Ghostget

Web actions for agents

Your agent gets the result without clicking around.

Install the CLI or tell your agent to. It reads a page, archives one media item, or acts in an account you connected, and returns the result instead of a browser to steer.

Free and MIT licensed · macOS and Linux with Bun 1.3.14 · Release v0.18.45

$ ghostget read https://example.com
Capturing https://example.com/ (auto, auto) ...
---
title: "Example Domain"
source: "https://example.com/"
clipped: "2026-09-05"
platform: "generic"
capture_status: "complete"
capture_method: "http"
capture_scope: "page"
---
# Example Domain

This domain is for use in documentation examples without needing permission. Avoid use in operations.

[Learn more](https://iana.org/domains/example)
The complete output of one ghostget read for a public page: a short record of what was captured and how, then the page as Markdown. Nothing was saved. Public-page read recorded on September 5, 2026; command updated for Ghostget.

How it works

Each request runs one named action.

Your agent asks for a supported action, such as reading an inbox or saving a video. Ghostget checks the inputs and the account, makes the request, and returns a structured result. Sign-in details stay inside Ghostget.

  1. Name the job

    The agent asks for an outcome, such as reading an inbox or preserving one video.

  2. Match one action

    Ghostget finds one installed, supported action. There is no general browser or request tool to fall back on.

  3. Check, then run once

    Ghostget checks the exact service, account, and risk level, then makes one exchange. Your sign-in can reach only the service that action needs.

  4. Return the result

    Your agent gets a structured result, a note of anything incomplete, or a saved record that the outcome is not yet known.

No browser to steer

Your agent never steers a browser.

Browser-using agents stream the live page into the model and let it choose each click. With Ghostget, the agent asks for an outcome and only the result comes back.

Page state and screenshots never enter the agent’s context. It never sees a cookie or token, and there are no selectors for it to guess. If a service changes how it responds, the affected action stops instead of improvising a click path.

Some pages need a real browser to render. For those, Ghostget runs its own browser internally, at most two at a time, and the agent can’t steer it. The agent-browser comparison shows how that works.

Measured

Smaller answers cost fewer tokens.

Your model provider charges for everything the agent reads. On September 22, 2026, ghostget read returned these bytes for each URL, compared with the raw HTML the URL serves. Every row was one HTTP capture with no browser and capture_status: "complete".

Page readghostget returnsRaw HTMLSmaller by
Wikipedia article15,021 bytes145,617 bytes9.7×
GitHub repository page79,955 bytes647,690 bytes8.1×
This site’s security guide7,220 bytes41,295 bytes5.7×
Hacker News front page7,311 bytes34,791 bytes4.8×
example.com345 bytes559 bytes1.6×

At roughly four bytes per token, that Wikipedia read costs about 3,800 tokens where the raw page carries about 36,000. The table counts bytes because tokenizers differ.

Browser-driving agents pay again on every step, because the page comes back into context each time. A July 2026 comparison matrix cites Microsoft’s reported figure of about 114,000 tokens for a typical Playwright MCP task, against about 27,000 for its disk-first CLI. Treat any single figure as an estimate.

What it does

Read a page, archive one item, or act in an account.

Read
Turn a public URL into Markdown your agent can inspect on the spot or keep in a local knowledge base.
Archive
Preserve one media item you’re allowed to access, with its source bytes, transcript, manifest, and SHA-256 records.
Act
Use named actions in 21 services, from Beeper and Gmail to YouTube. Most use an account you’ve connected; a few, such as GitHub, need no sign-in. If an action isn’t listed, Ghostget doesn’t offer it.

Providers

Reviewed actions across 21 services.

Each entry shows how Ghostget connects to that service and links to its supported actions in this release.

8 supported actions

Comments · Content · Feeds · Media · Posts · Profiles

Public web, no sign-in + Signed-in web session

1 supported action

Feeds

Signed-in web session

2 supported actions

Organizations · Profiles

Public web, no sign-in

3 supported actions

Contacts · Messages

Official API

3 supported actions

Comments · Feeds · Posts

Signed-in web session

8 supported actions

Comments · Contacts · Content · Feeds · Media · Messages · Posts · Profiles

Signed-in web session

5 supported actions

Conversations · Messages

Local app

13 supported actions

Articles · Comments · Contacts · Feeds · Organizations · Posts · Profiles · Reactions · Replies

Official API + Signed-in web session

11 supported actions

Comments · Content · Feeds · Flair · Media · Messages · Posts · Profiles

Signed-in web session

13 supported actions

Articles · Comments · Content · Feeds · Media · Messages · Organizations · Posts · Profiles · Subscribers

