← Back to archive

Repo of the Day

pinchtab/pinchtab: High-performance browser automation bridge and multi-instance orchestrator with advanced stealth injection and real-time dashboard.

Published: Aug 30, 2026

Open repository ↗

High-performance browser automation bridge and multi-instance orchestrator with advanced stealth injection and real-time dashboard. - pinchtab/pinchtab

Summary

PinchTab is a Go-based HTTP server that gives AI agents and scripts direct control over a locally installed Chrome through the Chrome DevTools Protocol, using a server, bridge, and attach process model. It exposes both a CLI and a REST API on http://localhost:9867, supports headless and headed modes, isolated browser profiles, and an element-ref system (e5-style) that survives filter and selector changes. The project is MIT-licensed, local-first by default, and ships as a single ~30 MB binary with ARM64 and Docker support.

What it is useful for

  • Driving a browser from agent tools (Claude, Cursor, Windsurf, Codex, OpenClaw, Grok) without the agent having to read raw HTML or screenshots. The README cites ~800 tokens per page with text extraction, compared to 5-13x more with screenshots, and publishes a benchmark showing 9.5-20.3% lower cost versus agent-browser on Haiku and Sonnet loops.
  • Running multiple isolated Chrome instances in parallel under one server, each with its own profile for cookies, history, and logins. Useful for QA grids, multi-account research, and separating automation identities.
  • Site audits and visual diffs in CI: pinchtab audit produces a report with screenshots, console errors, broken assets, accessibility score, and Core Web Vitals, and pinchtab compare can gate a release when two URLs differ.
  • Browsing sites that fingerprint stock Chromium, by pointing PinchTab at a user-supplied CloakBrowser binary (not bundled).
  • Deploying on Raspberry Pi or other ARM64 hosts; Chromium detection is built in.

The README is explicit about limits: Windows support is best-effort and the daemon workflow is not recommended there; PinchTab is not positioned as a turnkey internet-facing service; IDPI defaults to a local-only website allowlist; and attach is disabled by default. Exposing it beyond loopback is on the operator and requires handling tokens, TLS, and endpoint exposure.

How engineers can use it

Install via the documented install script, Homebrew, or npm:

curl -fsSL https://pinchtab.com/install.sh | bash
# or
brew install pinchtab/tap/pinchtab
# or
npm install -g pinchtab

Install the daemon once and point an agent at http://localhost:9867:

pinchtab daemon install

Basic CLI loop:

pinchtab nav https://pinchtab.com
pinchtab snap -i -c       # interactive element refs
pinchtab click e5
pinchtab fill e3 "[email protected]"

For programmatic control, the README documents creating a profile, starting an instance, opening a tab, and snapshotting via the HTTP API using a bearer token (PINCHTAB_TOKEN=$(pinchtab config token --stdout)). For audit and CI usage, see docs/audit.md in the repository. If Windows or remote exposure is required, the security guide at docs/guides/security.md is the starting point the project recommends.