@trishchuk/mcp-fetch-server
@trishchuk/mcp-fetch-server
Un servidor de alto rendimiento del Model Context Protocol (MCP) que proporciona una herramienta fetch resistente a bots para agentes de IA (Claude Code, Claude Desktop, Cursor, Windsurf, Cline, Antigravity, etc.).
Desarrollado por @trishchuk/fetch — un cliente HTTP nativo al estilo curl-impersonate que imita con precisión las huellas TLS (JA3/JA4, ClientHello) y HTTP/2 de navegadores reales.
🚀 ¿Por qué este servidor?
Los clientes HTTP estándar de Node.js/Undici son inmediatamente detectados y bloqueados por los sistemas modernos de protección contra bots (Cloudflare Turnstile / Under Attack Mode, DataDome, PerimeterX / HUMAN, Akamai, Kasada, AWS WAF).
Además, las herramientas estándar de recuperación de MCP a menudo fallan con cargas útiles grandes o saturan los contextos de tokens de los LLM.
@trishchuk/mcp-fetch-server resuelve ambos problemas:
Imitación realista de navegadores: Replica suites de cifrado exactas, extensiones TLS, orden ALPN y marcos de configuración HTTP/2 de navegadores modernos (Chrome, Safari, Firefox).
Truncamiento seguro para contextos de LLM: Transmite y limita los cuerpos de respuesta a 2MB (
maxResponseBytes). Las páginas demasiado grandes se truncan limpiamente y se marcan con"truncated": trueen lugar de fallar con errores.Sesiones con estado: Mantiene cookies, estados de inicio de sesión y grupos de conexión a través de múltiples llamadas de herramientas del agente usando el parámetro
session.Codificación inteligente: Detecta automáticamente los tipos MIME y devuelve texto UTF-8 limpio para HTML/JSON/XML o Base64 para archivos binarios (imágenes, PDFs, documentos).
Related MCP server: smart-webfetch-mcp
✅ Requisitos
Node.js >= 24 — requerido por
@trishchuk/fetch.Los binarios nativos precompilados están disponibles para macOS (arm64, x64), Linux (x64/arm64, glibc y musl) y Windows (x64). Otras plataformas no son compatibles con el cliente subyacente.
📦 Instalación y configuración
Opción 1: Ejecutar con npx (sin necesidad de instalación)
Puedes ejecutar el servidor directamente a través de npx:
npx -y @trishchuk/mcp-fetch-serverOpción 2: Instalación global o local
# Global
npm install -g @trishchuk/mcp-fetch-server
# Or clone & install locally
git clone https://github.com/x51xxx/mcp-fetch-server.git
cd mcp-fetch-server
npm install⚙️ Configuración del cliente MCP
Claude Code
Añadir directamente a través de CLI:
# Using npx (recommended)
claude mcp add fetch -- npx -y @trishchuk/mcp-fetch-server
# Or using local path
claude mcp add fetch -- node /path/to/mcp-fetch-server/src/index.jsClaude Desktop
Añadir a tu claude_desktop_config.json:
macOS:
~/Library/Application Support/Claude/claude_desktop_config.jsonWindows:
%APPDATA%\Claude\claude_desktop_config.jsonLinux:
~/.config/Claude/claude_desktop_config.json
{
"mcpServers": {
"fetch": {
"command": "npx",
"args": ["-y", "@trishchuk/mcp-fetch-server"]
}
}
}Cursor / Windsurf / Antigravity (.mcp.json)
Crear o actualizar .mcp.json en tu espacio de trabajo:
{
"mcpServers": {
"fetch": {
"command": "npx",
"args": ["-y", "@trishchuk/mcp-fetch-server"]
}
}
}🛠️ Referencia de la herramienta: fetch
Parámetros de entrada
Parámetro | Tipo | Por defecto | Descripción |
|
| obligatorio | URL absoluta objetivo (p. ej. |
|
|
| Método HTTP ( |
|
|
| Encabezados de solicitud como pares clave-valor ( |
|
|
| Cuerpo de la solicitud enviado como cadena UTF-8 (JSON, codificado en formulario, texto sin formato). |
|
|
| Preajuste de huella de navegador (p. ej. |
|
|
| SO declarado: |
|
|
| URL de proxy: |
|
|
| ID de sesión para compartir conexiones de cliente y contenedores de cookies entre múltiples llamadas. |
|
|
| Fijación DNS personalizada (p. ej. |
|
|
| Modo de redirección: |
|
|
| Forzar versión del protocolo: |
|
|
| Versión mínima de TLS: |
|
|
| Versión máxima de TLS: |
