Skip to main content

ricibrowser

A lightweight two-engine browser automation module built entirely on the Chrome DevTools Protocol (CDP). No Playwright, no Puppeteer, no selenium.

Engines

Engine Use case Technology
Lightpanda (fast path) crawl, recon, endpoint discovery, non-JS-heavy targets Zig-based headless engine, CDP at ws://127.0.0.1:9222
CDP-Chrome (thorough path) DAST, JS-heavy targets, auth flows, anti-bot Custom CDP client driving the user's real installed Chrome

Install

pip install ricibrowser

# For the fast path (optional):
bash scripts/install_lightpanda.sh
lightpanda serve --host 127.0.0.1 --port 9222

# For the thorough path:
# Just have Google Chrome installed on your system.

Quick start

Hybrid page snapshots

CDP-Chrome sessions can expose a bounded accessibility/DOM snapshot with stable references for the current page. Refresh the snapshot after navigation or DOM changes; references from an older snapshot are rejected.

snapshot = await session.accessibility_snapshot(interactive_only=True)
# Use snapshot["nodes"][0]["ref"] with session.act_reference(...)

The snapshot combines the CDP accessibility tree with DOM/ARIA enrichment, including roles, accessible names, disabled/checked state, and selectors where available.

JavaScript exception surfacing

Runtime.evaluate responses now carry CDP exceptionDetails through session.last_eval_error — a thrown expression returns None with the actual JS exception text instead of an unexplained null, so callers can distinguish "expression threw" from "returned undefined".

Trusted clicks and promise-aware evaluation

Session.click now dispatches a trusted CDP Input.dispatchMouseEvent at the element's center — React/Vue router buttons that ignore synthetic el.click() dispatches respond to these. A synthetic-click fallback remains for hidden or zero-size elements.

evaluate/evaluate_value now set awaitPromise, so expressions like fetch('/api').then(r => r.text()) resolve to the final body instead of an opaque {} — no store-then-read workaround needed.

Stealth diagnostics

ricibrowser.stealth_benchmark provides a defensive, local consistency benchmark for an operator-owned fixture page. It checks observable signals such as navigator.webdriver, user-agent/client-hint consistency, locale/timezone, WebGL, canvas/audio stability, plugins, CDP artifacts, and TLS consistency when the fixture supplies them. The score is a debugging heuristic, not a promise of invisibility or a vendor bot-detector result. It does not probe third-party anti-bot systems or attempt to evade them.

import asyncio
from ricibrowser import Engine, EngineConfig

async def main():
    engine = Engine(EngineConfig())

    # Fast path (Lightpanda) — crawl/recon
    page = await engine.fast_browse("https://example.com")
    print(f"Title: {page.title}")
    print(f"Text: {page.text[:200]}")
    print(f"Links: {len(page.links)}")

    # Thorough path (CDP-Chrome) — DAST/auth flows
    session = await engine.create_session()
    await session.navigate("https://example.com/login")
    await session.fill("#username", "admin")
    await session.fill("#password", "pass")
    await session.click("#login-btn")

    # Cookies persist across sessions via CookieJar
    await session.navigate("https://example.com/dashboard")  # authenticated!

    # JS evaluation in isolated world (never Runtime.enable on main world)
    count = await session.evaluate("document.querySelectorAll('script').length")

    # Network capture (opt-in, off by default)
    engine2 = Engine(EngineConfig(debug_network=True))
    session2 = await engine2.create_session()
    # ... browse ...
    flows = engine2.network.to_dict()

    await engine.close()

asyncio.run(main())

Stealth

  • navigator.webdriver suppressed via --disable-blink-features=AutomationControlled (Blink-level, not JS injection)
  • Uses the user's real installed Chrome (not bundled Chromium) — TLS/JA3 fingerprint matches a real Chrome release
  • Never calls Runtime.enable on the main world — isolated worlds only
  • Console.enable off by default — only enabled in explicit debug mode
  • Network.enable off by default — known CDP detection vector

Architecture

See ARCHITECTURE.md for the full design.

License

MIT

Release files for ricibrowser 0.2.23

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for ricibrowser 0.2.23
File Size Uploaded
ricibrowser-0.2.23.tar.gz 78.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for ricibrowser 0.2.23
File Interpreter ABI Platform
ricibrowser-0.2.23-py3-none-any.whl Python 3 none any Details

Total release size: 147.8 kB

Release files / ricibrowser-0.2.23.tar.gz

Download URL ricibrowser-0.2.23.tar.gz
Size 78.7 kB
Tags Source
SHA-256 checksum
How to use checksums
8111500de5fb21426ec13a03b6bc7778c715dd2f3c4ab4c5ab77f21f825ad6d4
BLAKE2b-256 checksum
How to use checksums
22d5c978b45d9e2a3731b2d32eecacd36cc26f43cebbaeb41198881708da6f7a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.3

Release files / ricibrowser-0.2.23-py3-none-any.whl

Download URL ricibrowser-0.2.23-py3-none-any.whl
Size 69.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
8fa78e685a6e98c5a37d9e696d3b6e2a8f5504ac1e1d30a530124c41e3136ae4
BLAKE2b-256 checksum
How to use checksums
1d4f44251cf6a3a3faf2f9df64cdf4f8eec83b0cedc3cda3bf6447fc25d8d237
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.3

Release history Release notifications | RSS feed

0.2.29

2 release files

0.2.28

2 release files

0.2.27

2 release files

0.2.26

2 release files

0.2.25

2 release files

This release

0.2.23 This release

2 release files

0.2.22

2 release files

0.2.21

2 release files

0.2.20

2 release files

0.2.19

2 release files

0.2.18

2 release files

0.2.12

2 release files

0.2.11

2 release files

0.2.10

2 release files

0.2.9

2 release files

0.2.8

1 release file

0.2.7

2 release files

0.2.6

2 release files

0.2.5

2 release files

0.2.4

2 release files

0.2.3

2 release files

0.2.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page