A headless browser is a real web browser engine, such as Chromium, Firefox or WebKit, that runs without a visible window and is controlled by code.
It loads pages, runs JavaScript and submits forms like a normal browser, but a script decides what to click and type. Developers use headless browsers for automated testing, screenshots, PDF generation and monitoring, usually through libraries such as Playwright, Puppeteer and Selenium. The same libraries can drive a browser with a visible window (“headed”), which is still automation.
Why are headless browsers used for abuse?
Because the engine is real, simple checks such as “does this client run JavaScript?” pass, and the user agent string can say anything. That makes headless browsers a common tool for scripted sign-ups, credential stuffing, scraping behind logins and checkout bots.
How are automated browsers detected?
By checking whether the browser behaves like the one it claims to be: automation artefacts such as navigator.webdriver, traces left by stealth plugins, whether the JavaScript engine matches the claimed browser, and how it renders. The decision should be verified on your server, never trusted from the page.
How Hextner uses it
DetectBT checks eight signal families in the browser, including automation tells, stealth-plugin tells, engine coherence and rendering, and your server verifies the signed token it issues. In our September 2026 lab (against a local worker, not production traffic) it blocked all 13 default and lightly evaded automation setups and headless puppeteer-extra stealth; headed stealth on real Chrome was not caught. The full results are on the DetectBT page.
Related reading
Browse every definition in the glossary.