Skip to main content

ricibrowser

A lightweight two-engine browser automation module built entirely on the Chrome DevTools Protocol (CDP). No Playwright, no Puppeteer, no selenium.

Engines

Engine Use case Technology
Lightpanda (fast path) crawl, recon, endpoint discovery, non-JS-heavy targets Zig-based headless engine, CDP at ws://127.0.0.1:9222
CDP-Chrome (thorough path) DAST, JS-heavy targets, auth flows, anti-bot Custom CDP client driving the user's real installed Chrome

Install

pip install ricibrowser

# For the fast path (optional):
bash scripts/install_lightpanda.sh
lightpanda serve --host 127.0.0.1 --port 9222

# For the thorough path:
# Just have Google Chrome installed on your system.

Quick start

Hybrid page snapshots

CDP-Chrome sessions can expose a bounded accessibility/DOM snapshot with stable references for the current page. Refresh the snapshot after navigation or DOM changes; references from an older snapshot are rejected.

snapshot = await session.accessibility_snapshot(interactive_only=True)
# Use snapshot["nodes"][0]["ref"] with session.act_reference(...)

The snapshot combines the CDP accessibility tree with DOM/ARIA enrichment, including roles, accessible names, disabled/checked state, and selectors where available.

Trusted clicks and promise-aware evaluation

Session.click now dispatches a trusted CDP Input.dispatchMouseEvent at the element's center — React/Vue router buttons that ignore synthetic el.click() dispatches respond to these. A synthetic-click fallback remains for hidden or zero-size elements.

evaluate/evaluate_value now set awaitPromise, so expressions like fetch('/api').then(r => r.text()) resolve to the final body instead of an opaque {} — no store-then-read workaround needed.

Stealth diagnostics

ricibrowser.stealth_benchmark provides a defensive, local consistency benchmark for an operator-owned fixture page. It checks observable signals such as navigator.webdriver, user-agent/client-hint consistency, locale/timezone, WebGL, canvas/audio stability, plugins, CDP artifacts, and TLS consistency when the fixture supplies them. The score is a debugging heuristic, not a promise of invisibility or a vendor bot-detector result. It does not probe third-party anti-bot systems or attempt to evade them.

import asyncio
from ricibrowser import Engine, EngineConfig

async def main():
    engine = Engine(EngineConfig())

    # Fast path (Lightpanda) — crawl/recon
    page = await engine.fast_browse("https://example.com")
    print(f"Title: {page.title}")
    print(f"Text: {page.text[:200]}")
    print(f"Links: {len(page.links)}")

    # Thorough path (CDP-Chrome) — DAST/auth flows
    session = await engine.create_session()
    await session.navigate("https://example.com/login")
    await session.fill("#username", "admin")
    await session.fill("#password", "pass")
    await session.click("#login-btn")

    # Cookies persist across sessions via CookieJar
    await session.navigate("https://example.com/dashboard")  # authenticated!

    # JS evaluation in isolated world (never Runtime.enable on main world)
    count = await session.evaluate("document.querySelectorAll('script').length")

    # Network capture (opt-in, off by default)
    engine2 = Engine(EngineConfig(debug_network=True))
    session2 = await engine2.create_session()
    # ... browse ...
    flows = engine2.network.to_dict()

    await engine.close()

asyncio.run(main())

Stealth

  • navigator.webdriver suppressed via --disable-blink-features=AutomationControlled (Blink-level, not JS injection)
  • Uses the user's real installed Chrome (not bundled Chromium) — TLS/JA3 fingerprint matches a real Chrome release
  • Never calls Runtime.enable on the main world — isolated worlds only
  • Console.enable off by default — only enabled in explicit debug mode
  • Network.enable off by default — known CDP detection vector

Architecture

See ARCHITECTURE.md for the full design.

License

MIT

Release files for ricibrowser 0.2.21

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for ricibrowser 0.2.21
File Size Uploaded
ricibrowser-0.2.21.tar.gz 76.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for ricibrowser 0.2.21
File Interpreter ABI Platform
ricibrowser-0.2.21-py3-none-any.whl Python 3 none any Details

Total release size: 144.0 kB

Release files / ricibrowser-0.2.21.tar.gz

Download URL ricibrowser-0.2.21.tar.gz
Size 76.4 kB
Tags Source
SHA-256 checksum
How to use checksums
213847a403e56bc4215465f0ff5e97be3e08b0a64925379c8fff41ac8de0eaab
BLAKE2b-256 checksum
How to use checksums
b37a67d24c49a2ec3fdfd19873ce71ee25ada296c5df13da276ad80065708130
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.3

Release files / ricibrowser-0.2.21-py3-none-any.whl

Download URL ricibrowser-0.2.21-py3-none-any.whl
Size 67.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
ec7907e3bd91346541719a58a92a04842d2b27f77a76866c5d46803b72e155dd
BLAKE2b-256 checksum
How to use checksums
446fd19ddb87149d95f282143c305457fb02c38e2b78b459f70610909cacd5fa
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.3

Release history Release notifications | RSS feed

0.2.29

2 release files

0.2.28

2 release files

0.2.27

2 release files

0.2.26

2 release files

0.2.25

2 release files

0.2.23

2 release files

0.2.22

2 release files

This release

0.2.21 This release

2 release files

0.2.20

2 release files

0.2.19

2 release files

0.2.18

2 release files

0.2.12

2 release files

0.2.11

2 release files

0.2.10

2 release files

0.2.9

2 release files

0.2.8

1 release file

0.2.7

2 release files

0.2.6

2 release files

0.2.5

2 release files

0.2.4

2 release files

0.2.3

2 release files

0.2.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page