Large Language ModelsGenerate imagesGenerate videos

Playwright MCP Token Usage: Setup Tips and Is It Safe?

Playwright MCP feeds a full accessibility snapshot back to your agent after every action, and that is where the tokens go. See the flags that trim usage, a lean config to paste, the CLI alternative, and an honest verdict on whether it is safe.

Playwright MCP Token Usage: Setup Tips and Is It Safe?
Cristian Da Conceicao
Founder of Picasso IA

Playwright MCP gives an AI agent real browser hands, and it bills you for every look at the page. One typical task has been reported at roughly 114,000 tokens through the MCP server, before the agent even finishes clicking. The same server can also sit inside a browser that holds your logged-in sessions. So the two questions in the search box are fair: how do you keep Playwright MCP token usage under control, and is it safe to run? Below you get the exact flags, a config you can paste, a comparison with the Playwright CLI, and a straight verdict on risk.

💡 Short answer: Turn screenshots off, leave optional capabilities disabled, run an isolated profile, and never aim the agent at accounts you cannot afford to lose. For long coding sessions, the Playwright CLI is the cheaper path.

Why Playwright MCP Eats Tokens

Microsoft's Playwright MCP server does not rely on screenshots by default. It returns an accessibility snapshot: a text tree of every heading, link, button, and input on the page, each tagged with a reference ID the model uses to click or type. That is a smarter way to drive a browser than guessing at pixels, because the model knows a button is a button without a vision pass. It is also a long block of text on any busy page, and you pay for it every time it arrives.

Snapshots arrive after every action

Each action tool, such as browser_click or browser_type, comes back with the new page state. The snapshot lands in your context window again and again. A ten-step task on a content-heavy site stacks ten trees in the window, and none of them leave until you clear the session.

The Playwright team's own comparison, as reported in several write-ups, put a typical task at about 114,000 tokens with MCP versus about 27,000 tokens with the CLI, a gap of roughly 4x. Treat those as ballpark figures, because page weight changes everything.

A clear glass pitcher overflowing with water onto a dark oak table beside a blurred laptop

A public bug report on the related Chrome DevTools MCP shows the same failure mode: context jumping from about 31,000 to 242,000 tokens after a single click on a heavy page. Different server, same culprit. The page tree is the cost driver, not the click.

Tool definitions load before you type

Every MCP server ships tool schemas, and your host loads them into context when the session starts. One practitioner measured 28.1k tokens, 14.1 percent of the window, for tool definitions across several servers in Claude Code. Playwright MCP has a long tool list, and each optional capability adds more. Hosts push back too: Cursor limits you to 40 tools across all servers.

💡 Tip: If you are not browsing in this session, disable the Playwright server. An idle server still costs schema tokens.

A top-down desk with a long printed text scroll beside a single glossy website photograph, glasses and a pencil on top

Setup That Keeps Context Small

The default config

This is the standard block for any host that reads an mcpServers section:

{
  "mcpServers": {
    "playwright": {
      "command": "npx",
      "args": ["@playwright/mcp@latest"]
    }
  }
}

It works, but the defaults favor convenience: a visible browser, a persistent profile, screenshots allowed, snapshots on, and every origin reachable. Most of that can be tightened in one line each.

Add it to Claude Code

claude mcp add playwright -- npx @playwright/mcp@latest --headless --isolated

Everything after the double dash is the server command. Run /mcp inside Claude Code to confirm it connected. If it fails to start, check that Node.js is installed and that npx is on your PATH.

A leaner starting config

{
  "mcpServers": {
    "playwright": {
      "command": "npx",
      "args": [
        "@playwright/mcp@latest",
        "--headless",
        "--isolated",
        "--image-responses=omit",
        "--allowed-origins=https://example.com;https://staging.example.com"
      ]
    }
  }
}

Here is what each flag does:

  • --headless runs the browser without a window. The default is a visible one.
  • --isolated keeps the profile in memory, so cookies disappear when the session ends.
  • --image-responses=omit removes screenshots from tool responses.
  • --allowed-origins takes origins separated by semicolons. Swap in your own domains.

Over-the-shoulder view of a developer typing on a slim aluminum laptop in a bright coworking space with exposed brick

Flags That Cut Token Usage

Not every flag saves tokens, and some trade tokens for safety. This table shows both effects side by side.

