Back to Browse

Fetch MCP Server

Developer ToolsLow Risk10.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

Drop-in fetch MCP: clean Markdown from any URL, with JS rendering and anti-bot.

About

Drop-in fetch MCP: clean Markdown from any URL, with JS rendering and anti-bot.

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (2 strong, 0 medium validity signals). No known CVEs in dependencies. Package registry verified. Imported from the Official MCP Registry.

6 files analyzed · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

file_system

Check that this permission is expected for this type of plugin.

Shell Command Execution

Runs commands on your machine. Be cautious — only use if you trust this plugin.

What You'll Need

Set these up before or after installing:

30000Optional

Environment variable: FETCHMCP_TIMEOUT_MS

2Optional

Environment variable: FETCHMCP_MAX_RETRIES

unsetOptional

Environment variable: FETCHMCP_ALLOW_PRIVATE_IP

unsetOptional

Environment variable: FETCHMCP_FLARESOLVERR_URL

unsetOptional

Environment variable: FETCHMCP_SKIP_BROWSER_DOWNLOAD

unsetOptional

Environment variable: FETCHMCP_PREINSTALL_BROWSER

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-labtools-studio-fetchmcp": {
      "args": [
        "-y",
        "@labtoolsstudio/fetchmcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

fetchmcp

A drop-in replacement for the official fetch MCP that actually works on modern web pages.

npm node license PRs welcome

The official fetch MCP is broken on JavaScript-heavy pages, truncates output at 5,000 characters, and ships an unpatched SSRF vulnerability. fetchmcp returns clean, LLM-ready Markdown from any URL — rendering JavaScript when needed, passing basic bot protection without paid proxies, and telling you honestly when a page is blocked instead of hallucinating content. npx and go.

Before and after: the official fetch MCP returns an empty SPA shell, fetchmcp returns clean Markdown

// Replace the official fetch server with this — one line in your MCP config:
"fetchmcp": { "command": "npx", "args": ["-y", "@labtoolsstudio/fetchmcp"] }

Add to Cursor   Install in VS Code

Why switch

official fetchfetchmcp
JavaScript pages❌ empty / broken✅ auto-renders in a real browser
Output length✂️ truncated at 5,000 chars✅ full page, with paging
Bot protection (403 / Cloudflare)❌ fails silently✅ passes mid-tier walls, no paid proxy
Blocked page❌ returns the CAPTCHA as "content"✅ honest typed error, never fakes it
SSRF safetyCVE-2025-65513 (CVSS 9.3)✅ private/metadata IPs refused by default
Costfreefree, self-hosted, $0

Install

Add to your MCP client config (claude_desktop_config.json, Cursor mcp.json, Cline, etc.):

{
  "mcpServers": {
    "fetchmcp": {
      "command": "npx",
      "args": ["-y", "@labtoolsstudio/fetchmcp"]
    }
  }
}

The install is light — no browser is downloaded up front, and static reading (fetch → Readability → Markdown) works immediately. The first time a page actually needs JavaScript, fetchmcp downloads a stealth Chromium once (~150 MB) automatically, then renders it — still zero-config. To pre-download it at install time, set FETCHMCP_PREINSTALL_BROWSER=1. To stay static-only and never download it, set FETCHMCP_SKIP_BROWSER_DOWNLOAD=1 (JS pages then return an honest needs_js).

Tools

read_url

Fetch any web page as clean Markdown.

argtypedescription
urlstringthe URL to fetch (http/https)
renderbooleanJS rendering: true = always, false = never, omitted = automatic (only for empty SPA shells)
rawbooleanreturn raw HTML instead of Markdown
headersobjectextra request headers, e.g. {"Authorization": "Bearer …", "Cookie": "…"}
max_lengthintegercap characters returned (0 = unlimited, the default)
start_indexintegeroffset for paging through a long page

read_docs

Same engine, tuned for documentation: strips navigation sidebars, headers, and footers so API docs and guides come back as clean reference text. Takes url, render, headers, max_length, start_index.

Honest statuses

fetchmcp never returns a bot wall, an error page, or a truncated shell dressed up as real content. When it can't read a page it says why, with a typed status: blocked (bot protection, with the vendor), blocked_ssrf, needs_js, http_error, timeout, network_error, unsupported_content, or empty.

Configuration (env vars)

vardefaultmeaning
FETCHMCP_TIMEOUT_MS30000per-request timeout
FETCHMCP_MAX_RETRIES2retries on network errors / 429 / 503 (with backoff + Retry-After)
FETCHMCP_ALLOW_PRIVATE_IPunsetset to 1 to allow private/localhost IPs (trusted intranet docs)
FETCHMCP_FLARESOLVERR_URLunsetself-hosted FlareSolverr endpoint for tougher challenges
FETCHMCP_SKIP_BROWSER_DOWNLOADunsetset to 1 for static-only: never download Chromium; JS pages return needs_js
FETCHMCP_PREINSTALL_BROWSERunsetset to 1 to download Chromium at install time instead of on first JS use

Development & testing

npm install          # installs deps (Chromium downloads on first JS use)
npm run build        # compile TypeScript to dist/
npm test             # unit tests (block detection, SSRF) — no network
npm run test:e2e     # live end-to-end suite against real sites

# Poke at any tool/URL by hand — no need to write a script:
node test/probe.mjs read_url  https://example.com
node test/probe.mjs read_url  https://some-spa.example.com --render
node test/probe.mjs read_docs https://docs.python.org/3/library/json.html
node test/probe.mjs read_url  https://api.example.com --header "Authorization=Bearer x" --max-length 500
node test/probe.mjs read_url  https://example.com --full     # print the whole response

test/probe.mjs --help semantics are documented at the top of that file.

How it works

Three tiers, escalating only as needed:

  1. Static — plain fetch → Readability → Markdown. Fast path for most pages.
  2. Browser — lazy patchright (stealth Chromium) when the static HTML is an empty SPA shell, a bot wall, or a 403/429/503.
  3. FlareSolverr (optional) — only if you've configured an endpoint, for challenges the browser can't clear.

Star history

If fetchmcp saved you from one more fetch-returns-nothing moment, a star helps others find it.

Star History Chart

License

MIT — see LICENSE.

Reviews

No reviews yet

Be the first to review this server!