Skip to main content
Glama
mysleekdesigns

CrawlForge MCP Server

stealth_mode

Bypass Cloudflare, Datadome, and other bot-detection blocks by rendering pages in a real browser with randomized fingerprints and human-like behavior. Use after a normal scrape returns 403, 429, CAPTCHA, or an empty shell.

Instructions

Use this when a site blocks normal scraping - Cloudflare, Datadome, or other bot-detection systems. Renders in a real browser with randomized fingerprints, human behavior simulation, WebRTC/canvas spoofing - Camoufox (Firefox) when it is installed, Chromium otherwise, and the result names the one that ran. operation:"scrape" is the one-shot path: it creates a context, navigates, returns the requested formats and tears down. The create_context -> create_page -> cleanup operations remain for multi-step work. robots.txt is respected on every navigation. Not a first choice: try scrape first and switch here after a 403/429/CAPTCHA/challenge page or an empty shell. Cost: 5 credits per browser operation; configure, enable, disable, get_stats and cleanup cost 1. Example: stealth_mode({operation:"scrape", url:"https://example.com", formats:["markdown","links"]})

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
urlNoURL to scrape — required for operation:"scrape"
engineNoBrowser engine: "auto" (default — camoufox when it is installed, Chromium otherwise, and the result says which), "camoufox" (Firefox-based, higher anti-detect score; fails if not installed), or "chromium" ("playwright" is the same engine under its old name)auto
formatsNoFormats to return from operation:"scrape" (default: ["markdown"]). "screenshot" returns a crawlforge://screenshot/{id} resource URI.
verboseNoReturn the full generated fingerprint from create_context instead of a summary
wait_forNoExtra wait after page load, in ms — for content that renders after DOMContentLoaded
contextIdNoBrowser context ID for page operations
operationNoStealth operation to performconfigure
urlToTestNoURL to navigate to when creating a page
redact_piiNoRedact personal data from the text this call returns, before it reaches your context window. true means the free regex pass over EMAIL, PHONE, FINANCIAL and SECRET. The result carries redaction:{entities,count}. Default: off
stealthConfigNoStealth browser configuration with anti-detection settings
respect_robotsNoRespect the target site's robots.txt (default: true). Setting this to false is honoured, returns a warning in the response, and is recorded against your API key — it is your decision, not a silent default.
max_inline_charsNoLargest result to return inline, in characters of its JSON. Over it, the call returns a preview plus a result_handle for read_result instead of the whole result (default 40,000; env CRAWLFORGE_MAX_INLINE_CHARS)

