# AIHawk: An Anti-Detection Browser Agent and MCP Server for Web Automation

> AIHawk is an open-source AI browser agent that drives a real browser while evading standard anti-bot detection. It works as an MCP plugin for Claude Code, Codex, and Gemini CLI, or as a standalone web UI, and requires an OpenRouter API key to connect to a language model.

**feder-cr/AIHawk** — Open-source AI browser agent for web automation: a web browsing agent and computer-use agent in plain English. Browser MCP for Claude Code and Gemini CLI.

- Repository: https://github.com/feder-cr/AIHawk
- Website: https://github.com/feder-cr/AIHawk/wiki
- Stars: 31,627 · Forks: 4,675
- Language: Python
- License: MIT
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/feder-cr-aihawk

## What AIHawk Is and What Problem It Solves

AIHawk is an AI browser agent that controls a real browser the way a person would: moving a pointer, pressing keys, and reading what appears on the screen. The README opens with a direct claim: "Other AI browser agents get captchas. This one is invisible to anti-bots." The underlying package name in the repository is invisible-playwright-mcp, and the tool ships with a hardened browser engine, described in the README as StealthFox, that is designed to pass standard anti-bot fingerprinting checks.

The problem it solves is web automation that requires a real browser rather than an API: tasks such as checking flight prices across specific dates, filling out forms that require clicking calendar widgets, or reading structured data from pages that block automated HTTP clients. The README gives a specific worked example involving flight searches across multiple dates, where the agent is instructed to click calendar days rather than type them and to report actual availability rather than guessing. This positions AIHawk as a tool for automating the kind of website interactions that have no API and require understanding page layout.

## Two Installation Modes: MCP Plugin and Standalone Web UI

AIHawk supports two distinct operating modes. The first is as an MCP server plugin running inside an AI assistant. The second is as a standalone web UI with a chat interface on the left and a live browser view on the right.

For the MCP mode, the uv package manager must be installed first. On Linux:

```bash
curl -LsSf https://astral.sh/uv/install.sh | sh
source $HOME/.local/bin/env
```

With uv installed, the plugin installs into Claude Code as follows:

```bash
claude plugin marketplace add feder-cr/invisible_playwright_mcp
claude plugin install invisible-playwright-mcp@feder-cr
```

For Gemini CLI, the install command is:

```bash
gemini extensions install https://github.com/feder-cr/invisible_playwright_mcp
```

For the standalone web UI on Linux, the OpenRouter API key must be provided directly:

```bash
uvx invisible-playwright-mcp ui --openrouter-key sk-or-...
```

After starting the UI, it is accessible at http://127.0.0.1:8765. The README notes that on Windows the same process uses PowerShell with the uv installer from astral.sh. The web UI brings a full browser interface; the MCP mode exposes the same browser as a tool that the assistant can call.

## Configuration: OpenRouter Keys, Proxies, and Profiles

AIHawk uses OpenRouter as its model provider. Every interaction between the user's prompt and the language model is routed through the user's own OpenRouter key. The README is explicit that the model provider (OpenRouter) sees the conversation and what the agent reads on the page. Nothing is sent to the tool's author.

The startup options documented in the README include:

- --openrouter-key: the OpenRouter API key, also readable from the OPENROUTER_API_KEY environment variable
- --model: an OpenRouter model ID; defaults to z-ai/glm-5.3-flash, also overridable with INVISIBLE_MCP_MODEL
- --proxy: an HTTP or SOCKS5 proxy such as http://user:pass@proxy.example.com:8080; both host and port are required
- --seed: an integer that pins the browser identity, so the same seed always produces the same fingerprint
- --profile-dir: a directory where the browser profile is persisted across restarts, keeping logins and cookies
- --headed: shows the browser window during automation
- --binary: a path to a locally available engine binary that skips the download step but still applies the version check
- --host and --port: default to 127.0.0.1 and 8765; changing the host exposes an interface that has no authentication

A .env file placed in the directory from which the command runs is read at startup. It never overrides a value already set in the environment or via a flag, so the priority order is: flag, then environment, then .env, then default. The README recommends using OPENROUTER_API_KEY in a .env rather than passing --openrouter-key on the command line, since flags appear in shell history and on Linux in the process list.

## Platform Support, Privacy, and Data Storage

The pyproject.toml classifiers list only two operating systems: Microsoft Windows and POSIX Linux. macOS is not listed. The README does not document macOS support, and the browser engine ships binaries only for the two listed platforms according to the pyproject.toml comment: "The engine ships binaries for these two only, so a mac reader finds out at the first browser call unless the index says so first."

The README describes the privacy model in specific terms. The session, profiles, and screenshots are stored locally under INVISIBLE_MCP_HOME if that variable is set, or otherwise in the application-data directory of the operating system. The README states that sessions are the user's to delete, and that nothing is retained anywhere else. The only external connections are to the sites being automated (which see the browser as they would any Firefox), to OpenRouter under the user's key, and to GitHub for the initial engine download and a per-launch counter file. The README specifies that the counter file carries no identifier beyond the IP address visible in any HTTPS request.

