Fortress MCP Server
Allows stealth browsing to bypass Akamai bot detection on sites protected by Akamai, enabling scraping or automated access without being blocked.
Allows stealth browsing to bypass Cloudflare challenges (including Turnstile) on protected sites, enabling scraping or automated access without being blocked.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Fortress MCP Serverscrape product prices from amazon.com without getting blocked"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
One browser engine to rule them all
Stealth Chromium engine · v3 (Chromium 153)
Fortress is a Chromium fork that stops scrapers and browser agents from getting blocked. Bot detectors flag automation by reading the browser fingerprint. Fortress corrects that fingerprint inside Chromium's C++, so the browser reads as an ordinary Chrome install. Point your existing Playwright or Puppeteer at it over CDP; nothing else in your code changes.
Headless, on datacenter IPs, with no proxies, Fortress loaded 86.4% of 92 protected sites. The next best stack (Camoufox) loaded 74.5%.
A site reads the fingerprint. Stock Chrome driven by a script fails CreepJS, BrowserScan, rebrowser and the WebGL check and is blocked; Fortress passes all four.
Real runs, fully headless
Unedited captures over CDP, with no stealth plugins. Reproduce with examples/scrape_demos.py.
Akamai, before and after, on aa.com from the same residential IP: a stock browser gets Access Denied, Fortress loads the page and Akamai issues its _abck sensor cookie. Same result on lowes.com, macys.com and kohls.com.
Contents
Quick start · Every session a distinct machine · The Fortress MCP · Works with your stack · Why patch the engine · How Fortress compares · Results · Configure the persona · Build & verify · Reference
Related MCP server: ScrapeLab MCP
Quick start
pip install tilion-fortress # or: npm install tilion-fortress
docker run --rm -p 9222:9222 tilion/fortress:latest # any OS, raw CDP on :9222from tilion_fortress import Fortress
from playwright.sync_api import sync_playwright
with Fortress() as f: # launches the engine on a CDP endpoint
with sync_playwright() as p:
browser = p.chromium.connect_over_cdp(f.cdp_url)
page = browser.new_page()
page.goto("https://bot.sannysoft.com")import { Fortress } from "tilion-fortress";
import { chromium } from "playwright";
const f = await Fortress.launch();
const browser = await chromium.connectOverCDP(f.cdpUrl);
const page = await browser.newPage();
await page.goto("https://browserscan.net");The pip and npm SDKs download a prebuilt, SHA-256-verified binary (Linux x64, Windows x64). Portable tarballs, a .deb and the Windows .zip are on Releases.
Free for developers
v3 is free for developers, with no machine, session or concurrency caps. Activate once:
tilion activate # sign in with GitHub, Google or email; key saved to ~/.tilion/license.jwtThe key is checked offline and Fortress never reports usage. Without activation it still runs, on the public first-generation engine. For CI, Docker and agents, set TILION_LICENSE_KEY=<key> or run tilion activate --token <key>; one key covers a fleet. Production keys for larger organizations are at fortress.tilion.com/pricing.
Command | What it does |
| Unlock v3 with a one-click device flow (browser sign-in) |
| Same flow, prints the URL and code (SSH or remote hosts) |
| Save a key with no browser (CI, agents) |
| Show the saved key's tier and expiry ( |
| Re-issue the key before it expires |
| Remove the saved key and drop back to v1 |
| Download the build for this host. |
| Run the Fortress MCP server, stealth browsing as agent tools |
| Launch the engine and print the CDP endpoint |
Platforms
Platform | Package | Widevine | Status |
Linux x64 | portable tarball · Docker · pip / npm | shipping | |
Windows x64 | portable | shipping | |
Linux arm64 | portable tarball (Graviton, dense cloud fleets) | no | shipping |
Linux x86 · armhf | portable tarball (32-bit x86 / ARM) | no | shipping |
macOS (arm64 / x64) |
| build from source |
The arm64, x86 and armhf builds ship without the bundled Widevine CDM.
