Repository navigation
playwright mcp browser already in use
The message reads roughly:
Browser is already in use for /path/to/mcp-chrome, use --isolated to run
multiple instances of the same browser
It is a lock on a profile directory, not a statement about a running browser. A persistent profile can only be opened by one browser instance at a time, and Playwright MCP defaults to a single fixed profile directory. Anything that took that lock and did not give it back produces this, including a process that is no longer alive.
Microsoft's own documentation states the constraint directly: a persistent profile can only be used by one browser instance at a time, so concurrent MCP clients sharing the same workspace will conflict.
A second client. You have the server registered in two places - your editor and a terminal assistant, say - and both are alive. Both want the same profile. This is the case the error is actually written for, and it is most common in an editor: a browser MCP server in GitHub Copilot covers why.
A previous run that was killed. The session ended by something other than a clean close, so the lock file outlived the process. Nothing is running and the error still fires. This is the most common one and the most confusing, because your process list is empty.
A close that did not reset the server's own state. Reported repeatedly
against the upstream server: after browser_close, the internal "in use" flag
is not always cleared, so the next navigate fails with the same message even
though the browser is gone. Restarting the MCP server clears it.
An install that half-started a browser. browser_install can leave an
instance that holds the profile without being usable, which leaves the server's
idea of the state and the actual state disagreeing.
If you want concurrent clients, use --isolated. The profile lives in
memory for the session and nothing is shared, so two clients stop fighting. The
cost is that you start logged out every time, which for exploration is usually
what you wanted anyway.
If you want the profile, give each client its own. Choosing this
deliberately rather than by accident is the second of the four decisions in
Playwright MCP best practices.
--user-data-dir <path> with a different path per client. You keep persistence and lose the collision.
Note that this is a command-line option on the server, so if your client only
lets you register a command with no arguments, you may not be able to reach it
without editing the config block by hand.
If nothing is running, restart the server. In an editor or a chat client that means reloading the MCP connection, not just closing the tab. That clears the in-memory flag from the third case above; if the message persists after a genuine restart, the lock is on disk and the profile directory is the thing to look at.
Before deleting anything, check whether a browser really is alive. A stale lock and a live second client look identical in the error text and need opposite fixes. Deleting a lock that a running browser holds corrupts the profile.
invisible_playwright_mcp's server went the other way
entirely, and the history is worth the paragraph because it is the same trade
seen from both ends. Until 0.39.0 a session could hold up to eight browsers
under names you invented; until 0.41.0 every tool also carried a session
identifier, and one process juggled several sessions behind it. Both are gone:
a server serves exactly one identity for its whole life, with one helper
browser beside it that shares nothing, and browser_open chooses between those
two rather than adding to a pool.
The collision cannot happen the way it does above, because there is no pool to collide inside. What you give up is running several identities through one registered server: you register a second server instead. Neither shape is better in the abstract - Microsoft's puts the choice in a flag and ours puts it in how many servers you register.
Where the same class of problem does reach us is persistent profiles, because
the constraint is the browser's, not the server's - the same reason a
logged-in session has to be handled deliberately. One directory, one live
browser. If you point two sessions at the same profile_dir, the second one has
the same bad day.
Why does it say the browser is in use when nothing is running? Because the lock is on the profile directory and can survive the process that took it, and because the server keeps its own flag that a hard kill does not clear.
Does --isolated lose my logins? Yes. That is what isolated means. Use
--storage-state if you need a specific logged-in state without a shared
profile.
Can I run two MCP browser clients at once? Yes, with --isolated or with a
distinct --user-data-dir per client. Not on one shared persistent profile.
Is this a bug? Partly. The profile lock is a browser constraint and correct. The flag not resetting after a close is tracked upstream as a defect.
See also: Playwright MCP best practices for the settings worth choosing on purpose, Playwright MCP vs the CLI, and the MCP server for this project's session model.
-
microsoft/playwright-mcp, retrieved 2026-09-10, for
--isolated,--user-data-dir,--storage-stateand the documented one-instance-per-profile constraint. - Upstream issues describing the failure modes above, retrieved 2026-09-10: #942 (fails on first attempt), #891 (lock on the fixed profile), #1245 (state not released after close), #1294 and #1305.
Written while maintaining a competing MCP browser server. The section about our own design says what it costs, and the last paragraph of it says where we have the same problem.
- OpenAI Operator alternatives
- Open-source Operator-style agents
- Is OpenAI Operator still available?
- OpenAI Operator vs Claude computer use
- browser-use alternatives
- Choosing an AI browser agent
- Open-source AI browser agents
- Open-source computer-use agents
- What is an AI web agent?
- AI browser agents vs traditional scraping
- Cloud browser infrastructure for AI agents, explained
- Browserbase alternatives
- Firecrawl vs an AI browser agent
- Skyvern alternatives
- Stagehand vs browser-use
- Project Mariner is gone: what replaced it
- Manus alternatives
- Gemini computer use vs Claude computer use
- A stealth browser MCP, reviewed honestly by its own wiki
- AI browser vs AI browser agent: which one do you want?
