← Back to directory
F

Fortress MCP Server

Community
Stealth browser engine that lets AI agents fetch pages past Cloudflare/DataDome/CAPTCHA and extract clean data.
Category
Browser #10 of 32
Stars
★ 747 Very popular
Transport
stdio (local process)
Runtime
Python · Node.js · Prebuilt binary · Docker
Credentials
No credential needed
License
Other / unspecified
Last commit
Tools
21
58FMRS · C

Fortress MCP server offers powerful stealth browsing for AI agents, enabling data extraction from heavily protected sites. While there are compliance risks, the engine is fully open-source and auditable, making it a strong choice for developers who value transparency and reproducibility.

Strongest · Documentation 14/20 Weakest · Reliability 7/20

Reliability
7/20
Security and permissions
12/20
Maintenance
13/20
Documentation
14/20
Setup experience
12/20
Why each score
Reliability 7/20
Limited evidence: no server source code, tests, or CI results provided; only README and manifest. Claims of 29 tools and prewarming are unverifiable. Per static calibration, unreliability cannot exceed 12; given 7 because key paths (tool behavior) are unproven and there are distribution risks (external browser binary, PyPI package). Deductions: missing test files and CI results.
Security and permissions 12/20
No obvious malicious behavior or credential leaks. TILION_API_KEY is flagged as secret, but protection measures (e.g., encryption) are not specified. SSRF guard exists (TILION_ALLOW_PRIVATE_EGRESS) and defaults to off, which is positive. However, tools like fetch_protected_page may access external sites; data boundaries and user consent need clarification. No evidence of confirmation mechanisms or principle-of-least-privilege details. Deductions: permission model and confirmation flow not fully disclosed; data flow (external network requests, uploads) not explicit.
Maintenance 13/20
Repository appears active (428 stars, 4 open issues, not archived), with versioned releases (0.1.3) and update notes. License is NOASSERTION but README claims BSD-3-Clause; inconsistency needs resolution. No security response channel. Deductions: unclear license, missing security response process.
Documentation 14/20
README provides detailed installation, tool list, configuration examples, and troubleshooting, but lacks full parameter reference and cost (if any). MCP server docs at mcp/README.md not reviewed, but main README includes sufficient information. Claims of '29 tools' match manifest description, but full list not provided. Deductions: missing detailed API reference and error handling docs; separate MCP docs not examined.
Setup experience 12/20
Installation steps clear: pip install 'tilion[mcp]' or npx tilion-mcp, with client config examples for Claude Desktop, Claude Code, Cursor. Requires Python but runtime hint (uvx) provided. Platform compatibility: Linux x64 and Windows x64 native, macOS via Docker. No automated tests or CI to validate install process. Per static calibration, setup cannot exceed 15; given 12. Deductions: no automated setup verification, macOS installation less straightforward.

Static review · not runListed 2026-08-07

Read the FMRS scoring method →

Fit and risk

What it can accessUses the networkControls a browser

Best for

  • AI agents and browser automation projects that need to access heavily protected websites.
  • Developers who need clean, reproducible page extraction and site crawling.
  • Teams that value open-source and auditable stealth technology.

Not for

  • Use cases requiring strict compliance with website terms of service; stealth techniques may violate ToS.
  • Users needing multiple simultaneous personas or highly configurable fingerprints (current CLI limits one persona per launch).
  • Native binaries on macOS or ARM platforms; must run via Docker.

Required permissions

  • Launches a local Chromium browser process and exposes a CDP endpoint on a local port (e.g., 9222).
  • Assumes full control of the browser via MCP tool calls: navigation, clicks, typing, etc.
  • May access localhost or private IPs, but is SSRF-guarded by default; set TILION_ALLOW_PRIVATE_EGRESS=1 to allow.

Risks and side effects

  • Use of stealth techniques may violate website terms of service and carry legal risks.
  • Even with fingerprint correction, advanced detection can still flag the browser, especially with datacenter IPs.
  • The browser process consumes CPU and memory; concurrent sessions may impact system performance.