FlagWhat it doesToken effectSafety effect
--image-responses omitStrips screenshots from tool responsesRemoves image payloadsLess page data leaves the browser
--snapshot-mode noneTurns the automatic page snapshot off (README values: full, none)Largest cut, but the agent works half blindNeutral
--capsEnables optional toolsets: vision, pdf, devtools, config, network, storage, testingFewer tool schemas when left offSmaller attack surface
--storage-stateLoads cookies and localStorage into an isolated contextSkips login steps, so fewer actionsCarries real session data, so use a test account
--blocked-originsBlocks requests to the listed originsLighter pages and smaller treesConvenience, not a wall

Drop images first

--image-responses accepts allow, omit, or only, and the default is allow. For text-heavy jobs such as reading a pricing table or filling a form, omit is free savings. It trims the bill rather than fixing it, though. The accessibility snapshot stays the biggest cost.

--snapshot-mode none is the blunt instrument. Use it only when the agent drives the page through scripts, because a model that cannot see the page will guess.

Gate capabilities with caps

The --caps flag turns on optional toolsets: vision for coordinate-based mouse actions, pdf, devtools, config, network, storage, and testing. Keep them off until a task needs them. The testing set enables the verification tools, so switch it on only for sessions where you are writing tests.

3 Common Mistakes

  1. Marathon sessions. Snapshots pile up and never leave. Start a fresh session for each task.
  2. Screenshots for text jobs. If the answer sits on the page as text, the image is dead weight.
  3. Clicking what you could script. Ask the agent to write a Playwright test once, then run it with npx playwright test. The run prints a few lines instead of dozens of trees.

A hand turning a brushed steel rotary dial on a vintage amplifier down to a low setting

Playwright MCP vs Playwright CLI

The project README is open about the tradeoff: "CLI invocations are more token-efficient: they avoid loading large tool schemas and verbose accessibility trees into the model context." It keeps MCP for workflows that need "persistent state, rich introspection, and iterative reasoning."

Reported numbers

MeasurePlaywright MCPPlaywright CLI
Typical task (reported)About 114,000 tokensAbout 27,000 tokens
Snapshot handlingReturned inline in each responseSaved to disk as a YAML file
Per interaction (practitioner reports)Large snapshot payloadsRoughly 1,000 to 2,000 tokens after tuning
Tool schemasLoaded into context at session startNone, it runs as shell commands
Best fitPersistent state and iterative reasoningLong coding sessions and high throughput

These figures come from write-ups of the Playwright team's benchmark and from practitioners, not from a test I ran, so measure your own task before you rebuild a workflow around them.

When MCP still wins

  • Short, high-value inspections. One page, one question, one answer.
  • Debugging a flaky flow. The agent has to choose each next step from what it sees.
  • Hosts without shell access. When an MCP server is the only way to give the model browser tools.

A simple rule works well: probe with MCP, then freeze the flow into a script and run that script from the CLI.

Two workbenches side by side in a sunlit workshop, one cluttered with tools and one holding a single screwdriver

Is Playwright MCP Actually Safe?

The honest answer has two halves. It is safe enough for local development on sites you trust, with an isolated profile. It is not safe as an unsupervised agent inside the browser you bank with. The README says it plainly: "Playwright MCP is not a security boundary."

A heavy brass padlock locked through a chain on a weathered wooden gate with rain beads on the metal

Prompt injection from web pages

Everything the agent reads becomes model input. A page can hide text in white on white, in an HTML comment, or in an image alt attribute, telling the agent to ignore your instructions and open some other URL. The accessibility tree flattens all of it into plain text right next to your own prompt. Models resist some of these attacks and miss others.

What helps:

  • Browse only pages you trust, or pages you control.
  • Keep per-tool approval switched on in your host while you test.
  • Do not pair the browser with other powerful tools, such as a shell, email, or file writes, in the same session.

Logged-in profiles raise the stakes

By default the browser keeps a persistent profile on disk, and --user-data-dir sets where, so cookies survive between sessions. The --extension option goes further and connects to an Edge or Chrome instance you already have open. A hijacked agent in that mode acts as you, on every site you are signed into. For anything that touches a login, use --isolated plus a throwaway account.

