About
CorpGateway Chrome Extension + MCP Server
README
Chrome extension + MCP server for connecting AI agents to corporate systems via browser session. Capture endpoints from your real work, curate them into skills, and let the agent accumulate knowledge across sessions.
Installation Guide | Creating Custom Skills | Agent Knowledge Layer | Security

How It Works
┌──────────────────────────────────────────────────────────────┐
│ │
│ AI Agent (OpenCode, Cursor, Claude Code) │
│ │ │
│ │ POST /mcp (Bearer token) │
│ ▼ │
│ ┌──────────┐ WebSocket ┌───────────────────────┐ │
│ │ cgw_mcp │◄────────────────►│ Chrome Extension │ │
│ │ :9877 │ │ │ │
│ │ │ │ • chrome.cookies │ │
│ │ Tokens: │ │ • chrome.webRequest │ │
│ │ • agent │ │ • fetch() w/ session │ │
│ │ • ext │ │ • Skill management │ │
│ └──────────┘ └───────────┬───────────┘ │
│ │ │
│ │ fetch() + cookies/auth
│ ▼ │
│ Corporate APIs │
│ (Jira, Mattermost, ...) │
└──────────────────────────────────────────────────────────────┘
Key advantage: the extension reuses your existing browser session for authorization. No need to store passwords, API keys, or configure OAuth — if you're logged into a corporate system in Chrome, the extension automatically uses that session.
Components
| Component | Description | Location |
|---|---|---|
| Chrome Extension | Skill management, request execution via browser session | extension/ |
| cgw_mcp | MCP server (HTTP + WebSocket daemon), bridge between agent and extension | cgw_mcp/ |
| Presets | Ready-made skill sets for popular systems | presets/ |
Quick Start
1. Install the extension
- Open
chrome://extensions - Enable Developer mode
- Click Load unpacked → select the
extension/folder
2. Install and run cgw_mcp
cd cgw_mcp
npm install
As a daemon (autostart):
# Linux / macOS
./install.sh
# Windows (PowerShell)
.\install.ps1
Manually:
node index.js
On first run, a config file is created at ~/.corpgateway/cgw_mcp.json:
{
"port": 9877,
"token": "abc123...",
"extensionToken": "def456...",
"mcpInstructions": "..."
}
3. Connect the extension to cgw_mcp
- Extension icon → ⚙ Settings
- In the MCP Connection section:
- Instance name: anything (e.g. "Chrome Work")
- MCP server URL:
http://localhost:9877 - Extension token: copy
extensionTokenfrom~/.corpgateway/cgw_mcp.json
- Click Save
- In the extension popup, click ⚡ Connect
- The extension icon turns colored — connection established
4. Import skills
- Extension settings → Import
- Select a file from
presets/(e.g.jira.json) - Replace URL placeholders with your actual system addresses
5. Connect the AI agent

Add to your agent config (opencode.json, .cursor/mcp.json, etc.):
{
"mcp": {
"corp": {
"type": "remote",
"url": "http://localhost:9877/mcp",
"headers": {
"Authorization": "Bearer <token from cgw_mcp.json>"
}
}
}
}
MCP Tools
The agent receives the following meta-tools:
| Tool | Description | Parameters |
|---|---|---|
cgw_groups |
List available groups | — |
cgw_list |
List skills (all or by group); prepends the knowledge digest | group? |
cgw_schema |
Get parameter details for a skill (includes confirm flag) |
skill |
cgw_invoke |
Invoke a skill (for skills with confirm=false) |
skill, params? |
cgw_invoke_confirmed |
Invoke a skill that requires confirmation (native mode only) | skill, params? |
cgw_recall |
Search the knowledge base — facts, skill annotations, recipes | query?, kind?, tag?, limit? |
cgw_remember |
Persist a new knowledge note | kind, title, body, tags?, skillName? |
cgw_update_note |
Modify an existing note | id, plus any subset of fields |
cgw_forget |
Delete a note | id |
Agent workflow
1. cgw_list → sees org digest + skills grouped by purpose
2. cgw_recall(query=...) → drills into details not covered by the digest
3. cgw_schema(skill=jira_issue) → sees parameters + confirm flag + which invoke to use
4. cgw_invoke(skill=jira_issue, params={key:"PROJ-1"}) → result (confirm=false)
cgw_invoke_confirmed(skill=delete_issue, params={key:"PROJ-1"}) → result (confirm=true)
5. cgw_remember(...) → saves a fact / annotation / recipe for the next session
Skill Configuration
