Back to Browse

Tor MCP Server

Developer ToolsUse Caution4.4MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Route HTTP requests through the Tor network. Rotating exit IPs, .onion support, no body logging.

About

Route HTTP requests through the Tor network. Rotating exit IPs, .onion support, no body logging.

Remote endpoints: streamable-http: https://tor.regiq.in/api/mcp

Security Report

4.4
Use Caution4.4High Risk

tor-mcp is a well-structured MCP server for routing HTTP requests through Tor with appropriate security controls. Authentication via Bearer tokens is properly enforced on the MCP endpoint, rate limiting is implemented, and network permissions align with the server's stated purpose. Minor findings include lenient exception handling in the control port logic and a low-severity logging concern, but these do not materially impact security. Supply chain analysis found 11 known vulnerabilities in dependencies (0 critical, 6 high severity).

7 files analyzed · 16 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

network_websocket

Check that this permission is expected for this type of plugin.

env_vars

Check that this permission is expected for this type of plugin.

process_spawn

Check that this permission is expected for this type of plugin.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

tor-mcp

Route HTTP requests through the Tor network from any MCP-compatible agent.

Live at tor.regiq.in · Free forever · Google sign-in

What it does

Gives Claude Desktop / Cursor / any MCP client four tools:

ToolWhat it does
tor_fetch(url, method?, headers?, body?)HTTP request through Tor; returns status/headers/body
tor_get_exit_ip()Current exit node IP + country (verified via check.torproject.org)
tor_new_circuit()Force a fresh Tor circuit (SIGNAL NEWNYM)
tor_check(url)HEAD probe — is target reachable through Tor?

Honest scope

Tor exit nodes are blocked by Cloudflare on most big-brand sites (Indeed, Google, Amazon, etc.). Use tor-mcp for:

  • Non-Cloudflare sites
  • Geo-hidden fetches (see a site from a random country)
  • .onion services
  • IP-based rate-limit circumvention on APIs that don't blocklist Tor
  • Testing your own site from N different exits

If you need to hit Cloudflare-protected sites, use browser-mcp instead — real Chrome from a fixed Hetzner IP works for most WAFs, and you can layer a residential proxy on top for the rest.

Setup

  1. Sign in with Google at tor.regiq.in
  2. Generate an MCP API key on your dashboard
  3. Add to Claude Desktop / Cursor:
{
  "mcpServers": {
    "tor": {
      "url": "https://tor.regiq.in/api/mcp",
      "headers": {
        "Authorization": "Bearer <YOUR_KEY>"
      }
    }
  }
}

Limits (per API key, free tier)

  • 100 requests/day
  • 30s timeout per request
  • 10 MB response body cap
  • Methods: GET, POST, HEAD only

Higher quotas for aggregators — email shreyas.pavuluri@gmail.com.

Privacy

  • DNS resolves inside Tor (socks5h:// scheme) — no plaintext lookup from our host
  • We log: target host, method, response status, duration, size
  • We never log: full URLs, query strings, request bodies, response bodies, cookies, headers
  • Standard TorBrowser User-Agent sent by default

Self-host

git clone https://github.com/globalion/tor-mcp
cd tor-mcp
cp .env.example .env  # fill in
docker compose up -d --build

Then browse to http://localhost:3021.

License

MIT · Built by Shreyas · Shipped by Globalion

Reviews

No reviews yet

Be the first to review this server!