Multiple JA4 profiles were observed in the cohort 95/100
Network
Residential network · fresh cohort observed 15 exits across 15 runs; one-network residential classification retained from prior enrichment 86/100
Connection
Cloud browser · CDP
Profile
DefaultMeasured August 23, 2026 with 15 fresh production-scored runs; 12 other attempts failed inside the remote browser during production CDN bootstrap.
Browser HTML + browser actions · default IP selectionMeasured August 23, 2026 from the newest 20 of 26 fresh production-scored runs.
Pricing
Measured Zyte API Stats: $0.0054–$0.0057 per browserHtml + actions request across the 20-run cohort; $0.55 per 100 at the observed $0.005525 mean. Zyte prices by site tier plus action CPU and network usage. ≈ $0.55 / 100 runs
Camoufox Scraper · headful + US residentialMeasured August 25, 2026 with 20 completed production-scored runs from 22 attempts. Two provider-successful Actors never submitted the form before the harness timeout and required top-ups.
Pricing
Finalized usage for 20 successful benchmark sessions: $0.596618 ÷ 20 × 100 = $2.98. Includes Camoufox compute and Apify-managed US residential proxy usage. Excludes $0.083067 from two provider-successful runs that timed out in the harness; including that retry overhead would be $3.40/100. ≈ $2.98 / 100 runs
Cloud Browser · direct CDP + residential poolMeasured August 23, 2026 with 20 fresh production-scored runs using the documented direct Cloud Browser CDP endpoint and residential pool. The separate ASP handoff remained intermittently unavailable and is excluded.
Pricing
Discovery $30/mo: 100 residential Cloud Browser sessions × (2 time credits for 60 seconds + 10 bandwidth credits for 0.5 MB rounded to 1 MB) × $30/200,000 credits. ≈ $0.18 / 100 runs
Extra Stealth · Anchor ProxyMeasured August 23, 2026 from the newest 20 of 23 fresh production-scored runs, with Extra Stealth and Anchor's built-in proxy enabled.
Pricing
Growth-tier infrastructure rates, standardized to 100 successful modeled runs: (100 browser creations × $0.01) + (1.667 browser hr × $0.05) + (0.05 GB Anchor Proxy × $8/GB) = $1.48. Excludes the $2,000/mo Growth plan required for Extra Stealth and excludes retries. ≈ $1.48 / 100 runs
Stealth profileMeasured August 23, 2026 with 20 fresh production-scored runs; one passed harness session that never appeared on the durable score read path was replaced by a verified top-up.
Cloud task API defaultMeasured August 23, 2026 from 20 production-scored runs. The identical 20-run cohort plus one canary consumed 3,900 credits across 130 regular browser actions.
Pricing
Pro $149/mo includes 150,000 credits and residential proxy access: (3,900 credits ÷ 21 successful identical runs) × 100 × ($149 ÷ 150,000) = $18.45. This measured cohort used the one-time Free grant; retries are excluded. ≈ $18.45 / 100 runs
Anti-detect browser with disposable fingerprint profiles and a local automation API.
Run spread
19–20 signals · 6 runs
Transport consistency
No scored transport inconsistencies observed 100/100
Network
Residential · fresh cohort observed 1 Comcast exit across 6 runs; no-proxy, VPN, hosting, relay, Tor, or suspicious-network classification retained from prior enrichment of the same exit 86/100
Connection
Local Docker API · CDP
Profile
Once Profile · Windows + Chrome · headlessMeasured August 23, 2026 with 6 fresh production-scored runs before the account returned exceeded plan limits. The benchmark used direct local residential egress; no NSTbrowser proxy was enabled.
Pricing
Free pay-as-you-go Once Profile rate: $0.004 per launch × 100 runs. Excludes self-hosted Docker compute and optional proxy traffic. ≈ $0.40 / 100 runs
AI web extraction API that renders target pages in a real browser and returns LLM-ready content.
Run spread
19–23 signals · 20 runs
Transport consistency
Multiple JA4 profiles were observed in the cohort 95/100
Network
Datacenter · GCP, 113 exits 30/100
Connection
AI extraction API
Profile
Full-browser render · x-api-keyMeasured August 29, 2026 from production-scored runs. Parallel egresses from cloud datacenter IPs and self-identifies with a crawler user-agent.
StealthMeasured August 23, 2026 with 20 production-scored runs. Kernel Stealth enables the managed anti-detection profile, ISP proxy, and CAPTCHA solver.
No scored transport inconsistencies observed 100/100
Network
Datacenter · Amazon AWS (7 exits) 30/100
Connection
Cloud browser · CDP
Profile
DefaultMeasured August 23, 2026 with 14 fresh production-scored default-profile runs before the account exhausted its free browser-minute quota. Verified and Advanced Stealth require Enterprise access, while managed proxies require a paid plan on this project.