Version 0.70.2 is the current release. The license changed on 2026-09-02: everything distributed before that date was under AGPL-3.0 and remains under it. From that date forward the license is MIT.

## The Family of Related Packages

AIHawk is built on top of two sibling packages that can be used independently. The first is invisible_playwright, described in the README as the engine as a Python library for writing code instead of prompts, with an API that matches Playwright's interface. The second is invisible_core, which handles the seed-to-fingerprint-to-preferences pipeline, proxy configuration, and geolocation. The MCP server itself is the invisible_playwright_mcp package with no subcommand; the web UI is the same package invoked as invisible-playwright-mcp ui.

The repository also includes plugin configuration files for multiple AI assistant environments: .claude-plugin/ for Claude Code, .codex-plugin/ for Codex, and gemini-extension.json for Gemini CLI. The .mcp.json file provides MCP server configuration for clients that use a configuration file rather than a plugin system. The wiki at github.com/feder-cr/invisible_playwright_mcp/wiki documents the MCP server tools, the configuration blocks for various clients, and the browser-agent landscape including comparisons with other tools.

## Limitations and When Not to Use It

AIHawk is a local tool. It requires a running process on the user's machine, an active OpenRouter key, and connectivity to the sites being automated. It is not a hosted service with a REST API that a backend system can call independently. Teams that need browser automation from a server environment without a local UI will need to run the MCP server process on that server or use a different architecture.

The README includes a section on responsible use: developers should read the terms of service of the sites they automate, respect rate limits, and not submit anything a human has not read. Sites that block automated browsers do so for reasons that include rate limits, copyright, and terms-of-service enforcement. The fact that AIHawk can bypass bot detection does not mean doing so is permissible for every target site.

Another limitation is the dependency on OpenRouter's model catalog. The default model is z-ai/glm-5.3-flash. Users who need a specific model must verify that it is available through OpenRouter and pass its model ID via --model. The model costs are billed to the user's OpenRouter account. There is no built-in rate-limit management for OpenRouter calls documented in the README.

## Comparison to Other Browser Agents

The wiki includes a guide titled "AI browser-agent landscape: browser-use, Operator-style and computer-use agents compared." The README describes that guide as covering the alternatives without giving specific comparative claims in the main README text.

Browser-use is a Python library for browser automation that also uses language models to interpret pages. The conceptual difference is that AIHawk centers on anti-detection, running a fingerprint-hardened browser engine rather than a standard Playwright or Chromium instance. Browser-use operates without that anti-detection layer and is aimed more at automation tasks on cooperative sites. AIHawk is aimed specifically at sites that apply bot-detection middleware. The choice between them depends on whether the target sites actively block automated browsers. For internal tooling against a team's own systems, anti-detection is irrelevant, and a simpler tool may suffice.

## Conclusion

Developers who need a browser agent that avoids CAPTCHA and bot-check systems, and who already work inside Claude Code, Codex, or Gemini CLI, will find AIHawk's MCP installation the fastest path to automated browsing in plain English. The standalone web UI option means non-developer users can also run it, provided they supply an OpenRouter key. The MIT license (covering versions from 2026-09-02 onward) allows commercial use. macOS is not supported by the pyproject.toml classifiers, so macOS users should confirm compatibility before committing to this tool. The key thing to verify before deployment is which OpenRouter model the workflow requires: the default model z-ai/glm-5.3-flash can be overridden with the --model flag or the INVISIBLE_MCP_MODEL environment variable.

## FAQ

### What is AIHawk?

AIHawk is an open-source AI browser agent that controls a real browser while avoiding anti-bot detection. It can run as an MCP plugin inside Claude Code, Codex, or Gemini CLI, or as a standalone web UI at http://127.0.0.1:8765, and uses an OpenRouter API key to connect to a language model.

### How do you use AIHawk?

Install the uv package manager, then add AIHawk as a plugin with claude plugin marketplace add feder-cr/invisible_playwright_mcp for Claude Code, or run it as a standalone web UI with uvx invisible-playwright-mcp ui --openrouter-key sk-or-... and open http://127.0.0.1:8765.

### Does AIHawk work on macOS?

The pyproject.toml classifiers list only Windows and Linux as supported platforms. The README notes the engine ships binaries for those two platforms only, so macOS users would encounter an error at the first browser call.

### What does AIHawk use to send data to a language model?

AIHawk routes all model calls through OpenRouter using the API key you provide. The README states that OpenRouter sees the conversation and what the agent reads on the page. Nothing is sent to the tool's author, and sessions are stored locally.

## Sources

- [feder-cr/AIHawk on GitHub](https://github.com/feder-cr/AIHawk)
- [License: MIT](https://github.com/feder-cr/AIHawk/blob/main/LICENSE)
- [Project website](https://github.com/feder-cr/AIHawk/wiki)
- [README](https://github.com/feder-cr/AIHawk/blob/main/README.md)
- [Releases](https://github.com/feder-cr/AIHawk/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/feder-cr-aihawk