Set it up with an AI assistant
Every session a distinct machine
Each launch mints a fresh, internally coherent machine: GPU, screen, cores, timezone, language and fonts all agree. The persona reaches the renderer over IPC, so nothing shows on the command line and every BrowserContext can hold its own identity. Across 40 back-to-back launches of the same binary:
Across 40 launches | Distinct |
Canvas fingerprint | 40 / 40 |
Audio fingerprint | 40 / 40 |
GPU (WebGL renderer) | 25 |
Screen resolution | 14 |
Timezone (geo-coherent with language) | 23 |
Platform mix | 31 Windows · 9 macOS |
Reproduce with tools/gauntlet.py --runs 40. A 64-clone fleet resumed from one snapshot comes up 48/48 distinct, because on_restore re-keys the whole persona with no relaunch.
The Fortress MCP
A Model Context Protocol server that gives Claude, Codex, Cursor, Windsurf, Cline or any MCP client a stealth browser as 29 tools, local and free. When a plain fetch is blocked, the agent calls a tool and gets the page.
pip install "tilion[mcp]" # or zero-install: npx -y tilion-mcp
claude mcp add fortress -- tilion-mcp # Claude CodeFor Claude Desktop, Cursor (~/.cursor/mcp.json), Cline and Windsurf, add the same block to the client's MCP config:
{ "mcpServers": { "fortress": { "command": "tilion-mcp" } } }tools | |
Get blocked pages |
|
Structured data |
|
Whole sites |
|
Drive a page |
|
Multi-step flows |
|
Capture / auth |
|
Bring your own |
|
The full tool reference, benchmarks and agent skill are in mcp/.
Works with your stack
With Fortress running (Docker or the tilion command), one line changes: launch() becomes connect_over_cdp("http://localhost:9222").
Framework | Connect via |
browser-use (~70k stars) |
|
Crawl4AI (~58k stars) | CDP endpoint |
Stagehand (~21k stars) |
|
LangChain Playwright toolkit | Playwright CDP |
Playwright / Puppeteer (Python & JS) |
|
Fortress MCP + | tools for agents, raw CDP underneath |
Why patch the engine, not the page
A JavaScript stealth patch is a function standing where a native one belongs, and detectors check for exactly that:
The tell | Why it catches a JS spoof |
| A native method stringifies to |
Descriptor and |
|
| Native getters throw a specific |
Realm re-acquisition defeats every main-world patch. A detector takes a pristine primitive from another realm and turns it on your function:
const iframe = document.createElement('iframe'); document.body.appendChild(iframe);
const realToString = iframe.contentWindow.Function.prototype.toString;
realToString.call(navigator.__lookupGetter__('vendor')); // returns your source code. Caught.In Fortress the getter for navigator.vendor is the C++ getter. It reports [native code] because it is native code, the same in every frame and worker. Fortress applies the Camoufox idea to V8 and Blink, so the fingerprint matches a Chrome user agent by construction.
The four layers of bot detection
Layer | The tells | Where the fix lives | Fortress |
A: driver / binary artifacts |
| Drive raw CDP, skip chromedriver | built to be driven this way |
B: CDP side-effects |
| The control / CDP-client layer: hold back | no leak (verified on rebrowser) |
C: fingerprint surface | canvas, WebGL, WebGPU, audio, fonts, navigator, across main frame, iframes, workers | The engine (C++), because JS overrides self-reveal | this is Fortress |
D: network / IP egress | datacenter ASN, IP reputation, geo-vs-persona mismatch | Your proxies (residential / mobile), or the Tilion hosted version | bring your own with the self-hosted engine; available on the Tilion hosted version, waitlist at tilion.com |
Fortress is the Layer C engine, built to be driven so A and B hold too, and to stay geo-coherent (timezone, locale, WebRTC) once you bring a Layer D IP.
