Camofox Browser

Agent-facing Camoufox server for authorized protected-page retrieval. It supplies a real Firefox engine/network shape and browser-property spoofing, but it is a guarded fallback—not a universal bypass or a configurable TLS-fingerprint spoofer.

What It Is

jo-inc/camofox-browser wraps Camoufox, a Firefox fork with browser-property spoofing, behind REST, MCP, OpenClaw, and agent-oriented surfaces. It exposes accessibility snapshots, stable element refs, search macros, sessions, traces, and page-context evaluation. Source: GitHub jo-inc/camofox-browser, reviewed 2026-08-11

The bookmark's durable lesson is that browser speed and CDP compatibility do not solve protected retrieval. Targets can combine TLS/HTTP2 shape, browser and automation fingerprints, IP reputation, rendered challenges, and behavior. The thread's “only one thing matters” TLS claim is too absolute, and current Camoufox source does not expose configurable ClientHello, JA3, or JA4 mutation. It uses a real Firefox engine and network stack while spoofing browser-visible properties at the C++ layer. Call this real Firefox TLS/network shape, not TLS spoofing. Source: X/@leftcurvedev_, 2026-04-09; Source: Camoufox current README and implemented-property inventory, reviewed 2026-08-11

  1. Confirm that access and automation are permitted; record the target, purpose, data owner, rate limit, and retention boundary.
  2. Prefer the official API, licensed export, direct fetch, or a managed extraction service when one answers the job.
  3. Use Browser Testing Skills or the ordinary browser harness for cooperative pages.
  4. Reproduce and classify the failure—transport/protocol, browser properties, automation protocol, IP/reputation, rendered challenge, or behavior.
  5. Pilot Camofox only when its real-Firefox/browser-spoofing lane matches the observed failure. Keep the incumbent as control and record pass/block rate, CAPTCHA rate, latency, cost, and regressions.

Do not use the route for account creation, login abuse, access-control circumvention, or collection that the operator is not authorized to perform.

Stack Fit

Need Start here
Fast ad-hoc browsing, lightweight snapshots, React/perf checks Browser Testing Skills / Lightpanda
Visual QA against the user's real browser Browser Harness - Self-Healing Browser Automation
Structured CI E2E tests Playwright
Authorized protected retrieval where a real Firefox stack and JS execution match the measured failure Camofox Browser / Camoufox pilot
HTTP-only client impersonation where a named browser profile is required and permitted curl_cffi or tls-client, separately evaluated
"I just need the content" on defended sites Cloudflare /crawl Endpoint / Firecrawl Monitoring before hand-rolling stealth

Treat Camofox Browser as a candidate runtime component, not a default dependency. A source screenshot or a successful historical run never establishes current target compatibility.

Required Pilot Configuration

The current server binds all interfaces when CAMOFOX_BIND_HOST is unset, makes its global bearer key optional, persists session state by default, exposes page-context evaluation, and sends crash/hang telemetry by default. A safe local pilot therefore requires:

CAMOFOX_BIND_HOST=127.0.0.1
CAMOFOX_ACCESS_KEY=<strong-random-secret>
CAMOFOX_CRASH_REPORT_ENABLED=false

Also isolate profile, upload, and trace directories; disable persistence/tracing unless the workflow needs them; deny private-network and public ingress at the container/network layer; avoid sensitive authenticated sessions until the threat model is proven; pin the scoped npm package, repository revision, Camoufox/browser build, and artifact digests. A remote deployment needs TLS, network allowlists, secret rotation, and an explicit outbound-address policy—bearer auth alone is not enough.

Versioning

Current source authority checked on 2026-08-11:

Surface Snapshot
Wrapper repo jo-inc/camofox-browser, MIT, af3a2505fc3853e976ad261b2ca0cfc445054d33, 8,493 stars / 899 forks / 52 open issues
Wrapper release/package GitHub v1.13.1, published 2026-08-02; @askjo/camofox-browser@1.13.1
Browser upstream daijro/camoufox, MPL-2.0, f1febf49006a1b2544bcd6fe965146fc63bdcf7a, release v152.0.4-beta.28, 11,006 stars / 943 forks / 120 open issues
JS dependency Wrapper pins camoufox-js@0.11.5; registry latest observed was 0.12.0

The unscoped camofox-browser@2.4.6 is a different package. Use the jo-inc/camofox-browser repo and scoped @askjo/camofox-browser package as authority. Do not infer package identity from a similar name. Source: GitHub and npm registries, captured 2026-08-11

Verification Receipt

  • Frozen wrapper test: six focused suites, 205/205 passed after npm ci --ignore-scripts; the browser-download postinstall was intentionally skipped.
  • Current lock audit: four findings—three high, one moderate, zero critical—in transitive dependencies. Fixes exist, but no upstream lockfile was modified during review.
  • Supply/runtime hold: no global install and no browser binary admission until package, binary, dependency, exposure, telemetry, persistence, trace, network, and target-specific quality gates pass.
  • Full hashes, APIs, release metadata, source boundaries, and visual observations live in .brain/artifacts/x/2042285416624128456/camofox/capture-manifest.md.

Timeline

  • 2026-08-11 | Replayed the complete thread and current wrapper/upstream sources. Corrected “TLS spoofing” to real Firefox network shape, refreshed to wrapper v1.13.1, preserved the scoped-package boundary, ran 205 focused tests, captured the four-finding dependency audit, and added loopback/auth/telemetry/profile/trace/network and target-evaluation gates. Source: replay receipt, 2026-08-11
  • 2026-06-30 | Created after reviewing the local X artifact for @leftcurvedev_'s TLS-fingerprinting thread. Decision: promote Camofox Browser as the concrete anti-detection browser server behind the screenshot, update scraping/browser routing, and keep it candidate-gated because stealth scraping has legal, ToS, and maintenance risk. Source: X/@leftcurvedev_, 2026-04-09; Source: GitHub jo-inc/camofox-browser, 2026-06-30