Detailed guide: Creating Custom Skills (Русский)

Via extension UI
Extension settings (chrome://extensions → CorpGateway → Details → Extension options):
- Sidebar tabs: Skills / Recordings / Knowledge
- Skills mode: groups in the sidebar, skill list in the center, edit form in the right panel
- Recordings mode: named captures of your real portal usage that can be promoted into skills (see SKILLS.md)
- Knowledge mode: the agent's long-running memory — digest + recallable notes (see KNOWLEDGE.md)
Skill structure
| Field | Description |
|---|---|
| Name | Function name for the agent (e.g. jira_issue) |
| Description | What the skill does (visible to agent) |
| URL | API endpoint with path parameters {id} |
| HTTP method | GET, POST, PUT, PATCH, DELETE |
| Origin URL | Where to execute the request from (if different from URL) |
| Body Template | JSON body template with {{param}} placeholders |
| Response Filter | Dot-notation paths for response filtering |
| HTTP headers | Custom headers (support {{param}}) |
| Parameters | Name, type (String/Integer/Float/Boolean/Date), required, description |
Parameter substitution
| Location | Format | Example |
|---|---|---|
| URL path | {param} |
/api/issues/{key} → /api/issues/PROJ-1 |
| Body | {{param}} |
{"text":"{{msg}}"} → {"text":"Hello"} |
| Headers | {{param}} |
X-Data: {{token}} → X-Data: abc123 |
| Query string | automatic | GET + remaining params → ?q=test&limit=10 |
Groups
Skills are organized into groups. Each group can be enabled/disabled — disabled groups and their skills are hidden from the agent.
Presets
Ready-made skill sets in presets/:
| File | System | Skills |
|---|---|---|
jira.json |
Jira REST API | issue, search, comments, transitions |
confluence.json |
Confluence REST API | pages, search, spaces |
gitlab.json |
GitLab API | projects, issues, merge requests |
mattermost.json |
Mattermost API | channels, posts, users, search |
outlook.json |
Microsoft Graph API | mail, calendar, contacts |
After import, replace URL placeholders (JIRA_URL, MATTERMOST_URL, etc.) with actual addresses.
Authorization
How the extension accesses APIs
- Cookies:
chrome.cookiesAPI — the extension has access to cookies for all permitted domains - Authorization headers:
chrome.webRequest.onSendHeaders— intercepts Authorization from all browser requests (Bearer tokens, JWT) - Fetch with credentials: requests are executed from the extension's Service Worker with
credentials: 'include'
You don't need to enter passwords or API keys. If you're logged into a corporate system in Chrome — the extension automatically uses that session.
Security
┌─────────────────────────────────────────────────────────┐
│ Layer 1: HTTP API (cgw_mcp) │
│ • Bearer token on every agent request │
│ • Timing-safe token comparison │
│ • Rate limiting: 10 attempts/min per IP │
│ • localhost only — not accessible from network │
│ • CORS restricted to localhost │
│ • JSON-RPC method whitelist │
│ • Message size limit (1 MB) │
│ │
│ Layer 2: WebSocket (cgw_mcp ↔ extension) │
│ • Extension token for authentication │
│ • Mutual auth: HMAC challenge-response │
│ • Both sides prove knowledge of extensionToken │
│ │
│ Layer 3: Chrome Extension │
│ • Sender validation — web pages cannot send │
│ commands to the extension │
│ • SSRF protection: private IP blocking, http(s) only │
│ • Template validation: JSON/HTTP injection protection │
│ • MCP connection — only via user button click │
│ • Notifications on auth session expiry │
│ │
│ Layer 4: Data │
│ • Credentials not stored — uses Chrome session │
│ • Tokens in cgw_mcp.json with 0600 permissions │
│ • Skills in chrome.storage.local (encrypted by Chrome) │
│ • Audit log: last 100 invocations in session storage │
│ • Tokens masked in logs │
│ • Confirmation modes: native (agent permissions) or OTP │
└─────────────────────────────────────────────────────────┘
Configuration
cgw_mcp.json
Location: ~/.corpgateway/cgw_mcp.json
{
"port": 9877,
"token": "agent-token",
"extensionToken": "extension-ws-token",
"mcpInstructions": "Instructions for the agent..."
