Skip to main content
Glama

solvegate-mcp

MCP-сервер, который позволяь агенту рабодаться с Cloudflare Turnstile: провеverять, есть ли он на странице, и решать его, если есть.

Три инструмента. Один из них не требует аккаунта.

Инструмент

Что делает

Нужен ключ

Оspect_page

Загружает URL and сообщet, is there a Cloudflare Turnse.sub on it: its sitekey, how it renders, configuration data-*, and is ли страницаыест WAF-Coldstock, а не виджет.

Нет

solve_turnstile

Решает Turnse или WAF-челжендж Turnse and return token.

Yes

get_solve

Достаёт решение по id — бесплатно, повторного списания не происходаит.

Yes

Установка

npx solvegate-mcp

Claude Desktop / and люМCP-клиент, в своей конфигурации:

{
  "mcpServers": {
    "solvegate": {
      "command": "npx",
      "args": ["-y", "solvegate-mcp"],
      "env": { "SOLVEGATE_API_KEY": "sk_test_…" }
    }
  }
}

SOLV_AAPI_KEY can not be set in the config, and inspect_page still works. This is intentional: you should be able to see what the server does on to decide writing for something.

There is a key at solvegate.io: Key at solvegate.io. Beсплатный песочный key sk_test_ does not require kanдэтy, but returns детерминированый токен yielding: it подходит для настройки, and it does not opensolve real.

Related MCP server: cloudscraper-mcp

Why source/check_exists

The most common error with a sol: is to call it when someone would have to first understand. Three cases cover most:

  • Page — with reCAPTCHA or hCaptcha, not Turnseite. That's done from different vendors. This serent not solve them, and SolveGate as well — inspect_page reported by названием of error, or you won't find it from 422.

  • It is WAF-challienge, not widget. A полностраничный Widget Cloudflare interstitial has no data-sitekey, because the challenge is owned by the zone rule, rather than the widget that you embed. To read with the page nothing, and the gate classes waf, / не turnstile.

  • The sitekey is drawn from the script after loading. In this case on the output from HTML its not at all, and the tool reports it, but does not have it.

Inspect_ is free, takes one second, and quite often is the entire answer.

Request what not our statement da

Wikite widget. Managed, non-interactive and invisible хранятся in the видиidget inside the accounts Cloudflare, whom owns the sitekey. Стresent not только key, so no insеnt cannot read the mode by "source code — in that the servers and its algorithms, who claims opposite.

This does not affect решение: all three mode svодится к одностому write. The input sitekey and page URL, output токen.

The exception is five documented in the Cloudflare dummy key. Sitekey, whose type of widget publishes along with Cloudflare. inspect_page сообщастookup in test on the page is useful: you look at the run-breeds, not at product.

Config

| Перемной | По обыч | What | --------- | ----------- | --------- | | SOLVE_ATE_API_KEY | — | Your keyai. sk_test_ — check the sandbox, sk_live — for feature. | SOLVE_ATE_BASE_URL | https://api.solvegate.io | Base URL API. | | SOLVCEGATE_SITE_URL | https://solvegate.io | Will the addresses inspect_page runs the check. | | SOLVEGATE_ME_MS | 30000 | Time out запроbo. | | SOLVEGATE_MAX_WAIT_MS | 60000 | For a long time solve_turnstile waits for the decision failing. |

The key, read the environment and never happens to the argument instrement: argument instrement is visible in the model and обрате у транспорт "transcripts."

The key is readable from the environment and never the argument tool argument: tool argument argument is visible and translated in transport.

The decision is asynchronous under the cover. solve_turnstile creates the resolve from async: true and polls it, in order to keep a connection for a whole attempt. From agent's call tool the tools have a timeout that not agent up-to-date; synchronous solution perhaps a slow gate will appear like a missing tool. At that time before you have a time-out no token, the error named is this, but get_solve подxватит "id" — "Yes".