Setup

Before you start

Runtime:Python · Node.js · Prebuilt binary · Docker

TILION_API_KEY optionalsecret Bearer key for the hosted Tilion server (cloud mode only); obtain it from Tilion (tilion.dev).
Other optional settings (4)
TILION_MCP_PREWARM optional Set to 1 (default) to boot the browser at startup so the first tool call is instant; nothing to obtain.
TILION_MCP_HEADLESS optional Set to 0 to show a visible browser window; default is headless.
TILION_ALLOW_PRIVATE_EGRESS optional Set to 1 to disable the SSRF guard and allow localhost/private IP access; for local debugging only.
TILION_BASE_URL optional Point the tools at a hosted Tilion server instead of running browsers locally; only needed for cloud mode.
  1. Install Python or Node.js.
  2. Run pip install "tilion[mcp]" or npm install -g tilion-mcp.
  3. Configure MCP client, e.g., add to Claude Desktop's claude_desktop_config.json: {"mcpServers":{"fortress":{"command":"tilion-mcp"}}}.
  4. Restart client to see the fortress tools.
claude_desktop_config.json
{
  "mcpServers": {
    "fortress": {
      "command": "tilion-mcp"
    }
  }
}

Shown for Claude Desktop. Other clients may use a different file or key (VS Code uses "servers") — the configurator below converts it.

.vscode/mcp.json
{
  "servers": {
    "fortress": {
      "command": "tilion-mcp"
    }
  }
}

Goes in your project's .vscode/mcp.json (VS Code uses a "servers" key).

Terminal
claude mcp add fortress -- tilion-mcp

Run it in a terminal; replace any <…> placeholders with your own values first.

Check that it works

After pip install "tilion[mcp]" and adding the fortress server to your client config, restart the client and check that fortress tools such as fetch_protected_page appear in the tool list; a fetch of bot.sannysoft.com confirms it works.

Troubleshooting

  1. If a tool is blocked, check if it's an IP issue: use residential or mobile proxies and retry.
  2. If the fingerprint looks off on Linux, match the persona to your egress OS or use --uxr-* flags.
  3. If first call is slow, set TILION_MCP_PREWARM=1 to prewarm the browser.
  4. Ensure Python is installed and on PATH when using npx (npx runs the server via uv).

Things to try

Once connected, you can ask your AI assistant things like:

  • Use fetch_protected_page to get the content of this page that's blocked by Cloudflare.
  • Use extract_page to pull book titles and prices from https://books.toscrape.com as structured data.
  • Crawl this documentation site with crawl_site and list every page title.
  • Use run_browser_task to log in to this site and screenshot the dashboard.

Tools 21

fetch_protected_page read-only
Fetch content of a protected page.
read_page read-only
Read the accessible text content of the current page.
get_page_html read-only
Get the raw HTML source of the current page.
search_web read-only
Perform a web search and return results.
extract_page read-only
Extract structured data from the current page based on a schema.
extract_document read-only
Extract content from PDF, DOCX, XLSX, and other document formats.
crawl_site read-only
Automatically crawl an entire website, including SPAs.
recon_site_apis read-only
Discover private JSON API endpoints used by the site.
Show 13 more tools
page_elements read-only
List all interactive elements available on the page.
click_button writes
Click a button on the page.
fill_field writes
Fill text into a form field.
press_key writes
Simulate a keyboard key press.
wait_for read-only
Wait for a specific element or condition to be met.
evaluate_js writes
Execute JavaScript code in the page context.
run_browser_task writes
Run a multi-step browser task (e.g., login, pagination, infinite-scroll, checkout).
screenshot_page writes
Take a screenshot of the current page.
save_page writes
Save the current page content to a local file.
download_file writes
Download a file from the page.
save_profile writes
Save the browser profile (cookies, localStorage, etc.).
load_profile writes
Load a previously saved browser profile.
get_stealth_cdp_endpoint read-only
Get the CDP endpoint of the stealth browser for external clients.

Use cases

Extracting data from pages that block standard browsers (e.g., Cloudflare, PerimeterX).
Automating flows that require passing CAPTCHAs or other anti-bot checks (e.g., logging in and downloading a report).
Large-scale site crawling for structured data while minimizing the risk of being blocked.

Supported clients

Claude Desktop
Claude Code
Cursor

Listed from the project's documentation, not tested by this site.

Overview

The Fortress MCP server provides 29 stealth browser tools for AI agents. It corrects the browser fingerprint inside Chromium's C++, so the browser presents as an ordinary Chrome install. It enables agents to fetch protected pages, extract structured data, crawl whole sites, and run multi-step browser tasks, all while avoiding bot detection. The server also exposes get_stealth_cdp_endpoint to get a CDP URL for reuse with Playwright/Puppeteer.

Similar servers

Source revision 026da4dab70e Data synced 2026-10-11 Read the FMRS scoring method