How Fortress compares
Stock Playwright | puppeteer-extra-stealth | undetected-chromedriver | Camoufox | Antidetect apps¹ | Fortress v3 | |
Spoof layer | none | JS injection | CDP/config patch | C++ engine (Firefox) | C++ engine | C++ engine (Chromium) |
| n/a | n/a | ||||
Survives realm re-acquisition (iframe/worker) | ||||||
No | ||||||
Engine = Chrome / V8 (majority traffic) | Firefox | |||||
Coherent Chromium TLS shape | Firefox | |||||
Parameter-level WebGL + WebGPU coherence | n/a | no WebGPU | varies | |||
Per-launch fleet dynamism (distinct machine) | persistent by design | 48/48 | ||||
Full-persona re-key on snapshot resume | | |||||
Native single-surface C++ patch engine | n/a | n/a | n/a | closed | 81 patches | |
States its own limits | n/a | n/a | n/a |
¹ Multilogin / GoLogin / Dolphin / Nstbrowser: closed-source engine patches, persistent identity by design, bundled residential egress (their Layer-D advantage over Fortress).
Fortress builds on prior art: fingerprint-chromium, ChromiumFish and CloakBrowser came first, and Camoufox, Multilogin, GoLogin and Dolphin also patch engine C++. Fortress's edge is the combination: the broadest native surface set on a Chromium base, fleet dynamism with on_restore, and parameter-level coherence. Where it is behind: IP egress (bring your own) and behavioral humanization beyond mouse motion.
Axis | v2 | v3 |
Chromium base | 151 / 152 | 153.0.8010.36 |
Single-surface C++ patches | ~34 | 81 |
Persona transport | command line, per launch, host-readable | IPC-delivered, in-process, per-context isolated |
Multi-identity in one binary | one persona per process | per- |
Snapshot resume | relaunch to change identity |
|
Fleet distinctness | not measured | 48/48 across 64 clones (500-clone stress-gated) |
Canvas noise | seeded | idempotent, byte-exact cross-path, 64-bit seeds, fail-closed |
WebGL | renderer string only (incoherent numbers) | parameter-level limits + extensions + string, per backend |
WebGPU | absent / software-backend tell | coherent with the persona GPU + per-clone variation |
Fonts | metric substitutes (~33) | 154-family substrate, enumeration gated to the persona |
Client-Hints | UA basics | full Sec-CH-UA + Device-Memory on the navigation path |
| fleet-uniform | per persona (about a third dark) |
Mouse motion | raw driver | recorded-human trajectories (~10k paths, ~16× more human) |
DRM | no Widevine | real Widevine CDM bundled, EME verified |
Results
Benchmark: 92 protected sites, eight stacks
Run on 2026-09-28 from US-East cloud machines, headless, on datacenter IPs with no proxies. Every tool loaded every target twice, each time on a fresh machine destroyed afterwards (1,584 machines). A run counts only if the real page loaded with no challenge or deny page. Method and target list: docs/BENCHMARK.md.
Stack | Served | n | 95% range |
Fortress | 86.4% | 159/184 | 81 to 91 |
Camoufox | 74.5% | 137/184 | 68 to 80 |
puppeteer-extra + stealth | 72.3% | 133/184 | 65 to 78 |
Brave | 36.4% | 67/184 | 30 to 44 |
nodriver | 35.9% | 66/184 | 29 to 43 |
stock Chrome | 34.2% | 63/184 | 28 to 41 |
patchright | 34.2% | 63/184 | 28 to 41 |
undetected-chromedriver | 33.7% | 62/184 | 27 to 41 |
95% Wilson intervals; Fortress's does not overlap the next stack's. Fortress got 2/2 on ten sites where neither Camoufox nor puppeteer-stealth got more than 1/2, and there is no site where it got 0/2 while either of them got 2/2. A repeat run the same day scored 85.3%.
Live detectors
Headless, from a datacenter IP, on the v3 binary. Reproduce with tools/gauntlet.py --bundle ./fortress-v153; dated re-runs are in docs/GAUNTLET_RESULTS.md.
