sits on the page as text, the image is dead weight.
Clicking what you could script. Ask the agent to write a Playwright test once, then run it with npx playwright test. The run prints a few lines instead of dozens of trees.
Playwright MCP vs Playwright CLI
The project README is open about the tradeoff: "CLI invocations are more token-efficient: they avoid loading large tool schemas and verbose accessibility trees into the model context." It keeps MCP for workflows that need "persistent state, rich introspection, and iterative reasoning."
Reported numbers
Measure
Playwright MCP
Playwright CLI
Typical task (reported)
About 114,000 tokens
About 27,000 tokens
Snapshot handling
Returned inline in each response
Saved to disk as a YAML file
Per interaction (practitioner reports)
Large snapshot payloads
Roughly 1,000 to 2,000 tokens after tuning
Tool schemas
Loaded into context at session start
None, it runs as shell commands
Best fit
Persistent state and iterative reasoning
Long coding sessions and high throughput
These figures come from write-ups of the Playwright team's benchmark and from practitioners, not from a test I ran, so measure your own task before you rebuild a workflow around them.
When MCP still wins
Short, high-value inspections. One page, one question, one answer.
Debugging a flaky flow. The agent has to choose each next step from what it sees.
Hosts without shell access. When an MCP server is the only way to give the model browser tools.
A simple rule works well: probe with MCP, then freeze the flow into a script and run that script from the CLI.
Is Playwright MCP Actually Safe?
The honest answer has two halves. It is safe enough for local development on sites you trust, with an isolated profile. It is not safe as an unsupervised agent inside the browser you bank with. The README says it plainly: "Playwright MCP is not a security boundary."
Prompt injection from web pages
Everything the agent reads becomes model input. A page can hide text in white on white, in an HTML comment, or in an image alt attribute, telling the agent to ignore your instructions and open some other URL. The accessibility tree flattens all of it into plain text right next to your own prompt. Models resist some of these attacks and miss others.
What helps:
Browse only pages you trust, or pages you control.
Keep per-tool approval switched on in your host while you test.
Do not pair the browser with other powerful tools, such as a shell, email, or file writes, in the same session.
Logged-in profiles raise the stakes
By default the browser keeps a persistent profile on disk, and --user-data-dir sets where, so cookies survive between sessions. The --extension option goes further and connects to an Edge or Chrome instance you already have open. A hijacked agent in that mode acts as you, on every site you are signed into. For anything that touches a login, use --isolated plus a throwaway account.
Why origin filters are not walls
--allowed-origins and --blocked-origins take semicolon-separated lists, and the default allows everything. They cut noise and stray requests, but they are not a security boundary. The same goes for --secrets, which points to a dotenv file so sensitive strings get masked in responses: handy, not a guarantee. Leave --allow-unrestricted-file-access off, since it permits file:// URLs and access outside your workspace.
Risk
What can happen
Fix
Prompt injection
Page text steers the agent
Trusted sites and tool approvals
Persistent profile
Cookies stay on disk and get reused
--isolated
Extension mode
The agent acts inside your real sessions
Skip it for sensitive accounts
File access
Local files become reachable
Keep unrestricted access off
Open port
Anyone on the network reaches the server
Bind to localhost, keep --allowed-hosts at its default
Hardening Checklist for Daily Use
Isolated profile first
Start with --isolated so nothing persists.
Need a login? Create a test account, save its state, and load it with --storage-state.
Keep passwords out of your prompts. Use --secrets with a dotenv file so the values are masked.
Pin an exact version instead of @latest, so a new release cannot change behavior under you.
Docker without exposing ports
For a throwaway browser that never touches your host profile, the README gives this command:
docker run -i --rm --init --pull=always mcr.microsoft.com/playwright/mcp
For a long-lived HTTP service, the README example publishes port 8931 and binds --host 0.0.0.0 inside the container. Publish it to loopback only, so other machines on your network cannot reach it:
The --no-sandbox flag switches off Chromium's own sandbox, so the container becomes your boundary. Do not mount sensitive host folders into it.
💡 Verdict: Run Playwright MCP like a contractor in your house, not a family member. Give it one room (an isolated profile), a short task, and someone watching.
How to Use Sonnet 5 on PicassoIA
A language model makes a cheap second pair of eyes for an MCP config. Claude Sonnet 5 on PicassoIA is listed for coding tasks, which fits a config review well.
💡 Warning: Never paste .env files, API tokens, or cookies into any chat box. Swap in placeholders first.
MCP is not only for browsers, either. PicassoIA offers its own connector for Claude that exposes image generation, image editing, and video generation through a handful of tools, which keeps schema overhead small compared with a server that exposes a long browser tool list.
Create Your Own Images Next
Browser agents read the web, but your articles, products, and posts still need pictures that stop the scroll. Picasso IA puts photorealistic image models a click away, so you can go from an idea to a finished visual in minutes.
Start with PicassoIA Image for a fast first draft, then run the same prompt through Seedream 5 Pro and compare the results side by side.
A prompt formula that works: subject + setting + light + lens. For example:
A developer reviewing a laptop screen at a sunlit window desk, morning light from the left, 85mm lens, shallow depth of field, natural film grain.
Change one detail at a time, such as the light or the lens, and watch how the result shifts. Ten minutes of small experiments will sharpen your prompts more than any checklist. Open Picasso IA, paste the prompt above, and make your first image today.