// PRODUCT

Antibot Detector: identify which protection a site uses

Detect which antibot system protects any website: point it at any URL and instantly identify Cloudflare, DataDome, Akamai, and 20+ more. Chrome extension or REST API, no sign-up required.

Detects Cloudflare, DataDome, Akamai and 20+ more.
Free forever. Open source.

  • Instant signal analysis. Reads response headers, cookie names, JS challenge patterns, and TLS fingerprints to identify the exact antibot vendor protecting a site.
  • Two ways to use it. Install the Chrome extension for passive browser-based detection, or call the REST endpoint from any script or CI pipeline.
1,000 free credits. No credit card required.

26+

antibot vendors detected automatically

4

signal layers - headers, cookies, JS, TLS

100%

local detection - no data leaves your browser

Free

open source, NPOSL-3.0, always free


DETECTION

Every Major Antibot, Identified on Sight

Headers, cookies, JS challenges, and TLS fingerprints - analyzed together for a confident match.

Detection Pipeline

Point the detector at any URL. It fetches the target with a real browser profile, collects evidence across four signal layers, and matches the fingerprint against known vendor signatures. Result: vendor name, confidence score, matched signals, and a recommended bypass path - all in one response.

URL input any target, no sign-up
Probe fetch headers, cookies, body, TLS
Signal match 26+ vendor signatures
Confidence score per matched evidence layer
URL Input target URL submitted via Chrome extension toolbar or REST endpoint
Fetch + Probes HTTP response headers, Set-Cookie names, response body scan, TLS handshake metadata
Fingerprint Signals cf-ray, _abck, datadome cookie, challenge JS src, x-kasada-pow header, sensor script paths
Vendor Match signals scored against 26+ vendor signature sets; highest confidence wins
Confidence + Recommendation vendor name, confidence level, matched signals, link to bypass guide for that vendor
F5
Arkose Labs
Shape Security
Queue-it
Reblaze

View full bypass catalog →

Multi-Layer Signal Analysis

Detection evaluates four independent evidence layers. A single cookie name may indicate a vendor; header plus cookie plus JS challenge pattern is a confident match. Confidence is scored per layer and combined.

Headers cf-ray, x-kasada-pow, server
Cookies cf_clearance, _abck, datadome
JS body challenge scripts, sensor iframe src
TLS JA3/JA4 fingerprint patterns

Chrome Extension

Install once. Detection runs passively on every page load and shows a badge on the toolbar icon. Click for a full breakdown with confidence scores and the exact signals that triggered each match.

Passive runs on every load
12h cache LRU, in-browser only
confidence scores
signal breakdown
per-domain history
export results

Install Extension

REST API Endpoint

Call the same detection engine from a script, CI job, or scraper bootstrapper. POST /classify takes a response you already fetched and returns whether it is a block page, plus the anti-bot vendor that matched.

No refetch classify what you already have
JSON output blocked, antibot, cost
blocked flag
antibot vendor
80+ shields
1 credit / call

View API docs →

Browser Fingerprinting Exposure

Beyond vendor detection, the extension exposes which browser fingerprinting surfaces a target site reads - Canvas, WebGL, AudioContext, WebRTC, and more. Useful for privacy research, browser-hardening audits, and understanding what stealth a scraper needs.

Open Source

Full source on GitHub under NPOSL-3.0. Submit PRs to add new vendor signatures, improve accuracy, or fix false positives. No black box.

NPOSL-3.0license
GitHubopen PRs welcome

View on GitHub →

100% Local, Zero Telemetry

All analysis runs in your browser. No browsing history, no URL list, no results are sent anywhere. Verifiable via the public source code.

In-browserno server calls
Verifiableopen source

Detection History

All detections are stored locally in the extension. Browse past results by domain, filter by vendor, and export the dataset for offline analysis or reporting.

Local storestays in browser
ExportCSV / JSON

Built for Engineers Diagnosing Blocks

The detector is step zero in any scraping workflow that targets a blocked site. Know the vendor, then pick the right tool.

SCRAPERS Diagnose before you code Identify the antibot before building your scraper so you choose the right HTTP client, proxy pool, and fingerprint strategy from the start.
SECURITY RESEARCH Vendor coverage audits Map which antibot stacks appear across a domain portfolio. Export the detection log for reporting or peer review.
CI PIPELINES Pre-scrape gating Call the REST endpoint at pipeline start. If the target changed vendors, route to the correct bypass strategy before any credits are spent.

Vendor Coverage

The signature database covers the most widely deployed antibot platforms in production use today.

26+vendors detected
12major platforms

Signal Types

Four independent evidence channels are evaluated and combined. More layers matching the same vendor raises confidence.

4signal layers
HeadersCookies, JS, TLS

Detection Speed

The extension uses a 12-hour domain cache and LRU pattern matching. Repeated page loads cost near-zero compute inside the browser.

12hdomain cache TTL
Asyncnon-blocking

CODE

Classify Any Response You Already Have

Run the same detection engine over a response you fetched yourself, from any language.

