What actually gets a profile flagged, how agents drive a real browser, and the detector runs behind our claims.
DataDome, Kasada, Cloudflare and PerimeterX do not run one check, they score a risk profile from network, TLS, fingerprint, behaviour and history. Understanding which layer flagged you is the difference between fixing it and guessing.
Checked against each vendor's own download endpoints on 2026-08-13. AdsPower, GoLogin, Dolphin Anty, Multilogin, Octo and Kameleo publish x86-64 Linux only, and one of them advertises ARM support its CDN does not back up. Here is what that actually costs you, and why an arm64 build is a deployment convenience rather than a stealth feature.
109 accounts, 1,989 logged actions, zero interactive challenges and zero re-logins across 32 warm-up sessions. The harness, the code, the per-batch variance, and what the free tier actually covers.
A script that opens one browser per task creates one profile per task, and every tool that lists profiles then has to list them forever. Temporary profiles go in a separate tree the desktop app never reads, and nothing in it is deleted for you, which is the point.
A launch that jumps to the front is fine once and unusable in a loop, and going headless to avoid it changes what the page can measure. There is a third option: keep a real, normally sized, visible window and stop only the part that interrupts you.
A loop that opens 400 browsers should not decide that you now have 400 cloud profiles. The sync option has three states rather than two, and the difference between the default and an explicit false is the part worth understanding.
A passkey is bound to an authenticator, not to a password store. Profiles without one cannot enrol, cannot re-authenticate, and get locked out of accounts they created. Why this breaks account warming, and what a per-profile virtual authenticator changes.
Most MCP browser tools hand the model a fresh context per call, so anything behind a login is unreachable. Here is the setup, why session persistence across tool calls is the part that matters, and what still goes wrong.
A page asks your GPU to identify itself, then measures dozens of rendering limits and a drawn scene's pixels. No permission prompt is involved, and the result is one of the most informative signals a browser exposes.
Every roundup in this category is written by a vendor. This one is too, and we are last on our own list where the criterion says we should be. Verified pricing captured 2026-08-01, one honest recommendation per use case.
Stealth plugins are free, they work, and for a one-off script we would use one too. The failure is not detection on day one, it is what happens on the release that moves the goalposts, and what a plugin never covered in the first place.
Fingerprinting identifies you from the combination of hundreds of ordinary browser properties, no cookies required. The counterintuitive part: aggressive blocking usually makes you more identifiable, not less.
Named, sourced, and dated. Where a vendor's price is not on their own page, we say so instead of quoting a number.
// Every competitor figure on those pages carries its source and the date we captured it. Where we could not source a number, it is missing rather than estimated.