Signed-in web session

4 supported actions

Feeds · Media · Posts · Profiles

Signed-in web session

3 supported actions

Comments · Feeds · Profiles

Signed-in web session

1 supported action

Profiles

Signed-in web session

3 supported actions

Registry sites · Registry tools

Public web, no sign-in

4 supported actions

Contacts · Media · Messages

Linked device

16 supported actions

Articles · Comments · Content · Feeds · Likes · Messages · Posts · Profiles · Replies · Threads

Official API + Signed-in web session

5 supported actions

Comments · Feeds · Media · Posts · Profiles

Signed-in web session

Plus 1,802 sites publishing WebMCP tools

The bundled webmcp adapter reads tool schemas from the public WebMCP Registry for 1,802 listed sites covering 15,282 published tools, and calls the 1,509 declared read-only, with no account needed. How WebMCP works with your agent · Use WebMCP sites

Provider names identify compatible services and do not imply endorsement. Counts are for release v0.18.45. Browse every supported action

Get started

Tell your agent, or run two commands.

Any agent that can run terminal commands can install Ghostget for you. To do it yourself, install Bun 1.3.14 on macOS or Linux, then install the @hraness/ghostget canonical release archive. Your first public-page read needs no account, API key, or vault.

terminalv0.18.45
bun add --global https://github.com/hraness/ghostget/releases/download/v0.18.45/hraness-ghostget-0.18.45.tgz
ghostget read https://example.com

Optional: add the Agent Skill

npx skills add hraness/ghostget#v0.18.45

Teach your agent the Ghostget commands after installing the CLI. With Bun, run bunx skills add hraness/ghostget#v0.18.45 instead. View the Ghostget Agent Skill on skills.sh.

Success prints Example Domain as Markdown without saving it. Next, save a page or connect one service. Provider setup starts with ghostget adapter sync-bundled --json.

Interfaces

Use an Agent Skill, CLI, or TypeScript SDK

Ghostget runs on your machine. It has no hosted API or MCP server, so your agent can do the same things from a skill, a terminal, or typed code.

Agent Skill

Add the release-matched capture, archive, provider, and publishing guide to an agent that can run commands.

npx skills add hraness/ghostget#v0.18.45

CLI

Use stable human output or JSON from a terminal, a script, or an agent tool call.

ghostget capabilities --json

TypeScript SDK

Import validators and types without starting the CLI or reading anything on your machine.

import { isProviderPluginId } from "@hraness/ghostget"

Menu bar and terminal

Review accounts and approvals.

Review connected accounts, permissions, pending approvals, and recent activity in your menu bar or terminal. The menu also opens recent output files. Your agent keeps using the same CLI and SDK.

Run ghostget menubar for the menu companion, and ghostget menubar install to start it at login. The downloaded companion is unsigned; ghostget menubar doctor explains platform setup.

Prefer the keyboard? Stop the menu with ghostget menubar stop, then run ghostget tui. Tab moves between six sections, Enter opens actions, and ? shows help. Only one control client runs at a time; public-page reads need neither.

Safety and limits

Keep accounts and saved work under your control.

Account state and saved results stay on your machine. Requested work contacts the source service, and your agent receives the results you give it.

Your sign-ins stay here
Ghostget stores sign-ins on this machine, including any linked-device store you choose to use. Your agent gets a named action and its result, never cookies, tokens, or a browser it can steer.
Import a token without showing it
For X, ghostget vault import-x accepts a 1Password field reference instead of a pasted secret; Ghostget verifies the X user and stores the token privately on your machine. It is a token importer for one provider, not a general password manager.
Only the traffic you asked for
Reads and actions contact their selected sources. Provider sign-in and explicitly started messaging sync also use the network. The CLI and SDK send no website analytics.
Reads you can open later
Provider-read snapshots are encrypted on your machine; owner messaging keeps a separate private local history and journal. A failed refresh does not erase the last verified state.
Writes need a preview and a confirmation
Anything that changes an account needs a preview and an explicit confirmation of that exact preview, or a limited grant you set up for owner messaging. If a write went out and its result is unknown, Ghostget won’t send it again. It stays marked unsettled until separate evidence shows what happened.
When a service changes
If a service changes how it responds, the affected action stays off until it is reviewed again. Ghostget never quietly falls back to a browser.
Bring your own agent
Ghostget supplies the local tools and a macOS menu-bar companion for outputs and CLI guidance. Your agent owns the model and planning.
No bypassing access controls
Media archiving is limited to one finite item you are allowed to access that is not protected by DRM. Ghostget does not bypass payment, sign-in, access controls, or DRM.

Compare

How Ghostget compares with browser tools.