- AI browser agent vs RPA: which one fits the job
- AI browser agent vs n8n, Zapier and Make
- Vercel agent-browser alternatives, compared honestly
- What is an agentic browser? Definition and the two kinds
- Open-source agentic browsers: the three layers, compared
- Choosing an MCP server for browser automation: four axes
- Stealth MCP servers compared: Camoufox, nodriver, Patchright
- Playwright MCP alternatives, and the three you don't need
- Autonomous browser agents: the four rungs of autonomy
- What is actually free in the AI browser agent stack
- browser-use on GitHub: what the repo actually gives you
- Playwright MCP vs Chrome DevTools MCP: different jobs
- How to choose among MCP servers: a map by category
- Which MCP servers are worth adding to Claude Code
- MCP on GitHub: finding servers and judging them fast
- MCP vs an API: the decision, and what the wrapper costs
- MCP alternatives: when the protocol is the wrong shape
- Why does my AI agent get blocked?
- The timing signal AI agents give off
- Agent retry loops trip rate limits, not fingerprints
- Claude computer use detected as a bot
- browser-use getting blocked: what you can and cannot change
- Playwright MCP session blocked: four causes, four fixes
- Playwright MCP and captchas: what actually gets you past
- Cloudflare and a browser MCP server: what is being read
- Can an AI agent solve a captcha? The honest answer
- Getting an AI agent to fill out forms
- The best model for an MCP browser agent, and what it really costs
- Browser problem or model problem?
- How to use a Playwright MCP server with Claude Code
- Extracting data to a CSV with an AI agent
- Monitoring a page for changes with an AI agent
- How to let Claude Desktop control a browser
- How to add a browser to Cursor as an MCP server
- Using an AI agent to hunt for apartments
- Getting website data into Google Sheets with an AI agent
- Using an AI agent to download invoices from portals
- AI agents for web research
- Using an AI agent to test your own website
- How to add a browser to Cline as an MCP server
- Posting to social media with an AI agent
- Posting to Facebook with an AI agent
- Posting to Instagram with an AI agent
- Posting to X with an AI agent
- Automating LinkedIn posts: read this first
- Appointment bots: what they are and what an agent can legitimately do
- Track prices across sites with an AI agent
- Build a lead list with an AI browser agent
- Run an AI browser agent on a schedule
- AI browser agent with a local LLM: what changes
- Should you log your AI agent into your accounts?
- How to write a task an AI browser agent can follow
- Move data between two web apps with an AI agent
- The MCP server
- How the tools are shaped, and why
- Playwright MCP vs the Playwright CLI: which fits when
- Playwright MCP: browser is already in use, and the fix
- Playwright MCP best practices: four decisions that matter
- Playwright MCP with a proxy, and the three leaks it leaves
- A browser MCP server in GitHub Copilot: setup and limits
- Using a browser MCP server for web scraping: the pattern
- Which LLM for browser automation: the four properties
- How to build a browser agent, and what to take instead
- Getting an AI agent to log into a website: three routes
- MCP tools, resources and prompts: who controls each
- How many MCP tools is too many? The context arithmetic
- How to build an MCP server: the decisions, not the scaffold
- Local or remote MCP server: what changes, and what does not
- Writing an MCP client in Python: the thirty-line version
- Self-hosted AI agent: what one actually costs to run
- How long an AI browser agent takes per step, measured
- Text, HTML, snapshot or screenshot: what the agent should read
- Giving an AI browser agent a stopping condition
- Keeping an AI browser agent out of destructive actions
- Why did the AI agent click the wrong thing
- When the page changes under the AI agent
- Running one AI agent task across a list of sites
- Seeing a page as it appears in another country
- Getting data out of a dashboard with no export button
- Two browsers in one session: main and support
- Finding the dead links on a site with an AI agent
- Filling a CRM record from a company's website
- One form submission per spreadsheet row, with an AI agent
- Dated screenshots of a page as evidence
- Checking order and delivery status with an AI agent
- Reading a PDF that opens inside the browser
- Summarising a long page or thread with an AI agent
- Collecting every image on a page with its caption
- Collecting event and course listings with an AI agent
- Cancelling a subscription with an AI agent
- What an AI agent can and cannot do inside an iframe
- Shadow DOM and an AI agent: you can click it, you cannot read it
- How to add a browser to Codex as an MCP server
- What a page snapshot costs, per control
- How to let Gemini CLI use a browser
- Native selects and the ones that only look like selects
- Clicking by selector or by coordinates
- How long the agent waits before it gives up
- What a second browser costs
- Uploading a file with an AI agent, and why this one cannot
- Watching the agent work, and when it is worth it
- When not to use an AI browser agent
- Agent or script: deciding once instead of every time
- Using the keyboard instead of the mouse
- Secrets in an agent task: where they end up
- What an agent run should log
- Deduplicating what an AI agent collects
- Normalising values across sites
- Validating an AI agent's output
- Reading a table with an AI agent
- Driving a site's own search and filters
- The task works headed and fails headless
- How to let the AdaL CLI use a browser