v1.9.0 ยท MCP-native ยท system WebKit ยท MIT

The browser for agents.

One tiny Rust binary driving the WebView your OS already ships โ€” no Chromium, no download, no RAM bonfire.
Navette is French for shuttle: the small vessel that carries your agent from page to page. Always fueled โ€” the engine ships with your OS.

626 KB installed 0 MB engine download 79 MB peak RAM vs 599 MB 11 ms navigate โ†’ read 2 ms act 3 OS engines, 1 binary 18 MCP tools
Why

Every agent drags along the same stack: headless Chromium.

Playwright and Puppeteer download ~300โ€“400 MB of browser per machine and burn ~100โ€“200 MB of RAM per open page, driven by CDP โ€” a protocol built for DevTools, not for agents. But what an agent actually needs is small: go to a page, execute its JS, read the text, take a screenshot, click, type. Your OS already ships a full rendering engine. navette is the few hundred KB of glue that drives it.

Playwright + ChromiumLightpandaBrowserbase (cloud)navette
Engine download~300โ€“400 MB96 MBnone (remote)none โ€” the engine is the OS
Engine completenessfullpartial (alpha)fullfull โ€” system WebKit, real layout + JS
RAM per page~100โ€“200 MB~123 MB peakn/a (their bill)WebView-native
ProtocolCDPCDPRESTMCP native (+ plain HTTP)
Runs whereanywhereanywheretheir cloudanywhere with a system WebView

On Windows the system WebView is WebView2 โ€” Chromium, preinstalled on every Windows 10/11: Chromium-grade rendering from a 0.6 MB binary. Headless Chromium is the Postgres of scraping; navette is the embedded SQLite.

Benchmarks

Measured, not vibes.

Same machine, same 100-page corpus (50 static / 50 JS-built) on loopback HTTP. Medians; RAM is the peak of the whole process tree. Reproducible with one command โ€” see BENCHMARKS.md.

Metricnavette (system WebKit)Playwright + ChromiumLightpanda (CDP)
Install size (on disk)0.6 MB215.8 MB96.1 MB
Cold start โ†’ first page read669 ms934 ms33 ms
Navigate โ†’ readable content11 ms12 ms12 ms
Act: type + click round-trip2 ms33 ms18 ms
Peak RAM, whole tree79 MB599 MB41 MB
Crawl: 100 pages navigate+read1.5 s1.8 s0.9 s

The honest reading: Lightpanda wins fresh-process boot and peak RAM โ€” it parses a partial DOM, cannot render and cannot screenshot. navette is the fastest full-rendering reader, and it acts 9โ€“16ร— faster than both (2 ms vs 18โ€“33 ms). On the real web: 95โ€“100% success vs 85% for Playwright. Resident daemon mode drops the cold start an agent feels to 24โ€“37 ms.

Install

One command. No browser comes with it โ€” one was already there.

Homebrew ยท macOS

arm64 bottle, WKWebView backend.

brew install slabbdev/tap/navette

cargo ยท any platform

From source on crates.io โ€” macOS, Windows, Linux.

cargo install navette-browser

Docker ยท stdio MCP

Container with WebKitGTK, amd64 + arm64.

docker run -i --rm ghcr.io/slabbdev/navette navette mcp

navette serve

HTTP JSON API on 127.0.0.1:8765 โ€” 19 routes, sessions, cookies, PNG screenshots.

navette mcp

MCP stdio for agent hosts โ€” auto-starts serve if nothing is listening.

navette install-daemon

Resident LaunchAgent, warm from login โ€” first page in 24โ€“37 ms.

The surface

8 primitives. No DevTools baggage.

Everything an agent does on a page, and nothing else. The same surface on WKWebView (macOS), WebView2 (Windows) and WebKitGTK (Linux) โ€” parity is compile-enforced by the WebviewKit trait.

navigate

open a URL in a session โ€” with_content folds the read into one round-trip

read

page as markdown, text or DOM

screenshot

native capture โ€” what the compositor drew

click

real pointer + mouse events; Radix/HeadlessUI menus open

type

React-safe native setter

evaluate

run JS in the page

wait

selector / idle / timeout

sessions

parallel named sessions, lazily created

โ€ฆplus hover key scroll upload viewport session_show/session_hide state_export/state_import โ€” 18 tools on the MCP surface. JS dialogs are auto-handled in-page, so agents never deadlock on a hidden modal.

Not a scraper โ€” an actor

It logs in. It reads. It comes back with proof.

navette doesn't fetch pages for later parsing โ€” it acts: opens sessions, fills forms, clicks through flows, verifies with screenshots, keeps state across steps. Scraping is the demo; acting is the product.

A logged-in 'Secure Area' page with a green confirmation banner โ€” the result of a human login performed inside a visible navette session.
One-time human login, then out of the way. session_show brings the ghost window on screen โ€” titled, key, focus-gated โ€” for the OAuth/2FA/captcha only a human can do; session_hide parks it again. The session state stays.
A dev.to article rendered in the navette session, ready to be returned as markdown by the read primitive.
Read like an agent. navigate + read in one round-trip returns clean markdown of a JS-built page; screenshots come back as MCP image content โ€” the agent sees the page. Full working recipe: demo/dailydev.
Security

Loopback by default. Isolation by build failure.

The full reference posture lives in docs/SECURITY.md. The short version:

Loopback only

The server binds 127.0.0.1; non-local Host headers are refused โ€” DNS-rebinding guard, /health exempt.

Token auth, constant-time

--token SECRET requires Authorization: Bearer on every route; comparison is constant-time.

Session isolation, CI-enforced ร—3 engines

A cookie imported into one session must not appear in another's jar โ€” or the build fails. Non-persistent WKWebsiteDataStore (macOS) ยท per-session WebView2 profile + InPrivate (Windows) ยท fresh WebContext, cookies never touch disk (Linux).

Explicit state, nothing implicit

Cross-run state moves only through state_export / state_import. Proxy credentials are redacted in logs.

The agent's JS runs sandboxed

Page JS executes inside the OS WebKit sandbox โ€” not in your terminal, not in the server.

Native input is focus-gated

Keystrokes are posted only after the Window Server confirms the session's window is key โ€” a key can never land in someone else's app.

Known gaps, stated plainly: real OS-level mouse trajectories, request/response network interception, OS file-dialog automation and full-page capture are not implemented yet โ€” tracked honestly rather than approximated. WebKit โ‰  Blink: a minority of Chrome-tuned sites may render slightly differently (on Windows, WebView2 is Chromium).