Skip to main content

ricibrowser

A lightweight two-engine browser automation module built entirely on the Chrome DevTools Protocol (CDP). No Playwright, no Puppeteer, no selenium.

Engines

Engine Use case Technology
Lightpanda (fast path) crawl, recon, endpoint discovery, non-JS-heavy targets Zig-based headless engine, CDP at ws://127.0.0.1:9222
CDP-Chrome (thorough path) DAST, JS-heavy targets, auth flows, anti-bot Custom CDP client driving the user's real installed Chrome

Install

pip install ricibrowser

# For the fast path (optional):
bash scripts/install_lightpanda.sh
lightpanda serve --host 127.0.0.1 --port 9222

# For the thorough path:
# Just have Google Chrome installed on your system.

Quick start

Hybrid page snapshots

CDP-Chrome sessions can expose a bounded accessibility/DOM snapshot with stable references for the current page. Refresh the snapshot after navigation or DOM changes; references from an older snapshot are rejected.

snapshot = await session.accessibility_snapshot(interactive_only=True)
# Use snapshot["nodes"][0]["ref"] with session.act_reference(...)

The snapshot combines the CDP accessibility tree with DOM/ARIA enrichment, including roles, accessible names, disabled/checked state, and selectors where available.

JavaScript exception surfacing

Runtime.evaluate responses now carry CDP exceptionDetails through session.last_eval_error — a thrown expression returns None with the actual JS exception text instead of an unexplained null, so callers can distinguish "expression threw" from "returned undefined".

Trusted clicks and promise-aware evaluation

Session.click now dispatches a trusted CDP Input.dispatchMouseEvent at the element's center — React/Vue router buttons that ignore synthetic el.click() dispatches respond to these. A synthetic-click fallback remains for hidden or zero-size elements.

evaluate/evaluate_value now set awaitPromise, so expressions like fetch('/api').then(r => r.text()) resolve to the final body instead of an opaque {} — no store-then-read workaround needed.

Stealth diagnostics

ricibrowser.stealth_benchmark provides a defensive, local consistency benchmark for an operator-owned fixture page. It checks observable signals such as navigator.webdriver, user-agent/client-hint consistency, locale/timezone, WebGL, canvas/audio stability, plugins, CDP artifacts, and TLS consistency when the fixture supplies them. The score is a debugging heuristic, not a promise of invisibility or a vendor bot-detector result. It does not probe third-party anti-bot systems or attempt to evade them.

import asyncio
from ricibrowser import Engine, EngineConfig

async def main():
    engine = Engine(EngineConfig())

    # Fast path (Lightpanda) — crawl/recon
    page = await engine.fast_browse("https://example.com")
    print(f"Title: {page.title}")
    print(f"Text: {page.text[:200]}")
    print(f"Links: {len(page.links)}")

    # Thorough path (CDP-Chrome) — DAST/auth flows
    session = await engine.create_session()
    await session.navigate("https://example.com/login")
    await session.fill("#username", "admin")
    await session.fill("#password", "pass")
    await session.click("#login-btn")

    # Cookies persist across sessions via CookieJar
    await session.navigate("https://example.com/dashboard")  # authenticated!

    # JS evaluation in isolated world (never Runtime.enable on main world)
    count = await session.evaluate("document.querySelectorAll('script').length")

    # Network capture (opt-in, off by default)
    engine2 = Engine(EngineConfig(debug_network=True))
    session2 = await engine2.create_session()
    # ... browse ...
    flows = engine2.network.to_dict()

    await engine.close()

asyncio.run(main())

Stealth

  • navigator.webdriver suppressed via --disable-blink-features=AutomationControlled (Blink-level, not JS injection)
  • Uses the user's real installed Chrome (not bundled Chromium) — TLS/JA3 fingerprint matches a real Chrome release
  • Never calls Runtime.enable on the main world — isolated worlds only
  • Console.enable off by default — only enabled in explicit debug mode
  • Network.enable off by default — known CDP detection vector

Architecture

See ARCHITECTURE.md for the full design.

License

MIT

Release files for ricibrowser 0.2.27

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for ricibrowser 0.2.27
File Size Uploaded
ricibrowser-0.2.27.tar.gz 96.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for ricibrowser 0.2.27
File Interpreter ABI Platform
ricibrowser-0.2.27-py3-none-any.whl Python 3 none any Details

Total release size: 175.5 kB

Release files / ricibrowser-0.2.27.tar.gz

Download URL ricibrowser-0.2.27.tar.gz
Size 96.1 kB
Tags Source
SHA-256 checksum
How to use checksums
68fe147f8f55dd43bdd1e20c5ac42212df36bee32736297400122007a1449095
BLAKE2b-256 checksum
How to use checksums
035e4eb95a591085babe7a9b49dbe3caf54c4a1be75a6789bffd681c1a8b1dc8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.3

Release files / ricibrowser-0.2.27-py3-none-any.whl

Download URL ricibrowser-0.2.27-py3-none-any.whl
Size 79.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
132538b64cc5a6f47046143200e73a09bef84f378de3d0065975b282a63fb9c1
BLAKE2b-256 checksum
How to use checksums
b15ec818b9559832bc1fb3e7710883012b24f1bedf72f15070a86d24c6406911
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.3

Release history Release notifications | RSS feed

0.2.29

2 release files

0.2.28

2 release files

This release

0.2.27 This release

2 release files

0.2.26

2 release files

0.2.25

2 release files

0.2.23

2 release files

0.2.22

2 release files

0.2.21

2 release files

0.2.20

2 release files

0.2.19

2 release files

0.2.18

2 release files

0.2.12

2 release files

0.2.11

2 release files

0.2.10

2 release files

0.2.9

2 release files

0.2.8

1 release file

0.2.7

2 release files

0.2.6

2 release files

0.2.5

2 release files

0.2.4

2 release files

0.2.3

2 release files

0.2.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page