@trishchuk/mcp-fetch-server
Allows fetching content from websites protected by Akamai's bot detection systems by mimicking realistic browser TLS and HTTP/2 fingerprints.
Allows fetching content from websites protected by Cloudflare's anti-bot measures (Turnstile, Under Attack Mode) by impersonating real browser fingerprints.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@@trishchuk/mcp-fetch-serverfetch https://www.bbc.com using chrome_147 impersonation"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
@trishchuk/mcp-fetch-server
A high-performance Model Context Protocol (MCP) server providing an anti-bot-resilient fetch tool for AI agents (Claude Code, Claude Desktop, Cursor, Windsurf, Cline, Antigravity, etc.).
Powered by @trishchuk/fetch โ a native curl-impersonate-style HTTP client that accurately mimics real browser TLS (JA3/JA4, ClientHello) and HTTP/2 fingerprints.
๐ Why this server?
Standard Node.js/Undici HTTP clients get immediately flagged and blocked by modern bot-protection systems (Cloudflare Turnstile / Under Attack Mode, DataDome, PerimeterX / HUMAN, Akamai, Kasada, AWS WAF).
Furthermore, standard MCP fetching tools often fail on large payloads or blow up LLM token contexts.
@trishchuk/mcp-fetch-server solves both problems:
Realistic Browser Impersonation: Replicates exact cipher suites, TLS extensions, ALPN order, and HTTP/2 settings frames from modern browsers (Chrome, Safari, Firefox).
LLM Context-Safe Truncation: Streams and caps response bodies at 2MB (
maxResponseBytes). Oversized pages are cleanly truncated and flagged with"truncated": truerather than crashing with errors.Stateful Sessions: Maintain cookies, login states, and connection pools across multiple agent tool calls using the
sessionparameter.Smart Encoding: Automatically detects MIME types and returns clean UTF-8 text for HTML/JSON/XML or Base64 for binary files (images, PDFs, documents).
Related MCP server: webfetch-mcp
โ Requirements
Node.js >= 24 โ required by
@trishchuk/fetch.Prebuilt native binaries ship for macOS (arm64, x64), Linux (x64/arm64, glibc and musl) and Windows (x64). Other platforms are not supported by the underlying client.
๐ฆ Installation & Setup
Option 1: Run with npx (No installation needed)
You can run the server directly via npx:
npx -y @trishchuk/mcp-fetch-serverOption 2: Global or Local Installation
# Global
npm install -g @trishchuk/mcp-fetch-server
# Or clone & install locally
git clone https://github.com/x51xxx/mcp-fetch-server.git
cd mcp-fetch-server
npm installโ๏ธ MCP Client Configuration
Claude Code
Add directly via CLI:
# Using npx (recommended)
claude mcp add fetch -- npx -y @trishchuk/mcp-fetch-server
# Or using local path
claude mcp add fetch -- node /path/to/mcp-fetch-server/src/index.jsClaude Desktop
Add to your claude_desktop_config.json:
macOS:
~/Library/Application Support/Claude/claude_desktop_config.jsonWindows:
%APPDATA%\Claude\claude_desktop_config.jsonLinux:
~/.config/Claude/claude_desktop_config.json
{
"mcpServers": {
"fetch": {
"command": "npx",
"args": ["-y", "@trishchuk/mcp-fetch-server"]
}
}
}Cursor / Windsurf / Antigravity (.mcp.json)
Create or update .mcp.json in your workspace:
{
"mcpServers": {
"fetch": {
"command": "npx",
"args": ["-y", "@trishchuk/mcp-fetch-server"]
}
}
}๐ ๏ธ Tool Reference: fetch
Input Parameters
Parameter | Type | Default | Description |
|
| required | Target absolute URL (e.g. |
|
|
| HTTP method ( |
|
|
| Request headers as key-value pairs ( |
|
|
| Request body sent as UTF-8 string (JSON, form-encoded, raw text). |
|
|
| Browser fingerprint preset (e.g. |
|
|
| Declared OS: |
|
|
| Proxy URL: |
|
|
| Session ID for sharing client connections and cookie jars across multiple calls. |
|
|
| Custom DNS pinning (e.g. |
|
|
| Redirect mode: |
|
|
| Force protocol version: |
|
|
| Minimum TLS version: |
|
|
| Maximum TLS version: |
|
|
| Overall request timeout in milliseconds. |
|
|
| Body limit in bytes (max 2MB). Responses exceeding this are safely truncated. |
|
|
| Body return format: |
Response Schemas
1. Successful HTTP Exchange
Any completed HTTP transfer returns a standard JSON result (including 404, 500, or 3xx under redirect: "manual"):
{
"status": 200,
"statusText": "OK",
"ok": true,