|
|
| Tiempo de espera total de la solicitud en milisegundos. |
|
|
| Límite del cuerpo en bytes (máx. 2MB). Las respuestas que excedan esto se truncan de forma segura. |
|
|
| Formato de devolución del cuerpo: |
Esquemas de respuesta
1. Intercambio HTTP exitoso
Cualquier transferencia HTTP completada devuelve un resultado JSON estándar (incluyendo 404, 500 o 3xx bajo redirect: "manual"):
{
"status": 200,
"statusText": "OK",
"ok": true,
"url": "https://example.com/data",
"redirected": false,
"headers": {
"content-type": "application/json; charset=utf-8",
"cache-control": "max-age=3600"
},
"bodyEncoding": "text",
"body": "{\"message\": \"Hello world\"}",
"truncated": false
}2. Fallo de red / transporte
Si la conexión de red falla, se agota el tiempo de espera o la URL no es válida, la herramienta devuelve isError: true:
{
"error": true,
"code": "TIMEOUT",
"message": "failed to read response body: request or response body error: operation timed out"
}💡 Ejemplos de uso para agentes
1. Evasión de detección de bots en un objetivo protegido
{
"url": "https://protected-site.com/products",
"impersonate": "chrome_147",
"platform": "macos",
"headers": {
"Accept-Language": "en-US,en;q=0.9"
}
}2. Raspado de múltiples pasos con sesión persistente (contenedor de cookies)
// Step 1: Login / Obtain Session Cookie
{
"url": "https://example.com/api/login",
"method": "POST",
"session": "agent-crawler-01",
"headers": { "Content-Type": "application/json" },
"body": "{\"user\":\"admin\",\"password\":\"secret\"}"
}
// Step 2: Access protected resource (session cookies automatically preserved)
{
"url": "https://example.com/api/dashboard",
"session": "agent-crawler-01"
}3. Enrutar a través de un proxy SOCKS5
{
"url": "https://geo-restricted.example.com",
"proxy": "socks5://user:pass@proxy.example.com:1080",
"impersonate": "safari_26"
}4. Obtención de activos binarios (imágenes, PDFs)
{
"url": "https://example.com/report.pdf",
"encoding": "base64"
}5. Fijación DNS para ingestión segura contra SSRF
{
"url": "https://internal-origin.example.com/feed",
"resolve": {
"internal-origin.example.com": "192.0.2.42"
},
"redirect": "manual"
}🔬 Preajustes de imitación y huellas
@trishchuk/mcp-fetch-server admite una amplia gama de huellas de navegador:
Chrome:
"chrome_100"…"chrome_149"(p. ej."chrome_147","chrome_131","chrome_116")Edge:
"edge_101"…"edge_148"Opera:
"opera_116"…"opera_131"Firefox:
"firefox_109","firefox_133","firefox_147"…, además de"firefox_private_136"y"firefox_android_135"Safari:
"safari_15.3"…"safari_26.4", más variantes para iOS/iPad ("safari_ios_26","safari_ipad_26")OkHttp (apps Android):
"okhttp_3.9"…"okhttp_5"Dinámico:
"random","weighted_random"(rota las huellas automáticamente, fijado porsession)
Los números de versión usan guiones bajos (chrome_147, no chrome147). Un nombre desconocido falla rápidamente con un error InvalidArg que enumera todas las variantes aceptadas.
🧪 Desarrollo
npm install
npm start # run the server over stdio
npm test # end-to-end smoke tests, no network required
npm run format # format with Biome
npm run lint # lint with Biome
npm run check # format + lint check, also run before publishLas pruebas inician el servidor real a través de stdio y lo manejan con un cliente MCP contra un servidor HTTP local, cubriendo el truncamiento en el límite, modos de redirección, HEAD, cuerpos base64, tiempos de espera y errores de transporte.
📄 Licencia
MIT © Taras Trishchuk
Available Tools
1 toolfetchFetchA
HTTP fetch backed by @trishchuk/fetch: a curl-impersonate-style client that emulates a real browser TLS/HTTP2 fingerprint (JA3/JA4, ClientHello, ALPN) so requests are not flagged by fingerprint-based bot detection (Cloudflare, DataDome, PerimeterX, etc.) the way Node's default HTTP client is. Use it for GET/POST/etc. against sites that block or challenge plain scrapers.