Why origin filters are not walls

--allowed-origins and --blocked-origins take semicolon-separated lists, and the default allows everything. They cut noise and stray requests, but they are not a security boundary. The same goes for --secrets, which points to a dotenv file so sensitive strings get masked in responses: handy, not a guarantee. Leave --allow-unrestricted-file-access off, since it permits file:// URLs and access outside your workspace.

RiskWhat can happenFix
Prompt injectionPage text steers the agentTrusted sites and tool approvals
Persistent profileCookies stay on disk and get reused--isolated
Extension modeThe agent acts inside your real sessionsSkip it for sensitive accounts
File accessLocal files become reachableKeep unrestricted access off
Open portAnyone on the network reaches the serverBind to localhost, keep --allowed-hosts at its default

Hardening Checklist for Daily Use

Isolated profile first

  • Start with --isolated so nothing persists.
  • Need a login? Create a test account, save its state, and load it with --storage-state.
  • Keep passwords out of your prompts. Use --secrets with a dotenv file so the values are masked.
  • Pin an exact version instead of @latest, so a new release cannot change behavior under you.

A sealed glass terrarium on a windowsill holding a small living moss garden with droplets on the inner glass

Docker without exposing ports

For a throwaway browser that never touches your host profile, the README gives this command:

docker run -i --rm --init --pull=always mcr.microsoft.com/playwright/mcp

For a long-lived HTTP service, the README example publishes port 8931 and binds --host 0.0.0.0 inside the container. Publish it to loopback only, so other machines on your network cannot reach it:

docker run -d -i --rm --init --pull=always \
  --entrypoint node --name playwright -p 127.0.0.1:8931:8931 \
  mcr.microsoft.com/playwright/mcp \
  /app/cli.js --headless --browser chromium --no-sandbox --port 8931 --host 0.0.0.0

The --no-sandbox flag switches off Chromium's own sandbox, so the container becomes your boundary. Do not mount sensitive host folders into it.

A stack of weathered steel shipping containers at a harbor at golden hour with one door slightly ajar

💡 Verdict: Run Playwright MCP like a contractor in your house, not a family member. Give it one room (an isolated profile), a short task, and someone watching.

How to Use Sonnet 5 on PicassoIA

A language model makes a cheap second pair of eyes for an MCP config. Claude Sonnet 5 on PicassoIA is listed for coding tasks, which fits a config review well.

  1. Open the Claude Sonnet 5 page on PicassoIA.
  2. Paste your MCP config with placeholders in place of real values, and describe the job in one sentence, such as "read a pricing table once a week".
  3. Ask: "Which flags can I drop to cut tokens, and which risks remain?"
  4. Ask for the same flow as a Playwright test script, so you can run it from the CLI instead of paying for snapshots on every step.
  5. Check every flag it suggests against the Playwright MCP README before you add it. Models sometimes invent options.

If the model page offers a temperature setting, keep it low for config reviews, since you want consistent answers rather than creative ones.

Other models worth a try for the same job:

💡 Warning: Never paste .env files, API tokens, or cookies into any chat box. Swap in placeholders first.

MCP is not only for browsers, either. PicassoIA offers its own connector for Claude that exposes image generation, image editing, and video generation through a handful of tools, which keeps schema overhead small compared with a server that exposes a long browser tool list.

Create Your Own Images Next

Browser agents read the web, but your articles, products, and posts still need pictures that stop the scroll. Picasso IA puts photorealistic image models a click away, so you can go from an idea to a finished visual in minutes.

Start with PicassoIA Image for a fast first draft, then run the same prompt through Seedream 5 Pro and compare the results side by side.

A prompt formula that works: subject + setting + light + lens. For example:

A developer reviewing a laptop screen at a sunlit window desk, morning light from the left, 85mm lens, shallow depth of field, natural film grain.

Change one detail at a time, such as the light or the lens, and watch how the result shifts. Ten minutes of small experiments will sharpen your prompts more than any checklist. Open Picasso IA, paste the prompt above, and make your first image today.

A designer at a standing desk reviewing a large print of a mountain landscape beside a tablet in warm afternoon light

Share this article