We configured residential proxies on our MCP server. They did nothing. Six releases later. A developer documented six CrawlForge MCP server releases shipped between September 16 and 27, 2026, after discovering that routing traffic through residential proxies did nothing to bypass Cloudflare bot detection. The releases replaced proxy rotation with a multi-rung escalation ladder — an honest CrawlForge User-Agent fetch, a Chrome-TLS client called impit, and a Camoufox stealth browser with Turnstile clicking and clearance-cookie replay — that charges 2 credits for a plain fetch and 2 + 5 when a stealth rung retrieves the page. "What browser MCP to bypass Cloudflare?" is a live question on r/ClaudeAI, and the honest answer for most of 2026 was: none of them reliably, ours included. In mid-September a bot-detection benchmark we ran against CrawlForge https://www.crawlforge.dev MCP v6.6.2 recommended routing through residential proxies. We configured it. It did nothing. Finding out why turned into six releases in eleven days, and this is the record of what they changed for anyone who needs to scrape a Cloudflare-protected site from an MCP server without pretending to be something they are not. The plain fetch still runs first and still costs 2 credits. What changed is everything that happens after it is refused. | Version | Date | The one-line version | |---|---|---| | v6.7.0 | 2026-09-16 | proxyRotation routes traffic for real; Camoufox stops announcing itself as Chrome | | v6.8.0 | 2026-09-22 | The stealth benchmark becomes npm run bench:stealth ; fingerprint leaks closed; "auto" engine defaults to Camoufox | | v6.9.0 | 2026-09-22 | agent retries a walled page in the stealth browser, 8 credits + 5 per retry that gets the page | | v6.10.0 | 2026-09-25 | Clearance jar: cf clearance , cf bm and datadome cookies replayed to the next stealth context | | v6.11.0 | 2026-09-26 | A Chrome TLS try impit before any browser launches; Turnstile checkbox click on Chromium; escalation audit rows | | v6.12.0 | 2026-09-27 | App-error fallbacks caught as soft blocks; CRAWLFORGE IMPIT=off per deployment | No tool was added or renamed, and no price changed except the agent ceiling, which now depends on what got through. Every line above is drawn from the server's changelog https://www.crawlforge.dev/changelog . Cloudflare scores a request before the page is served, and a Node HTTP client fails that score in three places at once: the IP is a known datacenter range, the TLS handshake does not look like a browser's, and the interstitial needs JavaScript the client will never run. The result is a 403, or a 200 carrying nothing but a challenge shell. Since v5.6.11, scrape has reported that wall as success: false with blocked.vendor naming Cloudflare, DataDome, PerimeterX, Akamai, Amazon or Vercel, whatever the HTTP status, and charged nothing for it. Since v5.9.0, escalate: true has let the same call render the page once in the stealth browser instead of returning the block. The six releases below are what that escalation stage turned into. With escalate: true and the default engine of "auto" , one scrape call now climbs a ladder, and stops at the first rung that returns the page: CrawlForge/