From terminal to live feed
Tek komut. Chrome trafiği aynı canlı akışa düşer — kurulacak sertifika yok.
# macOS / Linux (self-updates from the dashboard):
curl -fsSL https://cdp.busymate.net/install.sh | bash
# Sign in once, create a browser, and capture it → your Busymate feed:
bmc login
bmc create dev --browser chrome --start# Windows (PowerShell) — same, self-updating:
irm https://cdp.busymate.net/install.ps1 | iex
bmc login
bmc create dev --browser chrome --startThe simplest
"Chrome'u aç"tan "her isteği incele"ye en hızlı yol — üstelik o trafiği şekillendirebilir de.
Sıfır güven kurulumu — kelimenin tam anlamıyla
bmc, DevTools Protocol’e bağlandığı için trafik zaten şifresi çözülmüş hâldedir. Anahtar zincirine hiçbir şey girmez, hiçbir uyarı çıkmaz; yakalama, Chrome açıldığı anda başlar.
Adlandırılmış tarayıcı cihazları
Arka planda çalışan bir daemon, bağımsız Chrome profillerini adlandırılmış cihazlar olarak yönetir — her birini terminalden, dashboard’dan veya bir MCP çağrısıyla başlatın, durdurun, betikleyin. Tarayıcılarınız filo üyesi olur.
Yerelde mock’layın ve dönüştürün
Proxy’yi çalıştıran aynı sandbox JS motoru gerçek Chrome oturumunuzda çalışır: istekleri yeniden yazın, yanıtları sentezleyin ve her değişikliğin akışa görünür şekilde düştüğünü izleyin.
Terminalinizde BusyBro
Bu makinenin cihazlarını bilen, doğal scrollback’li bir REPL sohbeti. Ondan bir tarayıcı oluşturmasını, bir URL açmasını, bir kontrol çalıştırmasını isteyin — eylemler onay gerektirir, yanıtlar gerçek yakalamanıza dayanır.
Bir daha elinizi sürmeyin
Daemon boştayken kendini günceller, canlı build’ini raporlar ve dashboard’dan veya MCP’den istek gelince yeniden başlar. Kendi kendine bakan bir altyapıdır.
Reads Chrome traffic
bmc attaches to Chrome over the DevTools Protocol — the same wire DevTools itself uses — so it sees requests exactly as the browser does: already decrypted.
- 01
Its own Chrome, per folder
bmc start launches a dedicated Chrome with its own profile and its own debug port for the current directory. Each folder is an independent device — run it in two folders and you get two fully separate browsers.
- 02
Attach over the DevTools Protocol
It connects to Chrome's debug port over a WebSocket, auto-attaches to every tab, and enables the Network domain — the same wire Chrome DevTools itself uses. No extension, no proxy in the path, nothing injected into pages.
- 03
Events become entries
Request, response and timing events are correlated into the same entry shape every Busymate source uses, with headers and bodies (up to 1 MB per body) pulled straight from the browser — after Chrome already decrypted them.
- 04
Batched into one feed
Entries are batched and posted to the ingest API about once a second. The folder pairs as a real Busymate device, so its traffic lands in the same dashboard, the same filters, the same MCP tools and the same HAR export as every phone.
Capture without
TLS terminates inside Chrome, and bmc reads on the browser's side of it. There is no man-in-the-middle to trust — so there is nothing to install, and nothing for pinning to detect.
A proxy debugger decrypts HTTPS by re-signing it with its own certificate authority — which means installing that CA, trusting it in a keychain, and losing the apps that pin their certificates. bmc skips the whole problem: the DevTools Protocol hands over each request after Chrome has already decrypted it.
| What it takes | bmc (CDP) | Proxy (MITM) | iOS / Android app |
|---|---|---|---|
| Root CA to install | None | Yes — trust the proxy CA | Yes — on-device CA, decrypting only domains you opt in |
| Network setup | None | Point each client at the proxy | None — an on-device VPN tunnel |
| Pinned certificates | Unaffected — nothing sits in the TLS path | Pinned apps refuse the proxy CA | Pinned apps stay encrypted (metadata still visible) |
| What it sees | The Chrome it launches — every tab | Any app or script you point at it | Every app on the phone |
| Best for | Web apps, SPAs, agent-driven browsing | Backends, scripts, browsers on other machines | Mobile apps, in the field |
Each path is first-class: the proxy and the phone apps exist precisely for the traffic CDP can't see. Use bmc for browsers, the proxy for anything you can point at it, and the apps for whole-phone capture.
Drive the browser.
Every bmc browser is remote-controllable over MCP — an AI agent or a script can open pages, read them and act, while capture records every request the session makes. That combination is the point.
Drive and read the page
- browser_open
- Navigate the browser to a URL.
- browser_targets
- List the open tabs and pick the one to drive.
- browser_snapshot
- A compact accessibility-tree snapshot — the page as structured text, built for agents.
- browser_screenshot
- A PNG of the active page.
- browser_eval
- Run JavaScript in the page. Placeholder variables are resolved server-side from the device's env, so an agent can fill a login form without ever seeing the password.
- browser_cdp
- Raw DevTools Protocol access for everything else — owner-gated.
Browser profiles
Built-in Chrome, Brave and Edge profiles plus custom ones authored once in the dashboard — per-OS binaries, default flags and a flag catalog every machine's bmc resolves the same way.
- list_browser_profiles
- get_browser_profile
- upsert_browser_profile
- delete_browser_profile
The daemon, remotely
Live build, uptime and logs without SSH; list every named browser on a machine; restart or hot-update the daemon while running captures keep capturing. One switch arms or disarms it all, per device.
