Drive Kernel cloud browsers, and hold the automation runs for approval
Connect Kernel MCP and Luumen can work with your Kernel cloud-browser infrastructure from the terminal. It reads connection context, searches Kernel's documentation, and checks what the server can do before acting. Running Playwright code, shell commands, or HTTP requests inside a session is a change, so those steps are previewed and held for approval by default. Luumen signs in through OAuth with dynamic client registration.
25 tools: 3 read, 22 write. Reads answer instantly. Writes require approval by default. Everything is logged.
What a governed Kernel MCP run looks like inside Luumen.
Authorize once with OAuth 2.0. Luumen lists the scopes each action needs before you approve the connection, and credentials never appear in the chat.
Read actions answer immediately. Anything that writes — browser curl, computer action, exec command, execute playwright code, and more — is shown as a plan and requires approval by default, including the 19 actions classified as destructive. Administrators configure that per tool, so you decide exactly which actions can ever run unattended.
You decide. Actions are granted per agent, skill, and team, and per environment — production is not staging. Read access can be broad while writes stay narrow.
Every call to Kernel MCP — read or write, approved or declined — is recorded with the actor, the input, and the result, and can be linked to the ticket or change record.
Connect in minutes. Every action scoped, approved, and audited from day one.