The resolvent is the result, not the exception. The whole timeout gets in isError, with the errors status "the codebalance_empty, unknown_divekey, rate_limited, forbidden_target. The model can work with " last. An error StackTrace не на fine.

Tokens are same and short. expiresAAt — the Unix time in sixty seconds. after the step, Cloudflare does not take the token. The record is just a record. Request the token which is in "down with the upload".

Check the mode earlier than the testify. If the key will sk_test_ return mode: "sandbox" and prophetic token does not solve the real "стольц`; field, is * aimed at the test key in the production config would slip loudly, not quiet.

The --

**By spec: **the possible Pod: edges only which sites, "Which is in the ownership" or "on which "allowed to test". These are try for cross-checking" the tests which are already impossible to disperse, can not "From the testers" not narrow / "the "from" staging/to/by the synthetic testing of a real production. AvailableFor "shortly before" "C from "the "moved "-at the **The** official corrive: denied list, requested 403 forbidden_target` "with no" from that *not" while the "any agent".

The** "**.

The solution

npm install
npm run build
npm test          # spawns the built server and speaks MCP to it
OFFLINE=1 npm test  # skips the two tests that reach the network

The tests run a real stdio-transport not called directly. This is purposely: the scheme that the SDK rejects when "registration" or "a guide" "an "general-in" output" "in stdout` — that it affects the transport, because the *and is a transport" transport — and appears only when "from the "there are no "real" speaks the protocol.

MCPP

MIT.

Available Tools

3 tools
get_solveRetrieve a solve by idA
Read-only

Fetch a solve created earlier. Free — reading never re-bills. Use this when solve_turnstile timed out while still pending: the solve may have finished after the tool gave up, and the id is in that error message. A 404 means no such solve for this API key's workspace.

ParametersJSON Schema
NameRequiredDescriptionDefault
idYesThe solve id, e.g. slv_8Kd2aF9

Output Schema

ParametersJSON Schema
NameRequiredDescription
idYes
modeYes
tokenYes
billedYes
statusYes
summaryYes
errorCodeYes
expiresAtYes

TDQS

A4.7/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already mark it read-only and open-world, but the description adds valuable behavioral context: it is free and never re-bills, and a 404 is scoped to the current API key's workspace. This goes beyond structured metadata without contradicting it.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three concise sentences with no filler. The main purpose is front-loaded, followed by a concrete use case and an error interpretation; every sentence earns its place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a single-parameter retrieval tool with an output schema and safety annotations, the description fully covers when to call it, what the id means, cost implications, and error semantics. Nothing essential is missing for correct invocation.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% and the only parameter, id, is already clearly described with a format example. The description adds the useful hint that the id may come from a timeout error, but does not need to elaborate further since the schema carries the parameter meaning.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Fetch a solve... by id') and distinguishes itself from siblings by describing exactly when it is the right tool. The mention of solve_turnstile and 404 behavior makes its role unambiguous.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly tells the agent when to use this tool: after solve_turnstile times out while the solve is pending, with the id coming from that error message. It also interprets a 404 response, giving clear operational context beyond the schema.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

inspect_pageInspect a page for Cloudflare TurnstileA
Read-only

Fetch a URL and report what its HTML says about Cloudflare Turnstile: whether a widget is present, its sitekey, whether it renders implicitly or via turnstile.render(), the widget's data-* configuration, whether the sitekey is one of Cloudflare's documented test keys, and whether the page is a full-page WAF challenge rather than a widget. Free, no API key required. Use this before solving when the sitekey is unknown. It CANNOT determine the widget's mode (managed / non-interactive / invisible) — that is stored in the Cloudflare account that owns the sitekey and is not in the page at all.

