The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the AntiBrow listing page.
AntiBrow
The antidetect browser your AI agent can drive.
English | Русский
Kernel-level fingerprint spoofing, driven by the standard Playwright API you already write. Every profile carries a coherent real-device fingerprint — canvas, WebGL, WebGPU, audio, fonts, WebRTC and the protocol layer all agree, because they were sampled from one real machine rather than randomized independently.
This repository holds the open-source SDKs. See Licensing for what is and isn't open.
Python
JavaScript / TypeScript
Both SDKs speak the same on-disk format: a profile created by one is launchable by the other, with the identical fingerprint.
toString / prototype / stack-trace tells for a detector to
find.device_type="android" (deviceType: 'android'
in JS) gives a profile a real phone's identity - mobile client hints, touch input, portrait
screen, mobile GPU - with no device farm and no remote hardware. Real phones ship inside
both packages, so it works on the free tier.http / https / socks5 credentials go inline on
--proxy-server; the engine answers the challenge itself. No helper extension is loaded,
so nothing shows up in chrome://extensions.relay://…?key= is spoken
natively by the engine over a single WebSocket, with every frame sealed under
AES-256-GCM - no plaintext CONNECT line, no SOCKS5 handshake, no local forwarder process.
The relay server is MIT-licensed and self-hostable. See below..fpprofile file and import it on another machine or hand it to someone else.
Cloud sync moves the same payload for you, per profile, when you turn it on.BrowserContext over CDP. No proprietary API to
learn, and existing scripts port over by changing how the browser is launched.reddit/hot and get JSON, instead of a
browser handle and a scraping problem. See below.One command per site, published in a separate repository (antibrow/recipes) and shared by both SDKs, so adding a site is a pull request there rather than a release here.
Covered today: Google, Amazon, Walmart, Reddit, X, Medium, Yelp, Indeed, Hacker News,
DuckDuckGo, GitHub, PyPI, npm, plus exit-IP and fingerprint checks. Several of those answer
a plain scraper with a captcha, which is the point: a recipe runs inside a profile with its
own identity and its own exit IP, and fanout runs the same command on N of them at once.
Recipes are pinned by SHA-256, only reviewed ones run by default, and each one may only
reach the hosts it declares - a request to any other host is blocked.
Want a platform that is not there yet? Sites behind Cloudflare, DataDome, PerimeterX or
Akamai are the ones this layer exists for. Open an issue on the recipes repo, or write one
from its GUIDE.md - the format is a single file with no dependencies.
relay:// is a transport both SDKs accept wherever a proxy URL goes. SOCKS5 and HTTP
CONNECT put a fixed, recognizable handshake on the wire before any of your traffic moves;
this one doesn't. The engine opens a single WebSocket to the relay and speaks an
AEAD-sealed frame protocol inside it - keys derived per connection with HKDF-SHA256, each
frame sealed with AES-256-GCM under a counter nonce - so there is no plaintext CONNECT
line, no SOCKS5 handshake and no fixed-length header to match on. The target hostname
travels inside the sealed frame.
?key= is the relay's 32-byte base64url pre-shared key, and it is what selects the
encrypted protocol - both here and in the exit-IP lookup the SDK runs before launch, so
timezone and WebRTC follow the relay's exit. Leave it out and the URL means the older
plaintext protocol instead, which a relay serves only if its operator turned it on; a
malformed key is refused rather than downgraded.
There is no local forwarder process and no extension - the engine speaks the protocol itself, and the credential never reaches the page's renderer process.
The relay server is a separate MIT-licensed project
(antibrow/relay) and is meant to be self-hosted on a
domain you control: npx antibrow-relay keygen prints the deployment's pre-shared key,
then deploy it as a Cloudflare Worker or run it as a plain Node process and create an
upstream and an account at /admin. The account credential is what goes in the URL above.
A hosted one runs at https://bastion.antibrow.com/.
Two limits worth knowing: a device running TLS inspection sees the WebSocket upgrade and the sealed frames under it (it still finds no proxy-protocol signature, but it sees more than a passive observer does), and domain-category filtering blocks a hostname before any protocol is inspected - which is the reason to host on your own domain rather than a shared default. The frame format, key schedule and threat model are in the whitepaper.
| Python API, options, CLI | python/README.md |
| JavaScript API | js/README.md |
| Vercel AI SDK tools | ai-sdk-tool/README.md · antibrow.com/docs/ai-sdk |
| Runnable examples (Playwright, browser-use, crawl4ai, Scrapling, MCP, Docker) | python/examples/ |
Windows x64, macOS (universal) and Linux x64 / arm64.
Read this before you build on it — the SDK and the engine have different licenses.
LICENSE). Use them anywhere,
including commercially.BINARY-LICENSE.md. In short: you may use it for your own work,
including commercial work, at any company size — but you may not redistribute, resell,
repackage or embed it, and exposing it to third-party customers (bundled, hosted, or
behind your own API) needs a separate OEM/SaaS license.BINARY-LICENSE.md is the authoritative text; the summary above is not a substitute for it.
Automating systems without authorization, credential stuffing and bulk account-creation abuse are prohibited. You are responsible for complying with the terms of the sites you automate and with the law in your jurisdiction.