Hextner
VerifIPDetectBTPricingDocsSupport
Sign inStart free →
  1. Hextner
  2. Glossary
  3. Headless browser

What is a headless browser? 

A headless browser is a real web browser engine, such as Chromium, Firefox or WebKit, that runs without a visible window and is controlled by code.

It loads pages, runs JavaScript and submits forms like a normal browser, but a script decides what to click and type. Developers use headless browsers for automated testing, screenshots, PDF generation and monitoring, usually through libraries such as Playwright, Puppeteer and Selenium. The same libraries can drive a browser with a visible window (“headed”), which is still automation.

Why are headless browsers used for abuse?

Because the engine is real, simple checks such as “does this client run JavaScript?” pass, and the user agent string can say anything. That makes headless browsers a common tool for scripted sign-ups, credential stuffing, scraping behind logins and checkout bots.

How are automated browsers detected?

By checking whether the browser behaves like the one it claims to be: automation artefacts such as navigator.webdriver, traces left by stealth plugins, whether the JavaScript engine matches the claimed browser, and how it renders. The decision should be verified on your server, never trusted from the page.

How Hextner uses it

DetectBT checks eight signal families in the browser, including automation tells, stealth-plugin tells, engine coherence and rendering, and your server verifies the signed token it issues. In our September 2026 lab (against a local worker, not production traffic) it blocked all 13 default and lightly evaded automation setups and headless puppeteer-extra stealth; headed stealth on real Chrome was not caught. The full results are on the DetectBT page.

Related reading

  • Credential stuffing
  • Device fingerprint
  • Residential proxy
  • Datacenter IP

Browse every definition in the glossary.

Hextner

Adversarial traffic detection for teams that ship to the open internet.

Product

  • VerifIP
  • DetectBT
  • Pricing
  • Documentation

Company

  • Support
  • Release notes
  • Talk to sales
  • Get an API key
  • Console

Resources

  • Glossary
  • Use cases
  • India

Stay in the loop

Release notes (also as an RSS feed), new signals, and the occasional write-up on how detection actually gets evaded.

Create an account →

This product includes GeoLite Data created by MaxMind, available from https://www.maxmind.com. IP blocklist data: The Spamhaus Project (DROP). Phishing data: PhishTank, CC BY-SA 2.5. Malware data: abuse.ch. Hextner uses the IP2Proxy LITE database for IP geolocation. Full notices: Data sources.

© 2026 Hextner. All rights reserved.
Privacy PolicyTerms of ServiceData sources