ParametersJSON Schema
NameRequiredDescriptionDefault
urlYesThe page URL to inspect, e.g. https://example.com/login

Output Schema

ParametersJSON Schema
NameRequiredDescription
presentYesTurnstile was found on the page
summaryYesOne line a human can read
finalUrlYes
sitekeysYesSitekeys found, in document order
renderingYes
httpStatusYes
otherCaptchaYesOther CAPTCHA products on the page — we do not solve these
wafChallengeYesThe response is a Cloudflare WAF challenge interstitial
responseFieldPresentYes

TDQS

A4.7/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Beyond the readOnlyHint, it adds meaningful behavioral specifics: it performs an HTML inspection rather than solving a challenge, requires no API key, is free, and has a specific hard limitation around widget mode. These details substantially describe side effects and boundaries beyond annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Although the description is long, each clause delivers a distinct, useful fact: what is fetched, what is reported, cost/auth requirements, usage timing, and a critical limitation. The most important action and resource are front-loaded, and no sentence is slack.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given a single required parameter, an output schema, and annotations, the description covers everything an agent needs: when to call it, what it returns, its constraints, and what it cannot infer. The mitigation of return format details is appropriate.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The schema fully describes the single 'url' parameter with an example, so parameter documentation coverage is 100%. The description does not add much beyond the schema, but the schema already carries the necessary semantic weight. This aligns with the baseline for high schema coverage.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb ('Fetch') and a concrete result ('report what its HTML says about Cloudflare Turnstile') and enumerates exact outputs: widget presence, sitekey, render method, data-* configuration, test keys, and full-page WAF challenge. This clearly separates it from sibling solving/result-retrieval tools.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It explicitly says 'Use this before solving when the sitekey is unknown,' giving a direct invocation condition. It also provides an exclusion: it cannot determine the widget's mode because that data is not in the page, so agents know when this tool is not sufficient.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

solve_turnstileSolve a Cloudflare Turnstile or WAF challengeA

Clear a Cloudflare challenge and return a token. gate is "turnstile" for an embedded widget (there is a data-sitekey in the page) or "waf" for a full-page Cloudflare interstitial. sitekey and url are both required; the url must be the page the challenge actually renders on, because a sitekey is bound to its configured hostnames. Tokens are single-use and expire in minutes — request one at the moment you submit. Failed solves are never billed. Requires SOLVEGATE_API_KEY.

ParametersJSON Schema
NameRequiredDescriptionDefault
urlYesThe page URL the challenge renders on
gateYesWhich challenge type to clear
proxyNoOptional egress proxy URL to solve through
actionNoOptional Turnstile action label, if the widget sets one
sitekeyYesThe target's sitekey, e.g. 0x4AAAAAAA…

Output Schema

ParametersJSON Schema
NameRequiredDescription
idYes
modeYessandbox tokens NEVER clear a real gate
tokenYesSubmit this as the cf-turnstile-response field
billedYes
statusYes
solveMsYes
summaryYes
errorCodeYes
expiresAtYesUnix seconds after which the token is worthless

