Tilda editor MCP server via a Firefox session
tilda-edit-mcp
An MCP server for full Tilda editing directly through the editor API, with no password, using the session from local Firefox
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Uses the user's active browser session, including access to Firefox session-restore data
- Writes changes directly to real pages and can delete blocks with no undo
Install
Manual install
npm installInstalls dependencies after cloning the repository.
This is third-party code. Review the repository files before installing.
What it does
Tilda's public API is read-only, and full write access is only available through the editor's own API, so the server borrows the session of a Firefox browser logged into tilda.ru: it reads persistent cookies from cookies.sqlite and recovers a temporary PHPSESSID from the browser's session-restore file, adding the required origin headers. The agent then gets tools to read and write a block's fields with result verification, read and replace a repeatable block's rows, render a block's HTML, list a page's blocks, show or hide a block, add or delete a block by template ID, change a block's image from a URL or a local file, duplicate a page, rename a page and change its URL path, and publish without a browser. Every write reads the current state, changes only the needed fields, and reverifies the result so other values are not blanked out.
Who it is for. For people running Tilda sites who want to reliably make targeted changes to text, images and blocks without manually clicking through the editor.
Good fit when
- You need to bulk-change copy, colors or typography across several blocks without the risk of it silently reverting
- You want to duplicate a page, edit the copy, and publish a redesign alongside the original
- You want to replace a block's image with a local file the same way the editor's uploader does
Not a fit when
- You are not on Windows: the current version reads the Firefox profile from a Windows-specific path
- The page uses Zero Block, Tilda's free-form builder: the server only supports standard blocks
- You are not comfortable with the risk that Tilda changes its undocumented editor API: a contract test catches breakage, but there is no guarantee
Example request
Duplicate the landing page, change the heading and copy in the first block, then publish the copy under a new URLLimitations
The project has a single author and works only through Tilda's undocumented editor API, which can change without notice. Only Windows is currently supported due to the Firefox profile path, though the author notes the logic ports easily to macOS and Linux. Block deletion is irreversible at the API level. Zero Block is not supported, only standard blocks.
How to disable. Remove the tilda-edit entry from your MCP client config.
MCP
- Transport
- stdio
- Authentication
- not required
| Environment variables | |
|---|---|
| TILDA_FIREFOX_DIR | Path to the Firefox directory, if it is not installed in the default location. |
Security check
- Uses the user's active browser session, including access to Firefox session-restore data
- Writes changes directly to real pages and can delete blocks with no undo
README in short
The README explains in detail why browser automation of the Tilda editor is unreliable and why the server instead calls the editor's network requests directly, gives a full list of block and page tools, a things-learned-the-hard-way section with concrete Tilda API pitfalls, a step-by-step Firefox session recovery mechanism, requirements, installation, a typical workflow, and a warning about Tilda terms-of-service risk.
FAQ
Do I need a Tilda password or API key?
No, the server borrows the session of a Firefox browser already logged into tilda.ru; no password is ever entered or stored.
What if the server says Tilda rejected the session?
Log into tilda.ru in Firefox again and retry; the session is tied to the browser and drops if the account logs out anywhere else.
Related
Official Claude Code plugin from the Next.js repo: adopting Cache Components and Partial Prefetching, and verifying changes on a running dev server
Official shadcn/ui skill and MCP server: the agent searches registries, adds components via the CLI and follows the library's rules
A frontend design skill with 23 commands, live browser iteration and 61 detector rules for common AI-generated UI tells
Vercel Agent Skills
Agent Skills
Vercel's skills: React and Next.js performance, UI guideline audits, React Native, component composition and deploys