- get_cdp_daemon_status
- get_cdp_logs
- list_cdp_instances
- restart_cdp_daemon
- update_cdp_daemon
- set_device_cdp_control
Remote control is opt-in per device and permission-gated; capture keeps flowing either way.
Tutarlı bir cihaz kimliği,
GodBrowser, bir tarayıcıya tutarlı ve gerçekçi görünen bir cihaz kimliği veren anti-fingerprint bir Chromium'dur. bmc'ye gömülü bir tarayıcı profilidir — böylece bir ajan bir persona çalıştırıp trafiğini telefonlarınızla aynı canlı akışta yakalayabilir.
GodBrowser'ı tek bir bayrakla seçin; bmc onu, herhangi bir tarayıcı cihazıyla aynı DevTools Protocol üzerinden yönetir: personanın yaptığı her isteği inceler — şifresi çözülmüş halde, kök CA yok, proxy yok — ve bunları Busymate akışınıza aktarır. GodBrowser, bmc'yi tam da bu eşleştirme için istek inceleme yoldaşı olarak tanıtır.
Tek parça bir kimlik
User-agent, ekran, WebGL, canvas ve ses, yerel ayar ve saat dilimi — hepsi personayla uyumludur; TLS/JA4, UA-CH ve kodekler ise tek satır JavaScript çalışmadan önce iddia edilen cihaza hizalanır. GodBrowser'ın kendi ifadesiyle: gerçek bir cihaz, kılık değiştirmiş değil.
Deterministik tohumlar
--bot-profile bayrağı, bir tohum dizesinden bütün bir cihaz kimliği türetir. Tohumu değiştir, cihazı değiştir — tekrarlanabilir ve yeniden üretilebilir, böylece bir persona birebir aynı şekilde yeniden oynatılır.
Platform ve tarayıcı genelinde personalar
Windows, macOS, Linux, iOS ve Android; Chrome, Safari, Firefox, Samsung Internet ve Edge ile çaprazlanır ve --bot-os ile --bot-browser üzerinden seçilir. Temeli yamalı bir Chromium 151'dir.
Küme, API ve MCP
GodBrowser kendi düğüm kümenizde çalışır; koddan, kendi API'sinden veya bir yapay zekâ istemcisinden yönetilir — ve kendi uzak MCP sunucusunu sunar. Proxy'ler profil başına deterministik atanır; oturumlar makineler arasında Redis üzerinden senkronize olur.
# GodBrowser is a built-in bmc browser profile — pick it per device:
bmc create ios-persona --browser godbrowser -- \
--bot-os=ios --bot-browser=safari --bot-profile=seed-42 --startGodBrowser, Chrome, Brave ve Edge'in yanında bmc'nin yerleşik profillerinden biridir — onu --browser godbrowser ile seçmek kurulumun tamamıdır. bmc ikili dosyayı çözer, persona bayraklarını sunar, cihazı ayrı bir “God Browser” olarak eşler ve yakalanan trafiği akışta öne çıkması için gdp olarak etiketler. GodBrowser'a hiçbir şey enjekte edilmez: bmc onu DevTools Protocol üzerinden yönetir ve anti-fingerprint katmanı tarayıcı çekirdeğinde bulunur, dolayısıyla otomasyon altında bozulmadan kalır. Her iki araç da MCP yerlisidir — GodBrowser'ın uzak MCP sunucusu ve Busymate'inki sayesinde tek bir ajan, her biri kendi onaya dayalı jetonunun arkasında olacak şekilde, tek bir oturumda personaları yönetip trafiklerini okuyabilir.
One tool,
Agent-driven QA
An assistant opens your staging site, walks the flow and screenshots what it sees — while the network feed shows exactly what broke, with full request and response bodies.
Debug a SPA
Watch XHR and fetch calls stream live with headers, bodies and timings while you click through the app. The history survives a reload — no DevTools-tab archaeology.
Capture an OAuth flow
Redirect chains, tokens and callbacks recorded end to end — including on providers whose pinned certificates a proxy can't open.
Work a signed-in page
The folder's Chrome profile keeps its session between runs; snapshot and eval read the page while capture documents every request behind it.
The sceptical
Does bmc need a certificate or a proxy?
No. It attaches to Chrome over the DevTools Protocol and reads traffic after Chrome has decrypted it. There is no root CA to install, no keychain trust prompt, and no proxy settings to change.
Does it work with certificate pinning and HSTS?
Yes. Pinning defends the TLS connection between Chrome and the server — bmc never touches that connection; it reads inside the browser. HSTS, corporate device policy and managed keychains are equally unaffected.
Does it modify pages or the sites I visit?
Capture injects nothing — bmc listens to Chrome's own network events. It also launches its own Chrome with its own profile, so your everyday browser is never touched.
Can it run headless or in CI?
Yes. Anything after -- goes straight to Chrome (for example --headless=new), and CDP_USER_JWT or CDP_PAIR_EMAIL and CDP_PAIR_PASSWORD sign in without opening a browser.
Which browsers does it support?
Chromium-family browsers: built-in Chrome, Brave, Edge and Chromium profiles, plus custom profiles you author in the dashboard. Anything that speaks the DevTools Protocol.
What about traffic outside the browser?
bmc only sees the Chrome it is attached to. For backends and scripts use the Busymate proxy; for whole-phone capture use the iOS or Android app — everything lands in the same feed.
Start capturing
bmc'yi kurun, bir kez oturum açın; Chrome trafiği aynı canlı akışa düşer.