Ghost Browser provides per-tab session isolation with distinct fingerprints, proxies, and cookies
762
A browser automation agent using Ghost Browser (Chromium-based anti-detect browser) connected via CDP (Chrome DevTools Protocol), controlled by a vision-language model (VLM).
Ghost Browser provides per-tab session isolation with distinct fingerprints, proxies, and cookies — making it well-suited for multi-account automation and anti-bot bypass scenarios.
┌─────────────────────────────────────────────┐
│ Docker Container │
│ │
│ ┌──────────────┐ CDP websocket │
│ │ Ghost Browser│◄──────────────────────┐ │
│ │ (port 9223) │ │ │
│ └──────────────┘ │ │
│ │ socat │ │
│ ▼ │ │
│ 0.0.0.0:9222 (external CDP) │ │
│ │ │
│ ┌──────────────┐ │ │
│ │ Python API │ CDPClient ───────────┘ │
│ │ (port 443) │ LangGraph + VLM │
│ │ A2A + OpenAI │ │
│ └──────────────┘ │
│ │
│ VNC :5901 / noVNC :6901 │
└─────────────────────────────────────────────┘
docker build \
--build-context a2a_pkg=../../packages/a2a_agent \
-f Dockerfile.ubuntu \
-t ghost-browser-agent:latest \
.
docker build \
--build-context a2a_pkg=../../packages/a2a_agent \
-f Dockerfile.dev \
-t ghost-browser-agent:dev \
.
docker run -it \
-p 443:443 \
-p 6901:6901 \
-p 5901:5901 \
-p 9222:9222 \
-e VLM_URL=https://api.openai.com/v1 \
-e VLM_API_KEY=sk-... \
-e VLM_MODEL=gpt-4o \
ghost-browser-agent:latest
Mount a host directory to /data/ghost-profile — Ghost Browser will store all sessions,
cookies, extensions, and profile data there:
docker run -it \
-p 443:443 \
-p 6901:6901 \
-p 5901:5901 \
-p 9222:9222 \
-e VLM_URL=https://api.openai.com/v1 \
-e VLM_API_KEY=sk-... \
-e VLM_MODEL=gpt-4o \
-v /host/path/ghost-profile:/data/ghost-profile \
ghost-browser-agent:latest
The image bundles extensions from files/extensions/ at /data/extensions/ by default.
Mount your own directory to override:
-v /host/path/my-extensions:/data/extensions \
Supported formats:
.crx files — auto-unpacked at startup (CRX2 and CRX3)manifest.jsonOverride the path inside the container with GHOST_EXTENSIONS_DIR:
-e GHOST_EXTENSIONS_DIR=/my/ext/path \
-v /host/exts:/my/ext/path \
-e GHOST_USER_DATA_DIR=/my/custom/path \
-v /host/path:/my/custom/path \
| Variable | Default | Description |
|---|---|---|
VLM_URL | https://api.openai.com/v1 | VLM API endpoint |
VLM_API_KEY | `` | VLM API key |
VLM_MODEL | gpt-4o | VLM model name |
CDP_HOST | localhost | CDP host (internal) |
CDP_PORT | 9223 | CDP port (internal, socat forwards from 9222) |
VIEWPORT_WIDTH | 1920 | Browser viewport width |
VIEWPORT_HEIGHT | 1080 | Browser viewport height |
API_KEY | `` | Bearer token for API auth (optional) |
TRAJECTORY_DIR | None | Enable trajectory recording |
SEND_IMAGE | true | Send screenshot to VLM (set false for text-only LLMs) |
OMNIPARSER_URL | None | OmniParser API endpoint for element detection |
OMNIPARSER_API_KEY | None | Bearer token for OmniParser auth |
LOCATOR_URL | None | UI localization model endpoint |
LOCATOR_API_KEY | `` | Bearer token for locator model auth |
LOCATOR_MODEL | ui-tars | Locator model name (e.g. bytedance/ui-tars-1.5-7b) |
GHOST_USER_DATA_DIR | /data/ghost-profile | Ghost Browser user data directory (sessions, cookies, profiles) |
GHOST_EXTENSIONS_DIR | /data/extensions | Directory with extensions to load (.crx files or unpacked dirs) |
SOCKS_PROXY | `` | Transparent SOCKS5 proxy (e.g. socks5://host:1080) |
WORKSPACE_ID | None | Shared S3 workspace identifier |
WORKSPACE_MOUNT_PATH | /workspace | Local mount point for S3 workspace |
S3_BUCKET | None | S3 bucket for shared workspace |
S3_ENDPOINT_URL | None | S3 endpoint URL (omit for AWS S3) |
S3_ACCESS_KEY_ID | None | S3 access key |
S3_SECRET_ACCESS_KEY | None | S3 secret key |
S3_REGION | us-east-1 | S3 region |
AGENT_ID | ghost_browser_agent | Unique agent name written to blackboard |
S3_PREFIX | `` | Optional prefix before workspace_id in S3 |
| Port | Protocol | Description |
|---|---|---|
| 443 | HTTPS | Agent API (A2A + OpenAI-compatible) |
| 9222 | HTTP | Chrome DevTools Protocol (external, socat-forwarded) |
| 5901 | VNC | VNC server |
| 6901 | HTTP | noVNC web client |
The agent exposes a Google A2A JSON-RPC interface at https://host:443/.
Agent card: https://host:443/.well-known/agent.json
0.0.0.0:9222 → 127.0.0.1:9223/opt/ghost-browser/ghost-browser after dpkg -i; the startup script also checks /opt/ghost-browser-stable/, /usr/bin/, /usr/local/bin/The agent image exposes an MCP (Model Context Protocol) server on the same port as A2A at /mcp. Any MCP client — Claude Desktop, Cursor, Windsurf, ChatGPT Connectors, OpenAI Agents SDK — can list and invoke these tools using the pod's API_KEY as Bearer.
In production, Core proxies https://antidetect-ghost-agent.agents.forfetch.ai/mcp → the worker pod's /mcp.
| Tool (skill_id) | Description |
|---|---|
navigate | Navigate to a URL inside an isolated Ghost Browser identity |
click | Click on an element or coordinates |
double_click | Double-click on an element |
type | Type text into a focused element |
scroll | Scroll the page |
screenshot | Take a screenshot of the current page |
extract_text | Extract text content from the page |
evaluate_js | Execute JavaScript in the browser |
Input schemas are authored in apps/agents_mcp/app/seed.py. Skills without an explicit schema advertise a single {task: str} freeform parameter.
Content type
Image
Digest
sha256:3eb0a615d…
Size
904.6 MB
Last updated
5 months ago
docker pull superbizon007/antidetect-ghost-agent