TDQS

A4.7/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations indicate non-read-only and non-idempotent behavior, and the description adds meaningful operational context: tokens are single-use and expire in minutes, failed solves are never billed, SOLVEGATE_API_KEY is required, and sitekeys are bound to hostnames. This goes well beyond the annotations and clarifies important side effects and constraints.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Four sentences with no filler: purpose is front-loaded, then parameter guidance, then token lifecycle and error/cost behavior. Every sentence adds useful information and the structure is easy to parse.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With an output schema and useful annotations present, the description supplies the critical missing context: token expiry timing, no-billing on failed solves, API key requirement, and hostname binding. Nothing an agent needs to invoke this tool correctly appears to be missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3. The description adds extra semantic value by explaining the `gate` enum values, reinforcing that `sitekey` and `url` are both required, and explaining why `url` must be the actual rendering page. Some parameters like `proxy` and `action` receive no additional description, but the schema already documents them adequately.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific verb-resource pair ('Clear a Cloudflare challenge and return a token') and then defines the two `gate` modes, clearly distinguishing an embedded widget from a full-page interstitial. This makes the tool's purpose immediately understandable and separates it from generic 'solve' tools.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives actionable selection guidance: it explains when to use 'turnstile' versus 'waf', and instructs the agent to request tokens at submission time due to expiry. It does not explicitly name sibling tools as alternatives or state when not to use this tool, so it stops short of full when/when-not guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. 2 tool updatesv0.1.2
    • Changedget_solve6 fields changed
      • removedOutput schema / properties / errorCode / anyOf
        Removed value: -[
        -  {
        -    "type": "string"
        -  },
        -  {
        -    "type": "null"
        -  }
        -]
      • addedOutput schema / properties / errorCode / type
        Added value: +[
        +  "string",
        +  "null"
        +]
      • removedOutput schema / properties / expiresAt / anyOf
        Removed value: -[
        -  {
        -    "type": "number"
        -  },
        -  {
        -    "type": "null"
        -  }
        -]
      • addedOutput schema / properties / expiresAt / type
        Added value: +[
        +  "number",
        +  "null"
        +]
      • removedOutput schema / properties / token / anyOf
        Removed value: -[
        -  {
        -    "type": "string"
        -  },
        -  {
        -    "type": "null"
        -  }
        -]
      • addedOutput schema / properties / token / type
        Added value: +[
        +  "string",
        +  "null"
        +]
    • Changedsolve_turnstile8 fields changed
      • removedOutput schema / properties / errorCode / anyOf
        Removed value: -[
        -  {
        -    "type": "string"
        -  },
        -  {
        -    "type": "null"
        -  }
        -]
      • addedOutput schema / properties / errorCode / type
        Added value: +[
        +  "string",
        +  "null"
        +]
      • removedOutput schema / properties / expiresAt / anyOf
        Removed value: -[
        -  {
        -    "type": "number"
        -  },
        -  {
        -    "type": "null"
        -  }
        -]
      • addedOutput schema / properties / expiresAt / type
        Added value: +[
        +  "number",
        +  "null"
        +]
      • removedOutput schema / properties / solveMs / anyOf
        Removed value: -[
        -  {
        -    "type": "number"
        -  },
        -  {
        -    "type": "null"
        -  }
        -]
      • addedOutput schema / properties / solveMs / type
        Added value: +[
        +  "number",
        +  "null"
        +]
      • removedOutput schema / properties / token / anyOf
        Removed value: -[
        -  {
        -    "type": "string"
        -  },
        -  {
        -    "type": "null"
        -  }
        -]
      • addedOutput schema / properties / token / type
        Added value: +[
        +  "string",
        +  "null"
        +]
  2. 3 tool updatesv0.1.1
    • First observedget_solve
    • First observedinspect_page
    • First observedsolve_turnstile

TDQS

A4.8/5.0
Disambiguation5/5

Each tool serves a distinct purpose: inspect_page reads page HTML, solve_turnstile solves the challenge, and get_solve retrieves a previous result. There is no functional overlap between them, and their descriptions clearly differentiate when to use each.

Naming Consistency5/5

All tool names follow the verb_noun pattern in snake_case: inspect_page, solve_turnstile, get_solve. The pattern is consistent and predictable, making it easy to infer tool behavior from the name.

Tool Count5/5

With only 3 tools, the server remains tightly focused on the Turnstile solving workflow. Each tool is essential and there is no bloat or redundancy, so the count is perfectly matched to the scope.

Completeness5/5

The tool surface covers the full lifecycle: pre-flight inspection (inspect_page), actual solving (solve_turnstile), and post-hoc retrieval (get_solve). This is a complete workflow with no obvious dead ends or missing operations for the stated purpose.

Maintenance

ActivityMaintained
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    D
    maintenance
    Enables AI agents to scrape websites protected by Cloudflare, DataDome, and Akamai, bypassing anti-bot measures to retrieve page content.
    2
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    Provides a real browser that bypasses bot detection (Cloudflare, Turnstile) for AI agents, enabling navigation, clicking, typing, screenshots, and data collection through MCP tools.
    104
    MIT

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/SolveGate/solvegate-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server