Pass the response you fetched, get back whether it is a block page and which vendor matched. Then see the bypass catalog for the right tool.

import requests
from scrapfly import ScrapflyClient
client = ScrapflyClient(key="API KEY")

# Classify runs on a response you already have - fetch it
# yourself, or replay one from your proxy / cache.
response = requests.get('https://example.com')

result = client.classify(
    url='https://example.com',
    status_code=response.status_code,
    headers=dict(response.headers),
    body=response.text,
)

print(result.blocked)  # True / False
print(result.antibot)  # "cloudflare" | "datadome" | ... | None
import { ScrapflyClient } from 'jsr:@scrapfly/scrapfly-sdk';

const client = new ScrapflyClient({ key: "API KEY" });

// Classify runs on a response you already have - fetch it
// yourself, or replay one from your proxy / cache.
const upstream = await fetch('https://example.com');

const headers: Record<string, string> = {};
upstream.headers.forEach((value, key) => {
  headers[key] = value;
});

const result = await client.classify({
  url: 'https://example.com',
  statusCode: upstream.status,
  headers,
  body: await upstream.text(),
});

console.log(result.blocked);  // true / false
console.log(result.antibot);  // "cloudflare" | "datadome" | ... | null
# Classify runs on a response you already have
STATUS=$(curl -s -o page.html -w '%{http_code}' https://example.com)

http POST https://api.scrapfly.io/classify \
key==$SCRAPFLY_KEY \
url=https://example.com \
status_code:=$STATUS \
body=@page.html

LEARN

Understand Every Antibot You Encounter

Detection is step one. Our docs and guides take you the rest of the way.

API Reference

Full docs for the Classify API: request shape, response schema, SDK examples, and billing.

Developer Docs →

Academy

Interactive courses on anti-bot systems, how they work, and how scrapers bypass them.

Start learning →

Extension Source

Read the detection rules, contribute new vendor signatures, or fork and customize for your workflow.

View on GitHub →

Developer Tools

JA3/JA4 checker, TLS fingerprint inspector, HTTP/2 analyzer, and more - all free in the toolbox.

Browse tools →

// INTEGRATIONS

Seamlessly integrate with frameworks & platforms

Plug Scrapfly into your favorite tools, or build custom workflows with our first-class SDKs.


FAQ

Frequently Asked Questions

What is Antibot Detector?

Antibot Detector is a free Chrome extension and REST API tool that identifies which antibot system protects a given website. It analyzes response headers, cookie names, JavaScript challenge patterns, and TLS fingerprints to name the exact vendor - Cloudflare, DataDome, Akamai, PerimeterX, Kasada, Imperva, F5, AWS WAF, and 18+ more.

Does it collect or send any of my browsing data?

No. All detection runs locally inside your browser. The extension does not send browsing history, URLs, or analysis results to any external server. You can verify this claim by reading the open source code on GitHub.

Is it really free?

The Chrome extension is free for personal and non-profit use under the NPOSL-3.0 license. The REST API is a paid Scrapfly endpoint: POST /classify costs 1 API credit per successful call, and errors are not billed. Commercial redistribution of the extension requires a separate license.

How does it detect Cloudflare vs DataDome vs others?

Each antibot vendor leaves characteristic traces. Cloudflare sets a cf-ray header and a cf_clearance cookie. DataDome injects a datadome cookie and a specific interstitial redirect. Akamai's sensor data collection script has a distinctive URL pattern. Kasada sends a x-kasada-pow challenge header. The detector checks all known signals in parallel and returns a confidence-scored match.

Can I use the detector in a CI pipeline or automated script?

Yes, through the Classify API. Fetch the target with your own client, then POST the response to /classify with its url, status_code, headers, and body. You get back blocked and the antibot vendor that matched. Because you supply the response, the verdict reflects the exact session your scraper got, not a separate Scrapfly fetch.

What should I do after I detect an antibot?

Use Scrapfly's Web Scraping API with unblocker=true. The same engine that powers the detector also tells the Scrapfly Unblocker (formerly ASP) which bypass strategy to apply - the correct TLS fingerprint, proxy pool, and challenge-handling path for that specific vendor.

Does it slow down my browser?

No noticeable impact. The extension uses a 12-hour domain cache and an LRU pattern cache that reduces redundant work by 60-80%. Detection runs asynchronously after page load, never blocking rendering.


Free tool. Real bypass power one step away.

Antibot Detector identifies what you are up against - always free. When you are ready to bypass it, Scrapfly's Web Scraping API handles Cloudflare, DataDome, Akamai, PerimeterX, and more with a single unblocker=true flag. Start with 1,000 free credits, no credit card required.

Get Free API Key
1,000 free credits. No card.

Once you know the antibot, bypass it.

Antibot Detector tells you what you are up against. The Scrapfly stack handles the rest: Web Scraping API for one-call bypass, Unblocker when access is the only problem, Browser API for JS-heavy targets, Scrapium for stealth Chromium you drive directly, Curlium for byte-perfect HTTP, Extraction API for structured output. See the full bypass catalog with per-vendor guides for Cloudflare, DataDome, Akamai, and more.