Undetectable cloud browsers on real Windows and mobile devices.
Run spread
20–23 signals · 20 runs
Transport consistency
Multiple JA4 profiles were observed in the cohort 95/100
Network
VPN/tunnel exits · 1 network (20/20 same Fast Servers exit) 55/100
Connection
Cloud browser · patched Playwright CDP
Profile
Undetectable Cloud Browser profile 140594All 27 August 23 refresh and top-up attempts were blocked by HTTP 500 CDP session errors; retaining the June 4 audited cohort.
Pricing
Shared Windows PC: $0.20/hr × 1.667 hr. Optional proxy data is priced separately. ≈ $0.33 / 100 runs
No scored transport inconsistencies observed 100/100
Network
Datacenter · Latitude.sh 30/100
Connection
Cloud browser · CDP
Profile
DefaultMeasured August 23, 2026 with 20 fresh production-scored default-profile runs; network metadata remains curated from the prior enrichment cohort. Steel's managed residential proxy and automatic CAPTCHA solving both require plan entitlements unavailable on the benchmark account, so the combined maximum-stealth mode could not be measured.
Pricing
Starter $29/mo: $0.10/hr × 1.667 hr. Datacenter only (drops to $0.08/100 runs at Pro $499). ≈ $0.17 / 100 runs
Anti-detect browser with managed cloud sessions and persistent profiles.
Run spread
30–31 signals · 20 runs
Transport consistency
No scored transport inconsistencies observed 100/100
Network
Residential proxy · fresh cohort observed 2 exits across 20 runs; residential classification retained from prior enrichment 86/100
Connection
Cloud browser · CDP
Profile
Pre-created cloud profileMeasured August 23, 2026 from the newest 20 of 26 fresh production-scored runs using the stable pre-created profile. One additional attempt failed during cloud startup.
Pricing
Cloud Browser Professional overage: $0.09/hr × 1.667 hr; an active subscription is required. ≈ $0.15 / 100 runs
Universal source · JS renderAll 20 August 23 refresh attempts returned HTTP 401 from the provider API despite configured credentials; retaining the June 3 audited cohort.
Pricing
Web Scraper API Micro $49/mo: $1.35/1,000 successful JavaScript-rendered results × 100 benchmark requests. ≈ $0.14 / 100 runs
DefaultMeasured August 23, 2026 with 20 fresh production-scored runs. The default image self-identified as HeadlessChrome 128.
Pricing
Normalized marginal rate: Workers Paid is $5/mo with 10 browser-hours included, then $0.09/hr × 1.667 hr = $0.15. The modeled first 600 60-second runs have no browser-hour usage charge; monthly hours are rounded, and average concurrency above 10 is $2/browser. ≈ $0.15 / 100 runs
Web scraping API with JavaScript rendering over Geonode's residential, ISP, and datacenter proxy pool.
Run spread
40–45 signals · 20 runs
Transport consistency
No scored transport inconsistencies observed 100/100
Network
Residential · 9 exits 86/100
Connection
REST scraping API
Profile
Residential proxy · JavaScript renderingMeasured August 29, 2026 from production-scored runs. Geonode's render often returns before the external Foil SDK finishes reporting, so the lane retries sequentially; roughly half of runs still score.
Pricing
Scraper API PAYG entry (10K) tier at $0.35 per 1,000 requests — flat per-request, no JavaScript-render surcharge ($0.13/1K applies only at 1M+/mo). The lane fires ~3 render attempts per run and roughly half score, so ~6 requests per scored run. ≈ $0.20 / 100 runs
Figure 1: Every ranked engine, sorted by overall stealth score. Device integrity contributes 90%; network and transport contribute 5% each and remain independently sortable. Click any row for the per-engine breakdown.
Engines are ranked by their overall stealth score1 A 0–100 composite weighted 90% toward device integrity, 5% toward network reputation, and 5% toward transport consistency. Every distinct device issue contributes one full point; its production severity and confidence can add up to 25%, and run-to-run variance is penalized. Five issues is the near-clean device reference. Scores display as whole numbers, while the board sorts on the unrounded composite.: higher means fewer detection signals. The table is sortable, and each row expands to the full per-engine breakdown.
The full board, in leaderboard rank order. The leaders on the left are bunched within a few points of each other, and every engine was still detected on every run.
Overall stealth score by engine
Figure 2: Overall stealth score for all 31 engines in leaderboard rank order, from first to last. Higher is stealthier; every engine was still detected on every run.
Disagree with a ranking, or want to see a service on the board? Get in touch, we’ll run it through the harness.