Most “browser use” tools give the model a browser to drive, on your machine or in the cloud. With Ghostget, the agent asks for a reviewed outcome and gets back one result. Compare the approaches in detail.

ApproachBest fitHow Ghostget differs
browser-useOpen-ended, multi-step browsing where the model observes the page and decides each stepThe model chooses no steps. Each call runs one reviewed action or stops with an error.
Playwright MCPGiving an existing agent live browser controls, with the accessibility tree streamed into context per stepOne result per call. No page state goes back into the agent’s context.
agent-browserShell-level browser steering an agent composes itself: open, click, type, snapshotGhostget runs agent-browser internally for pages that need rendering, and the agent can’t steer it.
Browserbase + StagehandManaged cloud browser sessions at scale, with proxies, stealth, and session replayRuns on your machine with no remote browser, and never falls back to a browser when an action is missing or has changed.
Pipedream ConnectHosted integration breadth and managed end-user authentication across thousands of APIs and prebuilt toolsA smaller local set whose provider actions and implementations are reviewed before they run.
Apify MCPDiscovering and running eligible Apify Store Actors through a hosted MCP service, with access to results and storageEach provider action and implementation must be named and reviewed before it can run.
GhostgetRepeated account and page work where you want to know exactly what the agent can doEncrypted local copies of reads, a preview and a record for every write, and actions that stop when a service changes.

Questions

Before you install.

Which agents does it work with?

Any agent that can run commands: Claude Code, Codex, Cursor, Gemini CLI, or your own. The optional Agent Skill teaches it the Ghostget commands and their limits in one step.

Does Ghostget need an account?

No. Install the CLI and read a public page. You connect a service only when you want its actions, and each connection is stored on your machine. Hraness Accounts sign-in is optional and is not needed for page reads or provider setup.

Does it use my credentials?

It uses a sign-in you already have for a service, on this machine, and keeps it out of your agent’s hands. Each sign-in is bound to one account and one service, in a locked local store the agent cannot read. Ghostget’s normal outputs do not include cookies or tokens. The calling agent keeps the separate tools and permissions you give it.

What does it cost?

Nothing. Ghostget is free and MIT licensed, with no hosted tier and no paid plan. You pay your model provider and any service subscriptions you already have.

Does it phone home?

No. The CLI and SDK send no analytics to ghostget.com; they make only the network requests the action you chose requires. This website counts page views with cookieless analytics and honors Do Not Track. The privacy page explains both.

Which platforms does it run on?

macOS and Linux with Bun 1.3.14. Actions that read iMessage or Apple Photos need macOS. Beeper actions need Beeper Desktop on the same machine, and WhatsApp reads need a linked device.

Is Ghostget an AI agent?

No. Ghostget supplies a CLI, an SDK, and a macOS menu-bar companion. Your agent brings the model and the plan; Ghostget manages account permissions, approvals, and the records of its actions.

Does Ghostget use a browser internally?

Yes, in two cases. When a page can’t be read without rendering it, Ghostget runs its own browser, at most two at once; page reads try a single HTTP request first. Some signed-in provider actions, such as certain LinkedIn and Instagram reads, also run inside a contained browser session. In both cases the browser accepts no selectors, coordinates, or scripts from the caller.

Why does Ghostget refuse to retry some writes?

If a request left the machine and its response was lost, the effect may already exist. Ghostget keeps that uncertainty visible and settles it from separately obtained evidence instead of sending the request again.

What does release v0.18.45 include?

Page capture, media archives, encrypted reads, and 139 supported actions across 21 services. ghostget capabilities shows what is installed and available on your machine, and the provider list names every action in this release.

Documentation

Start with the outcome you need.

Each guide covers the current release, the commands to use, and the limits that apply.

Check provider support

See every provider action available in the current release and the access method it uses.

Understand the security model

How Ghostget keeps sign-ins on your machine, ties each action to one account, and handles a write whose outcome is unknown.

Author a provider plugin

Define one operation, prove what it sends and returns, then check, test, pack, trust, and install the exact code.

Essays

Arguments and comparisons

How named actions differ from browser control, virtual machines, device policy, and the other ways people try to limit what an agent can do.

How agents reach the web

browser-use, Playwright MCP, agent-browser, and hosted browsers compared side by side with Ghostget’s named actions.

Omarchy and named operations

Omarchy’s default desktop let any user process escalate to root. A host privilege grant is not a named web operation.

Made by

Hraness

Ghostget is built by Hraness, a software studio in Puerto Rico. We build tools that give AI agents memory, context, web access, and a record of their work, and we make apps and sourced archives for people.

Read your first page in two commands.

Start with one public page and no account or API key. Connect a service when you need its actions.