# What is an antidetect browser?

Source: https://kavralab.com/glossary/antidetect-browser/

An **antidetect browser** is a modified web browser that runs many isolated profiles, each presenting a different made-up device: its own screen, fonts, graphics card, timezone, language, cookies and proxy IP. To a website, every profile looks like a separate person, which is why fraud teams treat antidetect traffic as a strong multi-accounting signal.

## How an antidetect browser works

Most antidetect browsers are built on Chromium or Firefox. The vendor patches the browser so that the values a web page can read about the device come from a profile file instead of the real machine. Each profile stores its own cookies, local storage and saved logins, and is usually paired with its own proxy, so the network address changes along with the device.

The operator opens a dashboard, clicks "new profile", and gets what looks like a fresh laptop in another city. Commercial products sell this as a subscription, with team sharing and automation APIs built in.

- **Device values**: screen size, CPU cores, memory, graphics card name, installed fonts, audio and canvas output.
- **Locale values**: timezone, language, geolocation, matched to the proxy's country.
- **Storage isolation**: every profile starts with empty cookies and keeps its own history afterward.
- **Automation hooks**: many products expose profiles to Playwright, Puppeteer or Selenium for scripted work.

## Where antidetect browsers show up in real traffic

Some users are legitimate: agencies managing client ad accounts, affiliate marketers, QA teams testing localized sites, and privacy-minded people. The same features make these tools the default kit for [multi-accounting](https://kavralab.com/solutions/multi-accounting/), [bonus abuse](https://kavralab.com/solutions/bonus-abuse/), fake reviews and ban evasion. An operator can open fifty profiles, pair each with a [residential proxy](https://kavralab.com/glossary/residential-proxy/), and sign up fifty times for the same welcome offer.

Because each profile is internally tidy, basic [device fingerprinting](https://kavralab.com/glossary/device-fingerprinting/) sees fifty different visitors. The problem is not one profile. It is the cluster of profiles run by one person.

## Antidetect browser vs incognito mode

**Incognito or private window**

- Clears cookies when the window closes
- Shows the same real device every time
- Uses your normal network and IP
- One identity at a time, no profiles

**Antidetect browser**

- Keeps separate storage per profile for months
- Shows a different invented device per profile
- Routes each profile through its own proxy
- Hundreds of identities from one machine

## What a profile fakes, and what tends to give it away

Each faked value is easy to set on its own. Keeping all of them consistent with each other and with the real machine is the hard part.

| Layer | What the profile claims | Typical giveaway |
|---|---|---|
| Graphics | A named graphics card and driver | Drawn images match different hardware than the one named |
| Operating system | Windows, macOS or Android | Fonts, rendering and system features belong to another system |
| Locale | Timezone and language of the proxy country | Clock behavior or keyboard layout from somewhere else |
| Network | A home IP in the target city | The IP belongs to a commercial proxy pool |
| Browser build | Stock Chrome or Firefox | Patched functions behave unlike the real release |
| Hardware | A unique machine per profile | Many profiles share the same hidden traits |

## How to detect an antidetect browser

Spoofing every value a page reads is hard to do consistently. A profile may claim a Mac graphics card while drawing images like a Windows machine, or claim a timezone that does not match how the device keeps time. The browser build itself leaves traces that differ from the stock browser it imitates. And the real hardware underneath is shared by every profile on the same laptop.

Kavra checks the network, device, browser integrity and behavior layers against each other on every visit, so a profile that looks clean on one layer is caught by a contradiction on another. Profiles that share hidden hardware are linked into one actor. See [how Kavra detects antidetect browsers](https://kavralab.com/detect/antidetect-browsers/).

## FAQ

### Is it against the rules to use an antidetect browser on a website?

Often, yes. The software itself is legal to download and run, but many platforms ban it in their terms, especially where accounts carry money or rewards: betting sites, marketplaces, ad networks and social platforms. Using it to open extra accounts or claim offers again usually breaks those rules, even when it breaks no law.

### Can websites tell that I am using an antidetect browser?

Often, yes. A website cannot read the product name, but it can notice that the device a profile claims to be does not match how it behaves, that the browser build differs from the stock version, or that many profiles share the same underlying hardware. Detection is strongest when several layers are compared instead of one.

### Do I need a proxy to use an antidetect browser?

Most operators pair each profile with its own proxy, because a profile that fakes a new device but keeps the same home IP address is easy to link. That is why antidetect browsers and [residential proxies](https://kavralab.com/glossary/residential-proxy/) usually show up together in fraud traffic. A [VPN](https://kavralab.com/glossary/vpn/) only changes the network address; the antidetect browser changes how the device appears.

---
Kavra Lab: bot and fraud detection that explains every decision. Book a demo: https://kavralab.com/contact/
