A browser your agent can read
Riffle is an open-source MCP server and CLI that lets your agent use real websites without screenshots. Several steps per call. Only what changed comes back.
Your browser agent spends a turn and an image on every click. Or it re-reads the whole page after every action, and still can't tell that the Checkout button is behind a cookie dialog, that the price is struck through, or that a field is disabled.
Riffle gives your agent what the page means. Hidden, covered, primary, disabled, struck through, truncated: these are facts on the page outline, so your agent reads them instead of guessing from pixels.
What your agent reads
modal d1 "Cookie preferences" covers=page
button b1 "Accept all" primary
button b2 "Reject"
main covered-by=d1
h1 "Your cart"
item "Trail shoe 42" "€89" strike "€69" red | qty f1=1 | button b3 icon:trash
button b5 "Checkout" primary
What it sends
goto https://shop.example/cart
click "Reject"
fill "Email" "ralph@example.com"
fill "Password" $secret:shop
click "Sign in"
expect url ~ /account
view interactive budget=800
What comes back
- d1
~ main -covered-by=d1
Only what changed. The dialog closed, so the main content is no longer covered.
Install
npx @noetive/riffle init --client claude-code
npx @noetive/riffle init
{
"mcpServers": {
"riffle": { "command": "npx", "args": ["-y", "@noetive/riffle", "mcp"] }
}
}
go install github.com/noetive/riffle/cmd/riffle@latest
npx @noetive/riffle doctor
What you can do with it
- Log in and finish a flow. Fill, click and check the result, in one call.
- Read a page at a size you choose. Every view takes a token budget, so a long page costs what you decide.
- Pull a table out of a page. The table view returns rows as TSV, whatever the markup.
- See what the page calls. The net view lists the fetch and XHR requests behind it.
- Test your own web app. Drive localhost the way a person would, with the page's own JavaScript running.
- Know where a program stopped. A failed step names itself and the reason, such as a button covered by a dialog, so the next program can close the dialog first.
Safe by default
- Secrets are written as $secret:name, tied to one origin, and never shown back to the agent.
- Text a person couldn't see on the page is counted, and shown only when you ask, marked as page data.
- A control whose hidden label contradicts the words on it is flagged.
- Page text is quoted as data, so a page can't pass it off as your instructions.
- Uploads and script evaluation are off until you turn them on.
- riffle serve can limit which origins a session may visit and refuse private network addresses.
What it isn't
- Not a screenshot tool. If the answer is only in the pixels, Riffle can't give it to you yet.
- Not a way around bot protection or CAPTCHAs. It doesn't try.
- Not a visual regression test framework. Use a tool built for that.
- Chrome or Chromium only for now. Content inside iframes is reported as not shown rather than read.
Works with the rest of Noetive
Riffle runs on its own. It also pairs with: