Deck Help Center

Let AI agents drive LoginDeck (MCP)

Give Claude Desktop, Claude Code, Cursor or another MCP host a set of tools that open your profiles and run your Flows.

Updated Β· 5 min read

On this page

LoginDeck ships an MCP server: a small program an AI agent can talk to. Once it is connected, the agent gets 19 tools β€” list profiles, open one, run a Flow, read the result β€” and every browser it opens is a real LoginDeck session with that profile's fingerprint, proxy and cookies. It is the identity isolation that agentic browsing otherwise lacks.

Part of Pro, Team and Custom.

βœ… Before you start#

  1. Turn the local API on and leave it on: Settings β†’ API & MCP β†’ Serve the API on this machine. The MCP server is a thin wrapper around it, so with the API off every tool just says so. See Get started with the local API.
  2. Have Node 18 or newer installed on this computer. The MCP server runs under node and has no other dependencies.

🀝 Connect your agent#

  1. Go to Settings β†’ API & MCP.
  2. In the Connect panel, click the AI agent (MCP) tab. The block shown is already filled in with this install's path to the server and your token.
  3. Click Copy, paste it into your agent's config, and restart the agent.

The shape of it:

{
  "mcpServers": {
    "antiorbit": {
      "command": "node",
      "args": ["<the path the app prints>"],
      "env": {
        "ANTIORBIT_TOKEN": "your token"
      }
    }
  }
}
HostWhere the config goes
Claude Desktopclaude_desktop_config.json
Cursor~/.cursor/mcp.json
Claude Codeone command: claude mcp add antiorbit -e ANTIORBIT_TOKEN=… -- node <path>
OpenClaw, and other MCP hostswherever that host keeps its MCP servers

Copy the path from the app rather than typing one: in an installed copy the server lives inside the application's own files, and the app knows where. If you changed the port, the snippet adds ANTIORBIT_API_URL for you.

That config file now holds a key to your logged-in profiles

Treat it like any other credential file: not in a repository, not in a shared folder, not in a screenshot. Regenerate the token in Settings if it leaks, then paste the new one into the config.

🧰 What the agent can do#

ToolWhat it does
antiorbit_statusIs the app reachable: engine, profile count, how many browsers are running
antiorbit_list_profilesEvery profile, optionally filtered to one tag
antiorbit_list_proxiesThe saved proxy library, masked
antiorbit_create_profileCreate 1–100 fresh profiles, each with its own fingerprint; honours your plan's limit
antiorbit_start_browserOpen a profile and return its DevTools endpoint
antiorbit_stop_browserStop a running profile
antiorbit_list_runningEvery running session and its endpoint β€” how an agent reattaches
antiorbit_get_activeOne profile's session, or a note that it is not running
antiorbit_list_flowsYour Flows, and the inputs each one asks for
antiorbit_get_flowOne Flow in detail, including its ordered steps
antiorbit_run_flowRun a Flow on one profile; waits for the outcome by default
antiorbit_run_statusThe state of a run, finished ones included
antiorbit_stop_runStop a run
antiorbit_run_flow_manyRun a Flow across many profiles, by ids, names or tag
antiorbit_batch_statusHow a batch is going, per profile
antiorbit_stop_batchStop a batch
antiorbit_flow_historyRecent runs: outcome, steps, error, the page it stopped on
antiorbit_list_flow_templatesThe bundled template gallery
antiorbit_use_flow_templateCopy a template into your library, ready to run

The tool names still say antiorbit β€” that was LoginDeck's working name, and renaming them would break every config already out there.

πŸ’¬ What that looks like in practice#

Things people ask an agent to do once this is connected:

  • "List my profiles tagged warmup, then run the Warm up flow on all of them, three at a time."
  • "Open the profile called Shop 2 and tell me where it exits."
  • "Add the YouTube info template, run it on these five profiles and give me the titles."
  • "That run failed β€” read the log and tell me which step broke."

The agent can also drive the browser itself: antiorbit_start_browser returns a DevTools endpoint, which an agent that writes code can hand to Playwright exactly as your own script would. See Connect Playwright, Puppeteer or Selenium.

🧯 Limits worth telling your agent about#

  • Runs started this way never stop to ask a question. There is no stuck card for an agent; a failure comes back as a failure, with the log, the step and the page title. See When a Flow gets stuck.
  • Saved logins never come back. The variables a run returns leave out the profile's accounts, and a generated persona's password is masked.
  • A Flow can still sign in for the agent without the agent ever seeing the password, because Human type reads ${account.password} itself, on that account's own site only: Saved logins and 2FA codes.
  • Chromium profiles only. Firefox profiles cannot be automated yet.
  • Creating profiles counts against your plan, the same as clicking + New Profile.
  • Headless is allowed and discouraged β€” the tool descriptions say so, and an agent that reads them will prefer a window.

πŸ›Ÿ If the tools do not appear#

SymptomFix
The agent lists no LoginDeck toolsRestart the agent after editing its config. Most MCP hosts only read it at startup.
ANTIORBIT_TOKEN is not setThe env block is missing or misspelt. Re-copy the snippet from Settings β†’ API & MCP.
Every tool reports a connection errorThe API switch is off, LoginDeck is not running, or the port changed. Check Settings β†’ API & MCP shows listening on {port}.
401 from every toolThe token was regenerated. Paste the new one into the config.
node not foundInstall Node, or give the full path to it as command.

ℹ️ Good to know#

  • The MCP server does nothing on its own: it translates tool calls into requests to the local API, so there is one place that opens a browser and one security model to reason about.
  • It talks to 127.0.0.1 only, and the same token rules apply as to the API.
  • An agent can see your profile names, tags, notes and proxy hosts. Do not put anything in a profile note that you would not want an agent β€” or its provider β€” to read.
  • Flows are the safer surface to hand an agent: you decide what the steps are, and the agent only chooses when to run them and on which profiles.