Suite | Stock Chromium | Fortress v3 |
CreepJS | flagged headless | 0% headless · 0% stealth, worker signals coherent |
bot.sannysoft.com | red rows | 0 failed · every intoli + PHANTOM_/HEADCHR_ check green · |
browserscan.net | bot detected | “Normal: No bots detected, could be a human” · WebDriver / Selenium / PhantomJS / Headless / CDP / DevTool all Normal |
BrowserLeaks · WebGL | SwiftShader leak | Unmasked |
WebGPU (secure context) | software-backend tell |
|
AmIUnique · pixelscan · iphey | automation flags | consistent, no automation flags |
rebrowser bot-detector |
| no leak · |
64-clone fleet | one shared identity | 48/48 distinct canvas / audio / |
Cloudflare Turnstile | blocked | cleared: a human click cleared a live challenge (headed, datacenter IP) |
Unedited capture in a real window: Fortress clears a live Cloudflare challenge, turns bot.sannysoft.com all green and reads BrowserScan "Normal".
Configure the persona
The default is a fresh coherent persona per launch, delivered over IPC. Pin or override any surface with --uxr-* switches:
--uxr-platform / --uxr-ua-platform / --uxr-ua-os / --uxr-ua-arch / --uxr-ua-bitness
--uxr-ua-platform-version / --uxr-ua-brand / --uxr-hw-concurrency / --uxr-device-memory
--uxr-webgl-vendor / --uxr-webgl-renderer / --uxr-webgl-fullparams / --uxr-webgpu-vendor
--uxr-canvas-seed / --uxr-audio-seed / --uxr-timezone / --uxr-languages / --uxr-color-scheme
--uxr-screen-width / --uxr-screen-height / --uxr-webrtc-policy=disable_non_proxied_udpEnv var | Purpose |
| Skip the default persona (bare launch) |
| Quick timezone / language override |
Every flag, env var and coherence rule: docs/UXR_CONFIG.md.
Build & verify
export CHROMIUM_VERSION=$(cat CHROMIUM_VERSION) # 153.0.8010.36
build/build.sh # depot_tools, sync the tag, apply patches, gn gen, ninja
build/rebase-monthly.sh 154.0.XXXX.0 # bump + 3-way apply + rebuild + gauntlet-gateOutput: out/Fortress/chrome. The fork is 81 single-surface patches, and the gauntlet gates every release. The first-generation patch series is public and rebuilds with the same script.
Fortress ships only from these channels:
Official source | |
Source | |
Docker | |
Python | |
Node |
Every release ships SHA256SUMS (the SDKs check it on install). Verify the Docker image by digest against the release notes:
BASE=https://github.com/tiliondev/fortress/releases/download/v153.0.8010.36
curl -LO $BASE/fortress-v153-linux-x64.tar.gz
curl -Ls $BASE/SHA256SUMS | sha256sum -c --ignore-missing # -> OK
docker inspect --format '{{index .RepoDigests 0}}' tilion/fortress:153.0.8010.36Reference
Still blocked on Cloudflare, DataDome or Kasada. Usually the IP: datacenter ranges are flagged before any page script runs. Retry through a residential or mobile proxy; if it clears, the fingerprint was fine. Tilion Cloud runs Fortress on residential egress (waitlist at tilion.com).
The fingerprint looks off on a Linux host. The default persona is Windows, but TLS and some OS signals follow the host. Match the persona to your egress OS with --uxr-*, or run the native Windows build.
macOS. Run the Docker image or build the .app from source.
A detector flags something the gauntlet passes. Confirm you are on the current rebase, then email team@tilion.dev with the test page.
Does Fortress work with Selenium? Drive it over CDP. chromedriver adds the driver artifacts Fortress is built to avoid.
How is it different from puppeteer-stealth, undetected-chromedriver, nodriver and patchright? Those patch the JavaScript or CDP layer, which toString and realm re-acquisition reveal, and headless they send HeadlessChrome in the user agent. In the benchmark they loaded 34 to 36% (puppeteer-stealth 72.3%) against Fortress's 86.4%.
How is it different from Camoufox? Same engine-level idea. Camoufox forks Firefox; Fortress forks Chromium/V8, the majority engine, and adds WebGPU coherence and on_restore fleet re-identity. Benchmark: 86.4% vs 74.5%.
Is it an alternative to Multilogin, GoLogin, Kameleo, AdsPower or Dolphin? Those are closed-source builds sold as persistent profiles with bundled proxies. Fortress is an engine you run yourself, with a fresh identity per launch, published first-generation patches and no telemetry.
