26+
antibot vendors detected automatically
4
signal layers - headers, cookies, JS, TLS
100%
local detection - no data leaves your browser
Free
open source, NPOSL-3.0, always free
Every Major Antibot, Identified on Sight
Headers, cookies, JS challenges, and TLS fingerprints - analyzed together for a confident match.
Detection Pipeline
Point the detector at any URL. It fetches the target with a real browser profile, collects evidence across four signal layers, and matches the fingerprint against known vendor signatures. Result: vendor name, confidence score, matched signals, and a recommended bypass path - all in one response.
Multi-Layer Signal Analysis
Detection evaluates four independent evidence layers. A single cookie name may indicate a vendor; header plus cookie plus JS challenge pattern is a confident match. Confidence is scored per layer and combined.
cf-ray, x-kasada-pow, server
cf_clearance, _abck, datadome
Chrome Extension
Install once. Detection runs passively on every page load and shows a badge on the toolbar icon. Click for a full breakdown with confidence scores and the exact signals that triggered each match.
REST API Endpoint
Call the same detection engine from a script, CI job, or scraper bootstrapper. POST /classify takes a response you already fetched and returns whether it is a block page, plus the anti-bot vendor that matched.
Browser Fingerprinting Exposure
Beyond vendor detection, the extension exposes which browser fingerprinting surfaces a target site reads - Canvas, WebGL, AudioContext, WebRTC, and more. Useful for privacy research, browser-hardening audits, and understanding what stealth a scraper needs.
Open Source
Full source on GitHub under NPOSL-3.0. Submit PRs to add new vendor signatures, improve accuracy, or fix false positives. No black box.
100% Local, Zero Telemetry
All analysis runs in your browser. No browsing history, no URL list, no results are sent anywhere. Verifiable via the public source code.
Detection History
All detections are stored locally in the extension. Browse past results by domain, filter by vendor, and export the dataset for offline analysis or reporting.
Built for Engineers Diagnosing Blocks
The detector is step zero in any scraping workflow that targets a blocked site. Know the vendor, then pick the right tool.
Detect. Then Bypass.
The detector points you to the right tool. Each product below targets the full bypass workflow for a different engineering profile.
Vendor Coverage
The signature database covers the most widely deployed antibot platforms in production use today.
Signal Types
Four independent evidence channels are evaluated and combined. More layers matching the same vendor raises confidence.
Detection Speed
The extension uses a 12-hour domain cache and LRU pattern matching. Repeated page loads cost near-zero compute inside the browser.
Classify Any Response You Already Have
Run the same detection engine over a response you fetched yourself, from any language.
Pass the response you fetched, get back whether it is a block page and which vendor matched. Then see the bypass catalog for the right tool.
import requests
from scrapfly import ScrapflyClient
client = ScrapflyClient(key="API KEY")
# Classify runs on a response you already have - fetch it
# yourself, or replay one from your proxy / cache.
response = requests.get('https://example.com')
result = client.classify(
url='https://example.com',
status_code=response.status_code,
headers=dict(response.headers),
body=response.text,
)
print(result.blocked) # True / False
print(result.antibot) # "cloudflare" | "datadome" | ... | None
import { ScrapflyClient } from 'jsr:@scrapfly/scrapfly-sdk';
const client = new ScrapflyClient({ key: "API KEY" });
// Classify runs on a response you already have - fetch it
// yourself, or replay one from your proxy / cache.
const upstream = await fetch('https://example.com');
const headers: Record<string, string> = {};
upstream.headers.forEach((value, key) => {
headers[key] = value;
});
const result = await client.classify({
url: 'https://example.com',
statusCode: upstream.status,
headers,
body: await upstream.text(),
});
console.log(result.blocked); // true / false
console.log(result.antibot); // "cloudflare" | "datadome" | ... | null
# Classify runs on a response you already have
STATUS=$(curl -s -o page.html -w '%{http_code}' https://example.com)
http POST https://api.scrapfly.io/classify \
key==$SCRAPFLY_KEY \
url=https://example.com \
status_code:=$STATUS \
body=@page.html
Understand Every Antibot You Encounter
Detection is step one. Our docs and guides take you the rest of the way.
API Reference
Full docs for the Classify API: request shape, response schema, SDK examples, and billing.
Developer Docs →Academy
Interactive courses on anti-bot systems, how they work, and how scrapers bypass them.
Start learning →Extension Source
Read the detection rules, contribute new vendor signatures, or fork and customize for your workflow.
View on GitHub →Developer Tools
JA3/JA4 checker, TLS fingerprint inspector, HTTP/2 analyzer, and more - all free in the toolbox.
Browse tools →Seamlessly integrate with frameworks & platforms
Plug Scrapfly into your favorite tools, or build custom workflows with our first-class SDKs.
Agent skills
LLM & RAG frameworks
Frequently Asked Questions
What is Antibot Detector?
Antibot Detector is a free Chrome extension and REST API tool that identifies which antibot system protects a given website. It analyzes response headers, cookie names, JavaScript challenge patterns, and TLS fingerprints to name the exact vendor - Cloudflare, DataDome, Akamai, PerimeterX, Kasada, Imperva, F5, AWS WAF, and 18+ more.
Does it collect or send any of my browsing data?
No. All detection runs locally inside your browser. The extension does not send browsing history, URLs, or analysis results to any external server. You can verify this claim by reading the open source code on GitHub.
Is it really free?
The Chrome extension is free for personal and non-profit use under the NPOSL-3.0 license. The REST API is a paid Scrapfly endpoint: POST /classify costs 1 API credit per successful call, and errors are not billed. Commercial redistribution of the extension requires a separate license.
How does it detect Cloudflare vs DataDome vs others?
Each antibot vendor leaves characteristic traces. Cloudflare sets a cf-ray header and a cf_clearance cookie. DataDome injects a datadome cookie and a specific interstitial redirect. Akamai's sensor data collection script has a distinctive URL pattern. Kasada sends a x-kasada-pow challenge header. The detector checks all known signals in parallel and returns a confidence-scored match.
Can I use the detector in a CI pipeline or automated script?
Yes, through the Classify API. Fetch the target with your own client, then POST the response to /classify with its url, status_code, headers, and body. You get back blocked and the antibot vendor that matched. Because you supply the response, the verdict reflects the exact session your scraper got, not a separate Scrapfly fetch.
What should I do after I detect an antibot?
Use Scrapfly's Web Scraping API with unblocker=true. The same engine that powers the detector also tells the Scrapfly Unblocker (formerly ASP) which bypass strategy to apply - the correct TLS fingerprint, proxy pool, and challenge-handling path for that specific vendor.
Does it slow down my browser?
No noticeable impact. The extension uses a 12-hour domain cache and an LRU pattern cache that reduces redundant work by 60-80%. Detection runs asynchronously after page load, never blocking rendering.
Free tool. Real bypass power one step away.
Antibot Detector identifies what you are up against - always free. When you are ready to bypass it, Scrapfly's
Web Scraping API handles Cloudflare, DataDome, Akamai, PerimeterX, and more with a single unblocker=true flag.
Start with 1,000 free credits, no credit card required.
Once you know the antibot, bypass it.
Antibot Detector tells you what you are up against. The Scrapfly stack handles the rest: Web Scraping API for one-call bypass, Unblocker when access is the only problem, Browser API for JS-heavy targets, Scrapium for stealth Chromium you drive directly, Curlium for byte-perfect HTTP, Extraction API for structured output. See the full bypass catalog with per-vendor guides for Cloudflare, DataDome, Akamai, and more.