Cost vs. stealth
Stealth is only half the decision; the other half is what it costs to run2 Cost is the marginal usage price at each vendor’s matching paid tier for 100 successful benchmark signup runs. Time- and bandwidth-metered vendors are modeled as ~60-second sessions with ~0.5 MB of egress; request-, credit-, and workload-priced vendors use their published per-success rate or metering from successful cohort runs. Retries, top-ups, and failed or incomplete attempts are excluded from the plotted price and disclosed in the per-vendor notes when known. Monthly subscription floors and workload-dependent LLM charges are also disclosed but excluded from the comparison. Residential and mobile engines include that bandwidth; datacenter engines don’t, and would cost more once you add a proxy.. Plotting the two against each other, up and to the right is the better corner: cheap and stealthy.
Figure 3: Cost per 100 runs against stealth score (cost axis is log-scaled, cheaper to the right). The dashed line is the Pareto frontier; no engine is both cheaper and stealthier than a point on it. Hover or focus any point for its provider and exact values.
Among providers with a positive modeled cost, the frontier is ThorData → Browser Cash → Browser Use. Other plotted engines are dominated: you can pay less for equal stealth, or get more stealth for equal spend, by moving to a frontier point.
Where engines trip up
Detection was distributed across fingerprint inconsistencies, the runtime environment, automation markers, timing, and input behavior. Here is how the signals that did fire break down by category.
Fingerprint54%
Automation markers21%
Environment19%
Timing6%
Input behavior0%
Figure 4: Share of all detection signals fired across the test, by category.
Each category covers a different part of the session. Here is what each category examines, with examples of the signals it contains.
Category
What it examines
Example signals
Fingerprint
What it examinesThe hardware and rendering identity a browser presents: graphics, audio, fonts, screen, and the device it claims to be.
Example signalsValues that don’t cohere with one another, or that match a known spoofing toolkit instead of a real device.
Environment
What it examinesThe browser’s runtime: which capabilities are present, and how the underlying engine actually behaves.
Example signalsSurfaces a genuine install would expose that are missing, or behaviour that doesn’t match the browser being claimed.
Automation markers
What it examinesTraces left by the protocols and drivers used to control a browser remotely.
Example signalsSide effects of being driven by software that a human-operated browser never produces.
Timing
What it examinesHow long operations take, and the rhythm of events through a session.
Example signalsPatterns that are too uniform, too fast, or sequenced in an order people don’t manage.
Input behavior
What it examinesMouse, keyboard, scroll, and touch dynamics during the flow.
Example signalsMotion that’s too clean, missing the small corrections and variance of a real hand.
Figure 5: What each detection category examines.
How we tested
We tested 31 commercial anti-detect and automation browsers on the same task: create a new account on a site protected by Foil. Account creation is a high-risk point for automated abuse, so we use it as the benchmark task. The results above are averaged per engine across runs collected from May 25, 2026 to August 29, 20263 Scored end-to-end by the production API at api.usefoil.com, the same path that scores live customer traffic, not a research fork..
Every session is graded end to end by the same production API that scores live customer traffic, not a research fork. The headline stealth score weights device integrity at 90%, network reputation at 5%, and TLS/HTTP-2 consistency at 5%. Every distinct device issue contributes one full point, and its production severity and confidence can add a bounded 25% penalty. The device component uses five issues as its near-clean 100-point reference and penalizes run-to-run variance, so a provider averaging ten issues no longer appears nearly perfect. Network and transport also remain visible as independent sortable measurements. Higher means fewer detection signals.
Underneath that score, Foil watches dozens of independent signals across five families: fingerprint coherence, the runtime environment, automation-protocol markers, timing, and input behavior. Across the whole test, 131 distinct signals fired. No engine avoided all of them, and not one session ever scored as a genuine human.
Cohorts contain 6–20 runs. On August 23 we reran every provider with a runnable harness lane: 26 providers produced fresh production scores and 23 completed full 20-run cohorts. Browser Cash completed 15 before repeated remote CDN bootstrap failures, Browserbase completed 14 before exhausting its plan minutes, and NSTbrowser completed 6 before reaching its plan limit. Context.dev has no current harness lane; Rebrowser and Oxylabs retain their audited cohorts after every fresh attempt failed at the provider boundary. That is why the full snapshot spans May 25, 2026 to August 29, 2026. Results may change as vendors and Foil release updates.
What is Foil?
Foil specializes in catching AI-driven fraud. Agents have popularized tampered browser distributions (AKA stealth browsers) because they help evade bot defenses, but the same browsers are increasingly in the hands of fraudsters. That is exactly why we run this benchmark.
Foil catches them. First it detects when someone is spoofing a device or browser. Then it builds a stable, unique fingerprint for every one of your real users. And finally itanalyzes their behavior, every swipe, tap, and form fill, to seal the deal. It is the same engine that scored every run on this page.