CLI · bmc

From terminal to live feed in one command

أمر واحد. تصل حركة Chrome إلى الخلاصة الحية نفسها — دون شهادات للتثبيت.

A terminal window running "bmc start" that reports Chrome attached and capture live; the prompt line extends as a dashed stream into a mini dashboard card with green status codes. Two Chrome browser devices sit behind the terminal, and a BusyBro chat exchange with a confirm check fills its lower half. $ bmc start ✓ chrome attached · capture live live 200 201
التثبيت والالتقاط · macOS / Linux
bash
# macOS / Linux (self-updates from the dashboard):
curl -fsSL https://cdp.busymate.net/install.sh | bash

# Sign in once, create a browser, and capture it → your Busymate feed:
bmc login
bmc create dev --browser chrome --start
التثبيت والالتقاط · Windows
powershell
# Windows (PowerShell) — same, self-updating:
irm https://cdp.busymate.net/install.ps1 | iex

bmc login
bmc create dev --browser chrome --start

لماذا bmc

The simplest capture source

أسرع طريق من «افتح Chrome» إلى «افحص كل طلب» — وبإمكانه تشكيل تلك الحركة أيضًا.

صفر إعداد ثقة — حرفيًا

لأن bmc يتصل ببروتوكول DevTools، فالمرور مفكوك التشفير أصلًا. لا شيء يدخل سلسلة المفاتيح، ولا تحذيرات تظهر؛ يبدأ الالتقاط لحظة بدء Chrome.

أجهزة متصفح مسماة

يدير خفي في الخلفية ملفات Chrome مستقلة كأجهزة مسماة — شغّل وأوقف وبرمج كلاً منها من الطرفية أو لوحة التحكم أو نداء MCP. تصبح متصفحاتك أعضاء في الأسطول.

محاكاة وتعديل، محليًا

محرك JS المعزول نفسه الذي يشغّل الوكيل يعمل على جلسة Chrome الحقيقية: أعد كتابة الطلبات، وركّب الاستجابات، وراقب كل تغيير يظهر في التدفق بوضوح.

BusyBro في طرفيتك

محادثة REPL بتمرير أصلي تعرف أجهزة هذه الآلة. اطلب منها إنشاء متصفح أو فتح رابط أو تشغيل فحص — الإجراءات مقيدة بالتأكيد، والإجابات مستندة إلى التقاطك الفعلي.

لن تلمسه مجددًا

يحدّث الخفي نفسه عند الخمول، ويبلّغ عن إصداره الحي، ويعيد التشغيل عند الطلب من لوحة التحكم أو MCP. إنها بنية تحتية تصون نفسها.

How it works

Reads Chrome traffic after TLS

bmc attaches to Chrome over the DevTools Protocol — the same wire DevTools itself uses — so it sees requests exactly as the browser does: already decrypted.

مسار البيانات: ينتهي TLS داخل Chrome؛ يقرأ bmc أحداث DevTools Protocol المفكوكة التشفير ويبثّ الإدخالات إلى واجهة إدخال Busymate، لتصل إلى لوحة التحكم وMCP وتصدير HAR. chrome --remote-debugging ينتهي TLS هنا GET api.example.com 200 POST auth.example.com 201 GET cdn.example.com 304 ws:// Network.* مفكوك التشفير بالفعل bmc إدخالات + أجسام source: cdp POST /ingest dash.busymate.dev · بث مباشر mcp.busymate.dev · browser_* export_har · الإدخالات نفسها
  1. 01

    Its own Chrome, per folder

    bmc start launches a dedicated Chrome with its own profile and its own debug port for the current directory. Each folder is an independent device — run it in two folders and you get two fully separate browsers.

  2. 02

    Attach over the DevTools Protocol

    It connects to Chrome's debug port over a WebSocket, auto-attaches to every tab, and enables the Network domain — the same wire Chrome DevTools itself uses. No extension, no proxy in the path, nothing injected into pages.

  3. 03

    Events become entries

    Request, response and timing events are correlated into the same entry shape every Busymate source uses, with headers and bodies (up to 1 MB per body) pulled straight from the browser — after Chrome already decrypted them.

