Skip to main content

Tilion — a stealth browser for AI agents

mcp-name: io.github.tiliondev/fortress

pip install tilion — drive a real, undetected Chromium that gets past Cloudflare, DataDome, and bot detection. No server, no account, no API key.

PyPI Python MCP engine

Framework & MCP: Beta · runs local & free · Tilion Cloud (residential egress) coming soon

Same site, same prompt: a vanilla browser is blocked by PerimeterX while an agent with the Tilion MCP returns clean JSON

Real, dated run against stockx.com (PerimeterX). A stock browser gets HTTP 403 — "Access denied"; an agent with the Tilion MCP returns clean JSON — same site, same prompt.

Tilion runs a recompiled-Chromium stealth engine (Fortress) locally, in-process, and gives you one clean API for fetching protected pages, extracting content, crawling sites, reconnaissance, and multi-step automation — plus a Model Context Protocol (MCP) server so AI agents can reach for it the moment they get blocked.

pip install tilion

Quickstart

import asyncio
from tilion import Tilion

async def main():
    async with Tilion() as t:                                 # boots Fortress locally
        page = await t.fetch("https://protected.example")     # past Cloudflare/DataDome/403
        print(page["title"], page["text"][:200])

        data = await t.extract("https://site/pricing")        # clean markdown + tables
        docs = await t.crawl("https://site", depth=2)         # whole-site crawl (auto-SPA)
        apis = await t.recon("https://site")                  # discover the site's private API
        hits = await t.search("undetected playwright")        # real-browser web search

asyncio.run(main())

No uvicorn, no Redis, no auth — local mode holds one real browser and drives it directly.

Drop-in stealth for your existing stack

Already on browser-use, Playwright, Puppeteer, or Crawl4AI? They connect to a browser by CDP URL. Point that at Tilion and your code runs through the stealth engine — one line, no rewrite:

t = await Tilion().start()
cdp_url = t.cdp_url                       # hand this to any CDP-speaking stack

from browser_use import Agent, BrowserSession
agent = Agent(task="...", browser_session=BrowserSession(cdp_url=cdp_url))

MCP server — stealth browsing for any AI agent

pip install "tilion[mcp]"
tilion-mcp                                # or:  npx -y tilion-mcp

Claude Desktop / Cursor / Cline / Windsurf — add to the MCP config:

{ "mcpServers": { "fortress": { "command": "tilion-mcp" } } }

Claude Code (CLI): claude mcp add fortress -- tilion-mcp

26 tools: fetch_protected_page, extract_page, crawl_site, recon_site_apis, search_web, run_browser_task, save_page, save_profile, get_stealth_cdp_endpoint, and more — pre-warmed (~100 ms first call), concurrency-safe, timeout- and SSRF-guarded. Full tool table →

What you get

fetch stealth GET past Cloudflare/DataDome/403 + auto challenge-resolve
extract page → clean markdown + tables + metadata (or a schema-shaped record)
crawl / spa_crawl whole-site crawl, auto-handles SPA/JS + lazy-load → sitemap
recon reverse-engineer a site's private XHR/JSON API (secret-scrubbed)
search real-browser web search (no SERP API)
agent 20 multi-step flows: login, paginate, infinite-scroll, checkout, downloads…
screenshot / save PNG, or export as PDF / HTML / text
cdp_url raw CDP endpoint for browser-use / Playwright / Puppeteer

How stealth works

The engine is a recompiled Chromium C++ fork (shipped as the tilion-fortress dependency), not a JS patch or a stealth plugin. Persona, User-Agent, WebGL, and canvas fingerprints are applied natively with genuine binding returns (toString() === [native code]), so there are no JavaScript injection tells. In independent suites it runs Sannysoft-clean, CreepJS 0% headless, BrowserScan "Normal."

Honest note: a great fingerprint on a datacenter IP still gets blocked by the biggest sites — real anti-bot decisions weigh the egress IP heavily. For hostile targets, add a residential proxy or use hosted Tilion cloud egress (coming soon). Tilion does not claim to be "undetectable."

Install options

pip install tilion              # core: stealth browser + fetch/extract/crawl/recon/search
pip install "tilion[mcp]"       # + the MCP server
pip install "tilion[vision]"    # + LLM-driven agent (Claude/OpenAI/Gemini)

Links

Open-core: the tilion facade + MCP are BSD-3; the engine (tilion.core driver + the Fortress binary) is proprietary. Requires Python 3.10–3.13 on Linux, macOS, or Windows.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

tilion-0.1.14-py3-none-any.whl (612.3 kB view details)

Uploaded Python 3

File details

Details for the file tilion-0.1.14-py3-none-any.whl.

File metadata

  • Download URL: tilion-0.1.14-py3-none-any.whl
  • Upload date:
  • Size: 612.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.10

File hashes

Hashes for tilion-0.1.14-py3-none-any.whl
Algorithm Hash digest
SHA256 dc750a9cd7322462fe5ffe42e37ee2a33deadcd3655a32198f2796fa5d525118
MD5 d437c0d7783da5b04f3c9f8d72de8726
BLAKE2b-256 921bd98d5ac2022eca115261543f961c6184950f642e14a5623b5a120d70bf4a

See more details on using hashes here.

Release history Release notifications | RSS feed

This release

0.1.14 This release

1 file

0.1.12

4 files

0.1.11

4 files

0.1.10

4 files

0.1.9

4 files

0.1.8

4 files

0.1.7

4 files

0.1.6

4 files

0.1.5

4 files

0.1.4

4 files

0.1.3

4 files

0.1.2

4 files

0.1.1

4 files

0.1.0

4 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page