}
| Field | Description |
|---|---|
port |
HTTP port for cgw_mcp (default 9877) |
token |
Bearer token for the agent |
extensionToken |
Token for WebSocket connection from extension |
mcpInstructions |
Instruction text sent to agent on MCP initialize |
Extension (Settings)
| Field | Description |
|---|---|
| Instance name | Identification when using multiple browsers |
| MCP server URL | HTTP address of cgw_mcp |
| Extension token | extensionToken from cgw_mcp.json |
Managing cgw_mcp
Install as daemon
Windows:
cd cgw_mcp
.\install.ps1 # install (Task Scheduler)
.\install.ps1 -Uninstall # remove
Linux:
cd cgw_mcp
./install.sh # install (systemd user service)
./install.sh uninstall # remove
systemctl --user status cgw-mcp
systemctl --user restart cgw-mcp
journalctl --user -u cgw-mcp -f
macOS:
cd cgw_mcp
./install.sh # install (LaunchAgent)
./install.sh uninstall # remove
launchctl list | grep cgw-mcp
tail -f ~/.corpgateway/logs/cgw_mcp_launchd.log
Logs
Location: ~/.corpgateway/logs/
Rotation: last 7 days are kept. Format:
[2026-04-01T10:30:15.123Z] INFO cgw_mcp started on http://localhost:9877
[2026-04-01T10:30:20.456Z] INFO Extension connected: "Chrome Work"
[2026-04-01T10:31:05.789Z] INFO → Agent request id=1 method=tools/call
API Reference
POST /mcp
MCP JSON-RPC endpoint (Streamable HTTP). Requires Authorization: Bearer <token>.
GET /mcp
SSE keep-alive (MCP spec). Requires Authorization: Bearer <token>.
GET /health
{
"status": "ok",
"extension": true,
"extensionName": "Chrome Work"
}
WS /extension/ws
WebSocket for the extension. Two-stage authentication:
- Connect with
?token=<extensionToken>&name=<instanceName> - Mutual auth (HMAC challenge-response) — both sides prove knowledge of
extensionToken
Multiple Browsers
If the extension is installed in multiple Chrome profiles:
- Each profile has its own extension instance with its own skills
- Only one can be connected to cgw_mcp at a time
- The last one to connect displaces the previous
GET /healthshows the name of the connected instance- Set different Instance names in settings for identification
File Structure
├── extension/ # Chrome Extension (Manifest V3)
│ ├── manifest.json # Permissions, service worker
│ ├── background.js # WS connection to cgw_mcp, auth capture
│ ├── popup.html/js # Connect button, groups
│ ├── options.html/js # Full skill editor (3-column UI)
│ ├── lib/
│ │ ├── storage.js # CRUD for skills/groups/recordings/knowledge
│ │ ├── executor.js # Skill execution (fetch + substitution)
│ │ ├── recorder.js # Traffic capture (filter, sanitize, persist)
│ │ └── mcp.js # MCP JSON-RPC handler (meta-tools)
│ ├── _locales/ # i18n (en, ru)
│ └── icons/ # Colored + gray icons
│
├── cgw_mcp/ # MCP Server (Node.js)
│ ├── index.js # HTTP + WebSocket server
│ ├── package.json
│ ├── install.sh # Daemon installer (Linux/macOS)
│ └── install.ps1 # Daemon installer (Windows)
│
├── presets/ # Ready-made skill sets
│ ├── jira.json
│ ├── confluence.json
│ ├── gitlab.json
│ ├── mattermost.json
│ └── outlook.json
│
├── docs/ # Documentation
│ ├── README.ru.md # README (Russian)
│ ├── SETUP.ru.md # Setup guide (Russian)
│ ├── SKILLS.ru.md # Creating custom skills (Russian)
│ ├── KNOWLEDGE.ru.md # Knowledge layer (Russian)
│ └── SECURITY.ru.md # Security architecture (Russian)
│
├── README.md # This file
├── SETUP.md # Installation guide
├── SKILLS.md # Creating custom skills
├── KNOWLEDGE.md # Agent knowledge layer
└── SECURITY.md # Security architecture
Installing Cgw
This server has no published package — it is built from source. Open the repository and follow its README.
▸ github.com/ivsergeev/cgwFAQ
Is Cgw MCP free?
Yes, Cgw MCP is free — one-click install via Unyly at no cost.
Does Cgw need an API key?
No, Cgw runs without API keys or environment variables.
Is Cgw hosted or self-hosted?
Self-hosted: the server runs locally on your machine via the install command above.
How do I install Cgw in Claude Desktop, Claude Code or Cursor?
Open Cgw on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.
Related MCPs
Playwright
Browser automation, scraping, screenshots
by MicrosoftPuppeteer
Browser automation and web scraping.
by modelcontextprotocolopentabs-dev/opentabs
Plugin-based MCP server + Chrome extension that gives AI agents access to web applications through the user's authenticated browser session. 100+ plugins with a
by opentabs-devrobhunter/agentdeals
1,500+ developer infrastructure deals, free tiers, and startup programs across 54 categories. Search deals, compare vendors, plan stacks, and track pricing chan
by robhunterCompare Cgw with
Not sure what to pick?
Find your stack in 60 seconds
Author?
Embed badge for your README
Browse similar
All browse MCPs