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed4 schema fields changedv6.8.0
    • changedInput schema / properties / engine / default
      Previous value: -"playwright"New value: +"auto"
    • changedInput schema / properties / engine / description
      Previous value: -"Browser engine: \"playwright\" (Chromium, default) or \"camoufox\" (Firefox-based, higher anti-detect score — install with npm install camoufox)"New value: +"Browser engine: \"auto\" (default — camoufox when it is installed, Chromium otherwise, and the result says which), \"camoufox\" (Firefox-based, higher anti-detect score; fails if not installed), or \"chromium\" (\"playwright\" is the same engine under its old name)"
    • changedInput schema / properties / engine / enum
      Previous value: -[
      -  "playwright",
      -  "camoufox"
      -]New value: +[
      +  "auto",
      +  "chromium",
      +  "camoufox",
      +  "playwright"
      +]
    • addedInput schema / properties / stealthConfig / properties / proxyRotation / description
      Added value: +"Route the browser through your own proxies. Each entry is a proxy URL — \"http://user:pass@host:port\" (percent-encode a password containing @ : or /), or a bare \"host:port\" for an unauthenticated HTTP proxy; http, https, socks4 and socks5 are accepted. rotationInterval is the minimum ms on one proxy before the list advances. Cloudflare scores the IP before it serves a challenge, so a residential proxy is what gets past a block that no fingerprint fixes. CrawlForge supplies no proxies."
  2. Changed8 schema fields changedv6.0.0
    • removedInput schema / additionalProperties
      Removed value: -false
    • addedInput schema / properties / max_inline_chars
      Added value: +{
      +  "description": "Largest result to return inline, in characters of its JSON. Over it, the call returns a preview plus a result_handle for read_result instead of the whole result (default 40,000; env CRAWLFORGE_MAX_INLINE_CHARS)",
      +  "maximum": 10000000,
      +  "minimum": 1000,
      +  "type": "integer"
      +}
    • addedInput schema / properties / redact_pii
      Added value: +{
      +  "anyOf": [
      +    {
      +      "type": "boolean"
      +    },
      +    {
      +      "properties": {
      +        "entities": {
      +          "description": "Which classes to redact, case-insensitive: EMAIL, PHONE, FINANCIAL, SECRET, plus PERSON and LOCATION when mode is \"model\". Omitted or empty means all four regex classes (and both model classes in \"model\" mode). An unknown name, or a model-only name without mode:\"model\", is rejected",
      +          "items": {
      +            "type": "string"
      +          },
      +          "type": "array"
      +        },
      +        "mode": {
      +          "description": "\"fast\" (default) is regex only and free; \"model\" adds an Ollama NER pass for PERSON and LOCATION (+3 credits once per call)",
      +          "enum": [
      +            "fast",
      +            "model"
      +          ],
      +          "type": "string"
      +        },
      +        "replace_style": {
      +          "description": "\"tag\" (default) writes <EMAIL>, \"mask\" writes [REDACTED], \"remove\" deletes the value",
      +          "enum": [
      +            "tag",
      +            "mask",
      +            "remove"
      +          ],
      +          "type": "string"
      +        }
      +      },
      +      "type": "object"
      +    }
      +  ],
      +  "description": "Redact personal data from the text this call returns, before it reaches your context window. true means the free regex pass over EMAIL, PHONE, FINANCIAL and SECRET. The result carries redaction:{entities,count}. Default: off"
      +}
    • removedInput schema / properties / stealthConfig / additionalProperties
      Removed value: -false
    • removedInput schema / properties / stealthConfig / properties / antiDetection / additionalProperties
      Removed value: -false
    • removedInput schema / properties / stealthConfig / properties / customViewport / additionalProperties
      Removed value: -false
    • removedInput schema / properties / stealthConfig / properties / fingerprinting / additionalProperties
      Removed value: -false
    • removedInput schema / properties / stealthConfig / properties / proxyRotation / additionalProperties
      Removed value: -false
  3. Changed6 schema fields changedv5.4.0
    • addedInput schema / properties / formats
      Added value: +{
      +  "default": [
      +    "markdown"
      +  ],
      +  "description": "Formats to return from operation:\"scrape\" (default: [\"markdown\"]). \"screenshot\" returns a crawlforge://screenshot/{id} resource URI.",
      +  "items": {
      +    "enum": [
      +      "markdown",
      +      "html",
      +      "text",
      +      "links",
      +      "metadata",
      +      "screenshot"
      +    ],
      +    "type": "string"
      +  },
      +  "type": "array"
      +}
    • changedInput schema / properties / operation / enum
      Previous value: -[
      -  "configure",
      -  "enable",
      -  "disable",
      -  "create_context",
      -  "create_page",
      -  "get_stats",
      -  "cleanup"
      -]New value: +[
      +  "scrape",
      +  "configure",
      +  "enable",
      +  "disable",
      +  "create_context",
      +  "create_page",
      +  "get_stats",
      +  "cleanup"
      +]
    • addedInput schema / properties / respect_robots
      Added value: +{
      +  "description": "Respect the target site's robots.txt (default: true). Setting this to false is honoured, returns a warning in the response, and is recorded against your API key — it is your decision, not a silent default.",
      +  "type": "boolean"
      +}
    • addedInput schema / properties / url
      Added value: +{
      +  "description": "URL to scrape — required for operation:\"scrape\"",
      +  "format": "uri",
      +  "type": "string"
      +}
    • addedInput schema / properties / verbose
      Added value: +{
      +  "default": false,
      +  "description": "Return the full generated fingerprint from create_context instead of a summary",
      +  "type": "boolean"
      +}
    • addedInput schema / properties / wait_for
      Added value: +{
      +  "description": "Extra wait after page load, in ms — for content that renders after DOMContentLoaded",
      +  "maximum": 30000,
      +  "minimum": 0,
      +  "type": "number"
      +}
  4. Changed1 schema field changedv5.0.4
    • changedInput schema / $schema
      Previous value: -"http://json-schema.org/draft-07/schema#"New value: +"https://json-schema.org/draft/2020-12/schema"
  5. First observedv4.10.0

TDQS

A4.5/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description discloses several behavioral traits beyond the annotations: it renders in a real browser, randomizes fingerprints, simulates human behavior, spoofs WebRTC/canvas, respects robots.txt on every navigation, and names which engine ran. It also discloses the cost model (5 credits per browser operation, 1 for configure/enable/disable/get_stats/cleanup). The annotations only say readOnlyHint=false, openWorldHint=true, idempotentHint=false, destructiveHint=false, so the description carries the burden and does so well. It doesn't mention rate limits or what happens on failure, but the disclosed behaviors are substantial.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is dense but well-organized: it front-loads the trigger condition, then explains the rendering approach, the operation modes, the robots.txt behavior, the usage guidance, the cost, and an example. Every sentence earns its place. It's longer than ideal, but the tool is complex with 12 parameters and multiple operations, so the length is justified. The example at the end is a useful concrete anchor.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's complexity (12 parameters, nested objects, 8 operations, no output schema), the description covers the key decision points: when to use it, which operation to pick, what engine will run, cost, robots.txt behavior, and a concrete example. It doesn't explain the return format for each operation or the full semantics of every stealthConfig field, but the schema covers those. The description is complete enough for an agent to select and invoke the tool correctly in the common one-shot scrape case.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the baseline is 3. The description adds value by explaining the operation flow ('operation:"scrape" is the one-shot path: it creates a context, navigates, returns the requested formats and tears down'), clarifying the engine selection behavior ('auto (default — camoufox when it is installed, Chromium otherwise, and the result says which)'), and giving a concrete example call. It also explains the cost implications of operations, which the schema doesn't. It doesn't add much beyond the schema for nested stealthConfig fields, but the schema already documents those thoroughly.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific use case ('when a site blocks normal scraping - Cloudflare, Datadome, or other bot-detection systems') and names the tool's core behavior: rendering in a real browser with anti-detection measures. It clearly distinguishes itself from the sibling 'scrape' tool by positioning stealth_mode as the fallback after 403/429/CAPTCHA/challenge pages or empty shells. The verb 'use' plus the resource 'stealth_mode' and the explicit trigger conditions make the purpose unmistakable.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explicitly states when to use this tool ('when a site blocks normal scraping'), when not to use it ('Not a first choice: try scrape first'), and what signals should trigger switching ('switch here after a 403/429/CAPTCHA/challenge page or an empty shell'). It also distinguishes the one-shot 'scrape' operation from the multi-step create_context/create_page/cleanup path, giving an agent clear decision criteria.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.