| Name | Required | Description | Default |
|---|---|---|---|
| url | Yes | Absolute URL to request. | |
| body | No | Request body, sent as UTF-8 text (e.g. JSON string, form-encoded string). | |
| proxy | No | Proxy URL: http://, https://, or socks5://, optionally with user:pass@. | |
| method | No | HTTP method. | GET |
| headers | No | Request headers. | |
| resolve | No | Hostname-to-IP pinning, e.g. { "example.com": "192.0.2.1" }. Useful to pin DNS for SSRF-safety or A/B hosts. | |
| session | No | Opaque session id. Reusing it across calls keeps the same underlying client and cookie jar (e.g. to stay logged in). | |
| encoding | No | How to return the body: "auto" picks text for text-like content-types and base64 otherwise. | auto |
| platform | No | Declared OS for the fingerprint. | |
| redirect | No | Redirect handling. Defaults to "follow". | |
| timeoutMs | No | Request deadline in milliseconds. | |
| httpVersion | No | Force HTTP/1.1 or HTTP/2 instead of negotiating. | |
| impersonate | No | Browser fingerprint profile, e.g. "chrome_147", "safari_26", "random". Defaults to the library default. | |
| tlsMaxVersion | No | ||
| tlsMinVersion | No | ||
| maxResponseBytes | No | Response body cap in bytes (max 2097152, i.e. 2MB, to keep tool output usable). A larger body is truncated to this size and flagged with "truncated": true, not rejected. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description discloses the critical behavioral trait of browser fingerprint emulation (JA3/JA4, TLS, HTTP/2) to avoid detection. Without annotations, this provides transparency about why requests succeed. However, it does not mention whether the tool is read-only or has side effects, though HTTP fetch is inherently non-destructive to local state.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is extremely concise: two sentences that front-load the core purpose and differentiator, followed by usage guidance. Every sentence serves a purpose, and there is no redundancy or filler.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool has 16 parameters, no annotations, and no output schema, the description is somewhat incomplete. It does not explain what the tool returns (e.g., status code, headers, body format) or that the response is a standard HTTP response. While the schema covers some constraints like maxResponseBytes, the agent lacks clarity on what to expect after invocation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 88%, so the input schema already documents most parameters. The description adds general context about the underlying library and fingerprinting motivation but does not provide additional details on individual parameters beyond what schema descriptions offer. The baseline of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly identifies the tool as an HTTP fetch client with browser fingerprint emulation to bypass bot detection. It specifies the verb 'fetch', the resource (URLs), and the unique value proposition (curl-impersonate style). This distinguishes it from standard HTTP clients and makes its purpose immediately obvious.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly states when to use the tool: 'against sites that block or challenge plain scrapers'. It contrasts with Node's default HTTP client, implying an alternative. However, it does not list explicit sibling tools or provide when-not-to-use guidance, such as for sites without bot detection.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
v0.1.0- First observed
fetch
TDQS
Scored across 1 tool
With only a single tool, there is no possibility of confusion with other tools. The tool's purpose is clearly described and distinct by default.
With only one tool, there is no pattern to judge. The name 'fetch' is simple and conventional, matching common HTTP client terminology, but the lack of a verb_noun convention is neutral.
A single tool for an HTTP fetch server is too minimal. Most similar servers would include additional tools for managing headers, cookies, or caching, making this feel under-scoped for its stated purpose of scraping.
The server only provides a basic fetch tool with no support for managing sessions, handling redirects, managing cookies, or performing other common HTTP operations. This leaves significant gaps for any realistic scraping workflow.
Maintenance
Related MCP Connectors
Reliable web fetching for AI agents with retry, circuit breaker, caching, and anti-bot bypass
Reliable web access for AI agents: smart HTTP, rotating proxies, and full-browser rendering.
Prompt-injection scanning and safe webpage fetching for AI agents reading untrusted content.
Web search, browser automation, scraping, crawling and CAPTCHA solving for AI agents.
Related MCP Servers
- AlicenseNot gradedqualityAmaintenanceEnables AI agents to perform undetectable browser automation that bypasses Cloudflare, antibots, and social media blocks. Provides 105 tools for element extraction, network debugging, and real-world web scraping with a 98.7% success rate on protected sites.2,220MIT
- AlicenseAqualityDmaintenanceContext-aware web fetching for LLMs, providing 7 tools to check page size, fetch with truncation, extract code/sections/links/tables, and paginate large documents.7MIT
- AlicenseAqualityDmaintenanceEnables LLMs to fetch and extract web content as markdown with browser impersonation to bypass basic bot detection.1MIT
- AlicenseNot gradedqualityDmaintenanceProvides AI agents with reliable web fetching capabilities, handling retries, caching, and anti-bot bypass automatically.MIT