  4. 04

    Batched into one feed

    Entries are batched and posted to the ingest API about once a second. The folder pairs as a real Busymate device, so its traffic lands in the same dashboard, the same filters, the same MCP tools and the same HAR export as every phone.

No certificates

Capture without a root CA

TLS terminates inside Chrome, and bmc reads on the browser's side of it. There is no man-in-the-middle to trust — so there is nothing to install, and nothing for pinning to detect.

A proxy debugger decrypts HTTPS by re-signing it with its own certificate authority — which means installing that CA, trusting it in a keychain, and losing the apps that pin their certificates. bmc skips the whole problem: the DevTools Protocol hands over each request after Chrome has already decrypted it.

Capture paths compared: CDP, MITM proxy, on-device VPN
What it takesbmc (CDP)Proxy (MITM)iOS / Android app
Root CA to installNoneYes — trust the proxy CAYes — on-device CA, decrypting only domains you opt in
Network setupNonePoint each client at the proxyNone — an on-device VPN tunnel
Pinned certificatesUnaffected — nothing sits in the TLS pathPinned apps refuse the proxy CAPinned apps stay encrypted (metadata still visible)
What it seesThe Chrome it launches — every tabAny app or script you point at itEvery app on the phone
Best forWeb apps, SPAs, agent-driven browsingBackends, scripts, browsers on other machinesMobile apps, in the field

Each path is first-class: the proxy and the phone apps exist precisely for the traffic CDP can't see. Use bmc for browsers, the proxy for anything you can point at it, and the apps for whole-phone capture.

Browser automation

Drive the browser. See every request.

Every bmc browser is remote-controllable over MCP — an AI agent or a script can open pages, read them and act, while capture records every request the session makes. That combination is the point.

Drive and read the page

browser_open
Navigate the browser to a URL.
browser_targets
List the open tabs and pick the one to drive.
browser_snapshot
A compact accessibility-tree snapshot — the page as structured text, built for agents.
browser_screenshot
A PNG of the active page.
browser_eval
Run JavaScript in the page. Placeholder variables are resolved server-side from the device's env, so an agent can fill a login form without ever seeing the password.
browser_cdp
Raw DevTools Protocol access for everything else — owner-gated.

Browser profiles

Built-in Chrome, Brave and Edge profiles plus custom ones authored once in the dashboard — per-OS binaries, default flags and a flag catalog every machine's bmc resolves the same way.

  • list_browser_profiles
  • get_browser_profile
  • upsert_browser_profile
  • delete_browser_profile

The daemon, remotely

Live build, uptime and logs without SSH; list every named browser on a machine; restart or hot-update the daemon while running captures keep capturing. One switch arms or disarms it all, per device.

  • get_cdp_daemon_status
  • get_cdp_logs
  • list_cdp_instances
  • restart_cdp_daemon
  • update_cdp_daemon
  • set_device_cdp_control

Remote control is opt-in per device and permission-gated; capture keeps flowing either way.

GodBrowser

هوية جهاز متماسكة، كل طلب مُلتقَط

GodBrowser هو Chromium مضاد للبصمة يمنح المتصفح هوية جهاز متماسكة تبدو حقيقية. إنه ملف تعريف متصفح مدمج في bmc — لذا يمكن لوكيل تشغيل شخصية والتقاط حركتها في البثّ المباشر نفسه الذي تستخدمه هواتفك.

اختر GodBrowser بعلامة واحدة، ويقوده bmc عبر DevTools Protocol نفسه المستخدَم مع أي جهاز متصفح آخر: يفحص كل طلب تُصدره الشخصية — مفكوك التشفير بالفعل، دون CA جذري ودون وكيل — ويبثّها إلى بثّ Busymate الخاص بك. ويقدّم GodBrowser أداة bmc بوصفها رفيقه لفحص الطلبات لهذا الاقتران بالتحديد.

هوية واحدة، متماسكة بالكامل

وكيل المستخدم والشاشة وWebGL وcanvas والصوت واللغة المحلية والمنطقة الزمنية كلها تتوافق مع الشخصية — وتتماشى TLS/JA4 وUA-CH والكوديكات مع الجهاز المُعلَن قبل تشغيل سطر واحد من JavaScript. وبتعبير GodBrowser نفسه: جهاز حقيقي، لا جهاز متنكّر.

