Developers

Local API & MCP

A REST API and an MCP server that run inside the Privogrid desktop app, on your own computer. Drive profiles from your scripts, from Playwright / Puppeteer / Selenium, or from an AI agent. Included in Solo and every plan above it.

Available today ยท Solo and up
๐Ÿ”‘

1. Enable it in the app

Open API & MCP in the app's sidebar and click Create API key. Give the key a name, choose its permissions, optionally limit it to certain profiles or folders, set a per-minute rate limit and an expiry. Copy the key โ€” it is shown once and stored hashed (SHA-256).

The four permissions do not overlap:

  • read โ€” list profiles, list RPA processes, Synchronizer status.
  • control โ€” create a profile, and launch / stop / restart one.
  • automation โ€” drive a running profile (navigate, click, type, read, screenshot), run RPA processes, use POST /mcp, and see the CDP endpoint in a launch response.
  • admin โ€” delete a profile; also implies all of the above.

A typical script both launches a profile and then drives it, so give that key control and automation. A key that is missing the permission a call needs gets 403 with {"error":"missing permission: control"}; an unknown or expired key gets 401.

๐Ÿ–ฅ๏ธ

2. It listens locally only

The server binds to http://127.0.0.1:47800 while the app is running. Nothing about it goes over the internet: no cloud relay, no public endpoint. Authenticate with Authorization: Bearer <key> or X-API-Key: <key>.

๐ŸŽญ

3. Playwright, Puppeteer, Selenium

Launch a profile through the API with a key that has control, and if the same key also has automation the response includes the profile's CDP endpoint. Connect your existing scripts to it (chromium.connectOverCDP, puppeteer.connect, Selenium's debugger address) โ€” the profile keeps its fingerprint, proxy and cookies.

๐Ÿค–

4. MCP for AI agents

The same server speaks MCP (JSON-RPC over HTTP, protocol 2025-03-26) at POST /mcp, with 15 tools โ€” 14 of them on by default; delete_profile ships switched off because it wipes cookies and logins for good, and you turn it on per key set in API & MCP โ†’ MCP Server โ†’ Tool permissions. Each tool still needs its own permission on the key (launch_profile needs control, open_url needs automation, delete_profile needs admin), so an automation-only key can drive a running profile but cannot start one. Point any MCP client that supports the HTTP transport at it, with the API key as bearer token, and the agent can list, launch, navigate, click, type, read and screenshot profiles, and run your RPA processes.

# List your profiles (key with the read permission)
curl http://127.0.0.1:47800/v1/profiles \
  -H "Authorization: Bearer <your key>"

# Create one (control permission)
curl -X POST http://127.0.0.1:47800/v1/profiles \
  -H "Authorization: Bearer <your key>" -H "Content-Type: application/json" \
  -d '{"name":"shop-eu-01","proxy":"socks5://user:[email protected]:1080"}'

# Launch it (control permission; add automation to the same key to get
# the CDP endpoint back for Playwright/Puppeteer/Selenium)
curl -X POST http://127.0.0.1:47800/v1/profiles/<id>/launch -H "Authorization: Bearer <your key>"
โ†’ 200 # { "ok": true, "port": 9xxx, "cdp": "http://127.0.0.1:9xxx", ... }
REST routes (all under http://127.0.0.1:47800)
GET /helpEndpoint list, the MCP tool names and the permission map (needs a key with read)
GET /v1/profilesList profiles and their running state (read)
POST /v1/profilesCreate a profile (name, optional proxy, tag, notes) โ€” control
DELETE /v1/profiles/:idDelete a profile and its data (admin permission)
POST /v1/profiles/:id/launch ยท /stop ยท /restartStart, stop or restart a profile โ€” control
POST /v1/browser/:id/navigate ยท /click ยท /type ยท /read ยท /screenshotDrive a running profile without your own CDP client โ€” automation
GET /v1/rpa/processes ยท POST /v1/rpa/runList and run your RPA processes on chosen profiles โ€” automation
GET /v1/synchronizer/status ยท POST /v1/synchronizer/stopWindow Synchronizer status (read) and emergency stop (control)
POST /mcpMCP endpoint (automation, plus each tool's own permission) โ€” 15 tools, 14 on by default: list / create / delete / launch / stop / restart profile, open URL, click, type, read page, screenshot, list & run RPA processes, synchronizer status & stop

Rate limit per plan: Solo 300, Pro 600, Agency 900 requests per minute (a safety brake, not a meter; you can set a lower limit on any key). A blocked tool or an out-of-scope profile returns 403. Every call โ€” including refused ones โ€” is written to the audit log on the API & MCP page. Free-plan accounts cannot use the API (403).

Hosted cloud API โ€” planned

Everything above runs on your machine. A hosted API at api.privogrid.com โ€” manage profiles, fingerprints and team members without the app running โ€” is planned but not available yet. Tell us your use case and we will let you know when it opens.

[email protected]