camofox-browser
Anti-detection browser server for AI agents, powered by Camoufox
Standing on the mighty shoulders of Camoufox - a Firefox fork with fingerprint spoofing at the C++ level.
Built by the team behind jo, a personal AI agent that runs half on your Mac, half on a dedicated cloud machine just for you -- with zero maintenance needed. Available on macOS, Telegram, WhatsApp, and email. Try the beta free ->
Pradeep Elankumaran (@pradeep24) — co-founder and technical CEO at Jo.
git clone https://github.com/jo-inc/camofox-browser && cd camofox-browser
npm install && npm start
# -> http://localhost:9377
Why
AI agents need to browse the real web. Playwright gets blocked. Headless Chrome gets fingerprinted. Stealth plugins become the fingerprint.
Camoufox patches Firefox at the C++ implementation level - navigator.hardwareConcurrency, WebGL renderers, AudioContext, screen geometry, WebRTC - all spoofed before JavaScript ever sees them. No shims, no wrappers, no tells.
This project wraps that engine in a REST API built for agents: accessibility snapshots instead of bloated HTML, stable element refs for clicking, and search macros for common sites.
Features
- C++ Anti-Detection - bypasses Google, Cloudflare, and most bot detection
- Element Refs - stable
e1,e2,e3identifiers for reliable interaction - Token-Efficient - accessibility snapshots are ~90% smaller than raw HTML
- Runs on Anything - lazy browser launch + idle shutdown keeps memory at ~40MB when idle. Designed to share a box with the rest of your stack -- Raspberry Pi, $5 VPS, shared infra.
- Session Isolation - separate cookies/storage per user
- Cookie Import - inject Netscape-format cookie files for authenticated browsing
- File Upload - attach files from a configured upload directory without a native OS dialog
- Proxy + GeoIP - route traffic through residential proxies with automatic locale/timezone
- Structured Logging - JSON log lines with request IDs for production observability
- YouTube Transcripts - extract captions from any YouTube video via yt-dlp, no API key needed
- Search Macros -
@google_search,@youtube_search,@amazon_search,@reddit_subreddit, and 10 more - Snapshot Screenshots - include a base64 PNG screenshot alongside the accessibility snapshot
- Large Page Handling - automatic snapshot truncation with offset-based pagination
- Download Capture - capture browser downloads and fetch them via API (optional inline base64)
- DOM Image Extraction - list `` src/alt and optionally return inline data URLs
- Deploy Anywhere - Docker, Fly.io, Railway
- VNC Interactive Login - log into sites visually via noVNC, export storage state for agent reuse
- OpenAPI Docs - auto-generated spec at
/openapi.jsonand interactive docs at/docs - Structured Extract -
POST /tabs/:tabId/extractwith a JSON Schema that maps properties to snapshot refs viax-ref - Session Tracing - opt-in per-session Playwright trace capture (screenshots + DOM snapshots + network) with API endpoints to list, fetch, and delete trace zips
- Telemetry - automatic anonymized crash/hang telemetry via GitHub Issues. Identifies which sites cause failures and common failure patterns. Private domains are HMAC-hashed, paths/params stripped, tokens/IPs redacted. Opt-out with
CAMOFOX_CRASH_REPORT_ENABLED=false.
Optional Dependencies
| Dependency | Purpose | Install |
|---|---|---|
| yt-dlp | YouTube transcript extraction (fast path) | pip install yt-dlp or brew install yt-dlp |
The Docker image includes yt-dlp. For local dev, install it for the /youtube/transcript endpoint. Without it, the endpoint falls back to a slower browser-based method.
Quick Start
OpenClaw Plugin
openclaw plugins install @askjo/camofox-browser
Tools: camofox_create_tab | camofox_snapshot | camofox_click | camofox_type | camofox_navigate | camofox_scroll | camofox_screenshot | camofox_close_tab | camofox_list_tabs | camofox_import_cookies
Standalone
Run from npm:
npx @askjo/camofox-browser
Or from source:
git clone https://github.com/jo-inc/camofox-browser
cd camofox-browser
npm install
npm start # downloads Camoufox on first run (~300MB)
Default port is 9377. See Environment Variables for all options.
Note: the postinstall script unsets
PLAYWRIGHT_SKIP_BROWSER_DOWNLOADfor itself before fetching the Camoufox binary. Without that override, an exportedPLAYWRIGHT_SKIP_BROWSER_DOWNLOAD=1(common when Playwright is configured to use system Chrome) would silently skip the binary download and crash the server at runtime.External Camoufox executable: set
CAMOUFOX_EXECUTABLE=/path/to/camoufox-binbeforenpm installand when starting the server to skip the bundled download and launch that executable. Compatibility aliases areCAMOUFOX_EXECUTABLE_PATHandCAMOFOX_EXECUTABLE_PATH. This is useful for NixOS paths such as/nix/store/.../camoufox-bin; the executable must come from a Camoufox bundle that includesproperties.json,version.json, andfontconfig/.Air-gapped or custom binary management: prefer
CAMOUFOX_EXECUTABLEwhen you already have a Camoufox bundle. Otherwise disable the auto-fetch withnpm install --ignore-scripts(skips lifecycle scripts for every dependency -- bluntest option) or, more surgically,npm install --omit=optionalplus a manualnpx camoufox-js fetchstep against your mirror. Note thatPLAYWRIGHT_SKIP_BROWSER_DOWNLOAD=1 npm installno longer skips the Camoufox download (the postinstall sanitizes the env locally); use--ignore-scriptsorCAMOUFOX_EXECUTABLEfor that.
Docker
The included Makefile auto-detects your CPU architecture and pre-downloads Camoufox + yt-dlp binaries outside the Docker build, so rebuilds are fast (~30s vs ~3min).
# Build and start (auto-detects arch: aarch64 on M1/M2, x86_64 on Intel)
make up
# Stop and remove the container
make down
# Force a clean rebuild (e.g. after upgrading VERSION/RELEASE)
make reset
# Just download binaries (without building)
make fetch
# Override arch or version explicitly
make up ARCH=x86_64
make up VERSION=135.0.1 RELEASE=beta.24
Windows
On Windows, make is not available. Use the included build.ps1 PowerShell script instead:
# Build and start
.\build.ps1 up
# Stop and remove the container
.\build.ps1 down
# Build image only
.\build.ps1 build
# Force a clean rebuild
.\build.ps1 reset
# Download binaries only (without building)
.\build.ps1 fetch
# Override architecture
.\build.ps1 up -Arch x86_64
.\build.ps1 up -Arch aarch64
Note: PowerShell 7+ (
pwsh) is recommended butpowershell.exe(Windows PowerShell 5.1) also works. The script requires Docker Desktop for Windows with the WSL2 backend.Line endings: This project includes a
.gitattributesfile that forces Unix (LF) line endings for.shfiles. If you've already cloned the repo and getsh: not foundorset: Illegal option -errors duringdocker build, run:Get-ChildItem -Recurse *.sh | ForEach-Object { (Get-Content $_) -join "`n" + "`n" | Set-Content $_ -NoNewline }This converts shell scripts to LF line endings. Future clones will handle this automatically thanks to
.gitattributes.
WARNING: Do not run
docker builddirectly. The Dockerfile uses bind mounts to pull pre-downloaded binaries from `

