Riffle · Open source · ISC

A browser your agent can read

Riffle is an open-source MCP server and CLI that lets your agent use real websites without screenshots. Several steps per call. Only what changed comes back.

Your browser agent spends a turn and an image on every click. Or it re-reads the whole page after every action, and still can't tell that the Checkout button is behind a cookie dialog, that the price is struck through, or that a field is disabled.

Riffle gives your agent what the page means. Hidden, covered, primary, disabled, struck through, truncated: these are facts on the page outline, so your agent reads them instead of guessing from pixels.

What your agent reads

modal d1 "Cookie preferences" covers=page
  button b1 "Accept all" primary
  button b2 "Reject"
main covered-by=d1
  h1 "Your cart"
  item "Trail shoe 42" "€89" strike "€69" red | qty f1=1 | button b3 icon:trash
  button b5 "Checkout" primary

What it sends

goto https://shop.example/cart
click "Reject"
fill "Email" "ralph@example.com"
fill "Password" $secret:shop
click "Sign in"
expect url ~ /account
view interactive budget=800

What comes back

- d1
~ main -covered-by=d1

Only what changed. The dialog closed, so the main content is no longer covered.

Install

Claude Code
npx @noetive/riffle init --client claude-code
Cursor, Copilot, Kiro or Antigravity
npx @noetive/riffle init
Any MCP client
{
  "mcpServers": {
    "riffle": { "command": "npx", "args": ["-y", "@noetive/riffle", "mcp"] }
  }
}
Go
go install github.com/noetive/riffle/cmd/riffle@latest
Check Chrome is found
npx @noetive/riffle doctor

What you can do with it

  • Log in and finish a flow. Fill, click and check the result, in one call.
  • Read a page at a size you choose. Every view takes a token budget, so a long page costs what you decide.
  • Pull a table out of a page. The table view returns rows as TSV, whatever the markup.
  • See what the page calls. The net view lists the fetch and XHR requests behind it.
  • Test your own web app. Drive localhost the way a person would, with the page's own JavaScript running.
  • Know where a program stopped. A failed step names itself and the reason, such as a button covered by a dialog, so the next program can close the dialog first.

Safe by default

  • Secrets are written as $secret:name, tied to one origin, and never shown back to the agent.
  • Text a person couldn't see on the page is counted, and shown only when you ask, marked as page data.
  • A control whose hidden label contradicts the words on it is flagged.
  • Page text is quoted as data, so a page can't pass it off as your instructions.
  • Uploads and script evaluation are off until you turn them on.
  • riffle serve can limit which origins a session may visit and refuse private network addresses.

What it isn't

  • Not a screenshot tool. If the answer is only in the pixels, Riffle can't give it to you yet.
  • Not a way around bot protection or CAPTCHAs. It doesn't try.
  • Not a visual regression test framework. Use a tool built for that.
  • Chrome or Chromium only for now. Content inside iframes is reported as not shown rather than read.