Does it run headless? Yes. The benchmark is headless, and headless and headed launches present the same fingerprint.
Do I still need proxies? For sites that block datacenter ranges, yes. Fortress keeps timezone, locale and WebRTC coherent with whatever exit you use.
Is it open source? What does it cost? Source-available under the Fortress Source Available License 1.1; see License.
Is this legal? Fortress is for legitimate automation, testing and scraping of public data. Respect each site's terms and your local law.
Will it pass everything forever? No. Detection moves, so Fortress rebases on Chromium monthly and publishes a dated, reproducible gauntlet.
First-party residential and mobile egress, wired to the existing geo-coherence
Keystroke and scroll variance (mouse motion has shipped)
TLS ClientHello (JA3/JA4) in the persona surface set
Linux arm64 / x86 / armhf tarballs (rolling out) and a macOS
.appCode-signed Windows
.exeand macOS.app
Shipped in v3: the IPC persona with per-context isolation, on_restore, parameter-level WebGL and WebGPU, recorded-human mouse motion, the Widevine CDM, the native Windows build, the MCP server and the 92-site benchmark.
patches/ the first-generation C++ patch series (Fortress Source Available License 1.1)
build/ args.gn, build.sh, apply-patches.sh, rebase-monthly.sh, windows/, macos/
packaging/ tilion launcher, fonts.conf, Dockerfile, .deb + bundle builders
fonts/ 222 metric-compatible OS-named font files (154 distinct families, incl. color emoji)
sdk/ python + node (tilion-fortress) prebuilt-binary SDKs
mcp/ the Fortress MCP server (29 tools) and the agent skill
tools/ gauntlet.py, the CreepJS / Sannysoft / BrowserScan CI gate
docs/ UXR_CONFIG (the --uxr-* reference), GAUNTLET_RESULTS, BENCHMARKContributing
Fortress does not accept outside pull requests; see CONTRIBUTING.md. Found a detection vector or a leak? Email team@tilion.dev with a reproducible test page.
License
Fortress Source Available License 1.1. Free to read, modify, rebuild and redistribute, and to use for development, testing and evaluation at any size. Production use is free for individuals and for organizations under US$500,000 in cumulative funding and US$300,000 or less in ARR; other organizations need one flat subscription (fortress.tilion.com/pricing, LICENSE, SUBSCRIPTION-TERMS.md). Earlier BSD-licensed releases keep their BSD permissions (LICENSE-BSD-LEGACY). Chromium and the bundled fonts keep their own licenses (NOTICE).
This server cannot be deployed
Maintenance
Related MCP Connectors
Stealth web automation for AI agents. Login, signup, navigate, screenshot.
Stealth web automation for AI agents. Login, signup, navigate, screenshot.
Web search, browser automation, scraping, crawling and CAPTCHA solving for AI agents.
AI-powered browser automation — navigate, click, fill forms, and extract data from any website.
Related MCP Servers
- AlicenseNot gradedqualityAmaintenanceEnables AI agents to perform undetectable browser automation that bypasses Cloudflare, antibots, and social media blocks. Provides 105 tools for element extraction, network debugging, and real-world web scraping with a 98.7% success rate on protected sites.2,162MIT

ScrapeLab MCPofficial
AlicenseNot gradedqualityDmaintenanceEnables undetectable web scraping and browser automation for AI agents with 84 tools including stealth navigation, element extraction, network interception, and auto cookie consent dismissal. Bypasses anti-bot systems like Cloudflare and DataDome while providing LLM-ready markdown output and full Chrome DevTools Protocol access.MIT- AlicenseAqualityDmaintenanceStealth browser automation for AI agents, using source-patched Chromium to bypass bot detection systems like Cloudflare, reCAPTCHA, and FingerprintJS.28Apache 2.0
- AlicenseNot gradedqualityDmaintenanceEnables AI agents to control browsers with human-like behavior, stealth anti-detection, and 70 tools for navigation, interaction, and monitoring.8 npm1MIT