"url": "https://example.com/data",
"redirected": false,
"headers": {
"content-type": "application/json; charset=utf-8",
"cache-control": "max-age=3600"
},
"bodyEncoding": "text",
"body": "{\"message\": \"Hello world\"}",
"truncated": false
}2. Network / Transport Failure
If the network connection fails, times out, or the URL is invalid, the tool returns isError: true:
{
"error": true,
"code": "TIMEOUT",
"message": "failed to read response body: request or response body error: operation timed out"
}๐ก Usage Examples for Agents
1. Bypass Bot Detection on Protected Target
{
"url": "https://protected-site.com/products",
"impersonate": "chrome_147",
"platform": "macos",
"headers": {
"Accept-Language": "en-US,en;q=0.9"
}
}2. Multi-Step Scraping with Persistent Session (Cookie Jar)
// Step 1: Login / Obtain Session Cookie
{
"url": "https://example.com/api/login",
"method": "POST",
"session": "agent-crawler-01",
"headers": { "Content-Type": "application/json" },
"body": "{\"user\":\"admin\",\"password\":\"secret\"}"
}
// Step 2: Access protected resource (session cookies automatically preserved)
{
"url": "https://example.com/api/dashboard",
"session": "agent-crawler-01"
}3. Route Through a SOCKS5 Proxy
{
"url": "https://geo-restricted.example.com",
"proxy": "socks5://user:pass@proxy.example.com:1080",
"impersonate": "safari_26"
}4. Fetching Binary Assets (Images, PDFs)
{
"url": "https://example.com/report.pdf",
"encoding": "base64"
}5. DNS Pinning for SSRF-Safe Ingestion
{
"url": "https://internal-origin.example.com/feed",
"resolve": {
"internal-origin.example.com": "192.0.2.42"
},
"redirect": "manual"
}๐ฌ Impersonation Presets & Fingerprints
@trishchuk/mcp-fetch-server supports a wide range of browser fingerprints:
Chrome:
"chrome_100"โฆ"chrome_149"(e.g."chrome_147","chrome_131","chrome_116")Edge:
"edge_101"โฆ"edge_148"Opera:
"opera_116"โฆ"opera_131"Firefox:
"firefox_109","firefox_133","firefox_147"โฆ, plus"firefox_private_136"and"firefox_android_135"Safari:
"safari_15.3"โฆ"safari_26.4", plus iOS/iPad variants ("safari_ios_26","safari_ipad_26")OkHttp (Android apps):
"okhttp_3.9"โฆ"okhttp_5"Dynamic:
"random","weighted_random"(rotates fingerprints automatically, pinned persession)
Version numbers use underscores (chrome_147, not chrome147). An unknown name fails fast with an
InvalidArg error that lists every accepted variant.
๐งช Development
npm install
npm start # run the server over stdio
npm test # end-to-end smoke tests, no network required
npm run format # format with Biome
npm run lint # lint with Biome
npm run check # format + lint check, also run before publishThe tests spawn the real server over stdio and drive it with an MCP client against a local HTTP server,
covering truncation at the cap, redirect modes, HEAD, base64 bodies, timeouts and transport errors.
๐ License
MIT ยฉ Taras Trishchuk
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Tools
Related MCP Servers
- Alicense-qualityAmaintenanceEnables AI agents to perform undetectable browser automation that bypasses Cloudflare, antibots, and social media blocks. Provides 105 tools for element extraction, network debugging, and real-world web scraping with a 98.7% success rate on protected sites.1,589MIT
- Alicense-qualityCmaintenanceDrop-in MCP replacement for the built-in WebFetch tool. Adds domain-scoped custom HTTP headers via YAML config, with bot-block detection, HTML-to-text extraction, retries, proxies, and prompt-injection sanitization.1MIT
- AlicenseAqualityDmaintenanceContext-aware web fetching for LLMs, providing 7 tools to check page size, fetch with truncation, extract code/sections/links/tables, and paginate large documents.7MIT
- AlicenseAqualityDmaintenanceEnables LLMs to fetch and extract web content as markdown with browser impersonation to bypass basic bot detection.1MIT
Related MCP Connectors
Reliable web access for AI agents: smart HTTP, rotating proxies, and full-browser rendering.
Deterministic AI agent microtools, no accounts/API keys. fetch_extract: 98% token cut. 38 tools.
Web scraping for AI agents. Converts URLs to clean, LLM-ready Markdown with anti-bot bypass.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/x51xxx/mcp-fetch-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server