بذور حتمية

تشتقّ راية --bot-profile هوية جهاز كاملة من سلسلة بذرة. غيّر البذرة يتغيّر الجهاز — قابل للتكرار وإعادة الإنتاج، فتُعاد الشخصية تمامًا كما هي.

شخصيات عبر المنصّات والمتصفّحات

ويندوز وmacOS ولينكس وiOS وأندرويد متقاطعة مع Chrome وSafari وFirefox وSamsung Internet وEdge، تُختار عبر --bot-os و--bot-browser. وأساسها Chromium 151 مُعدَّل.

العنقود وواجهة API وMCP

يعمل GodBrowser عبر عنقود العُقد الخاص بك، مُدارًا من الكود أو من واجهة API الخاصة به أو من عميل ذكاء اصطناعي — ويأتي بخادم MCP بعيد خاص به. تُخصَّص الوكلاء لكل ملف تعريف بشكل حتمي؛ وتتزامن الجلسات بين الأجهزة عبر Redis.

شغّل شخصية والتقط حركتها
bash
# GodBrowser is a built-in bmc browser profile — pick it per device:
bmc create ios-persona --browser godbrowser -- \
  --bot-os=ios --bot-browser=safari --bot-profile=seed-42 --start

GodBrowser هو أحد ملفات تعريف bmc المدمجة، إلى جانب Chrome وBrave وEdge — واختياره عبر --browser godbrowser هو كامل الإعداد. يحلّ bmc الملف الثنائي، ويكشف علامات الشخصية الخاصة به، ويقرن الجهاز بوصفه “God Browser” مميّزًا، ويضع على حركته الملتقطة وسم gdp ليبرز في البثّ. لا يُحقَن أي شيء في GodBrowser: يقوده bmc عبر DevTools Protocol، وتقع طبقته المضادّة للبصمة في نواة المتصفّح، فتبقى سليمة أثناء الأتمتة. كلتا الأداتين أصليّتان لـ MCP — خادم MCP البعيد لـ GodBrowser وخادم Busymate يتيحان لوكيل واحد قيادة الشخصيات وقراءة حركتها في جلسة واحدة، كلٌّ خلف رمز خاص به قائم على الموافقة.

What people build

One tool, four jobs

Agent-driven QA

An assistant opens your staging site, walks the flow and screenshots what it sees — while the network feed shows exactly what broke, with full request and response bodies.

Debug a SPA

Watch XHR and fetch calls stream live with headers, bodies and timings while you click through the app. The history survives a reload — no DevTools-tab archaeology.

Capture an OAuth flow

Redirect chains, tokens and callbacks recorded end to end — including on providers whose pinned certificates a proxy can't open.

Work a signed-in page

The folder's Chrome profile keeps its session between runs; snapshot and eval read the page while capture documents every request behind it.

FAQ

The sceptical questions

Does bmc need a certificate or a proxy?

No. It attaches to Chrome over the DevTools Protocol and reads traffic after Chrome has decrypted it. There is no root CA to install, no keychain trust prompt, and no proxy settings to change.

Does it work with certificate pinning and HSTS?

Yes. Pinning defends the TLS connection between Chrome and the server — bmc never touches that connection; it reads inside the browser. HSTS, corporate device policy and managed keychains are equally unaffected.

Does it modify pages or the sites I visit?

Capture injects nothing — bmc listens to Chrome's own network events. It also launches its own Chrome with its own profile, so your everyday browser is never touched.

Can it run headless or in CI?

Yes. Anything after -- goes straight to Chrome (for example --headless=new), and CDP_USER_JWT or CDP_PAIR_EMAIL and CDP_PAIR_PASSWORD sign in without opening a browser.

Which browsers does it support?

Chromium-family browsers: built-in Chrome, Brave, Edge and Chromium profiles, plus custom profiles you author in the dashboard. Anything that speaks the DevTools Protocol.

What about traffic outside the browser?

bmc only sees the Chrome it is attached to. For backends and scripts use the Busymate proxy; for whole-phone capture use the iOS or Android app — everything lands in the same feed.

Start capturing Chrome

ثبّت bmc وسجّل الدخول مرة واحدة، فتصل حركة Chrome إلى الخلاصة الحية نفسها.

Ask your mate