Kernel MCP
for LuumenAI

Drive Kernel cloud browsers, and hold the automation runs for approval

Connect Kernel MCP and Luumen can work with your Kernel cloud-browser infrastructure from the terminal. It reads connection context, searches Kernel's documentation, and checks what the server can do before acting. Running Playwright code, shell commands, or HTTP requests inside a session is a change, so those steps are previewed and held for approval by default. Luumen signs in through OAuth with dynamic client registration.

The Kernel MCP toolbox

25 tools: 3 read, 22 write. Reads answer instantly. Writes require approval by default. Everything is logged.

  • ReadGet connection contextInspect the authenticated Kernel connection before a project-scoped operation.
  • ReadGet more toolsReport a genuine server capability gap only after checking the available tools and confirming none can complete the task.
  • ReadSearch docsSearch Kernel platform documentation for guides, tutorials, and API references.
  • WriteBrowser curlSend an HTTP request through an existing Kernel browser session's Chrome network stack. Approval by default
  • WriteComputer actionExecute computer actions on a browser session. Approval by default
  • WriteExec commandExecute a command synchronously inside a browser VM. Approval by default
  • WriteExecute playwright codeExecute Playwright/TypeScript automation or browser-wide WebMCP helpers against an existing Kernel browser session. Approval by default
  • WriteManage api keysManage Kernel API keys. Approval by default
  • WriteManage appsManage Kernel apps when an agent needs to discover deployed app actions, invoke an app, or inspect deployment/invocation state. Approval by default
  • WriteManage auth connectionsManage reusable authenticated profiles for third-party websites. Approval by default
  • WriteManage browser poolsManage pre-warmed browser pools when an agent needs fast browser acquisition or reusable session capacity. Approval by default
  • WriteManage browsersManage browser sessions and their archived telemetry. Approval by default
  • WriteManage credential providersManage external credential providers (e.g. Approval by default
  • WriteManage credentialsManage credentials stored in Kernel for managed auth. Approval by default
  • WriteManage extensionsManage browser extensions uploaded to Kernel. Approval by default
  • WriteManage profilesManage browser profiles when an agent needs persistent cookies, login state, or reusable browser state. Approval by default
  • WriteManage projectsManage Kernel projects for resource isolation within an organization. Approval by default
  • WriteManage proxiesManage proxy configurations for routing browser traffic. Approval by default
  • WriteManage replaysManage video replay recordings for a browser session. Approval by default
  • WriteManage vault cardsConfigure requests for live payment cards, not merchant payments. Approval by default
  • WriteManage vault itemsInspect payment vault items and immutable audit events. Approval by default
  • WriteManage vaultsManage project-owned payment vaults, not merchant payments. Approval by default
  • WriteManage vault walletsConnect payment wallets without exposing secrets. Approval by default
  • WriteSubmit feedbackSend feedback about anything KERNEL to the KERNEL team. Approval by default
  • WriteWebmcpDiscover and invoke native WebMCP tools registered across every open tab and frame in a Kernel browser. Approval by default

One prompt, start to finish

What a governed Kernel MCP run looks like inside Luumen.

Questions

How does LuumenAI connect to Kernel MCP?

Authorize once with OAuth 2.0. Luumen lists the scopes each action needs before you approve the connection, and credentials never appear in the chat.

Can LuumenAI change things in Kernel MCP on its own?

Read actions answer immediately. Anything that writes — browser curl, computer action, exec command, execute playwright code, and more — is shown as a plan and requires approval by default, including the 19 actions classified as destructive. Administrators configure that per tool, so you decide exactly which actions can ever run unattended.

Who gets access to the integration?

You decide. Actions are granted per agent, skill, and team, and per environment — production is not staging. Read access can be broad while writes stay narrow.

Is there an audit trail?

Every call to Kernel MCP — read or write, approved or declined — is recorded with the actor, the input, and the result, and can be linked to the ticket or change record.

Put Kernel MCP to work with Luumen

Connect in minutes. Every action scoped, approved, and audited from day one.