Which Stealth Headless Browser Actually Gets Through in 2026?
There is no single best stealth headless browser, because the winner changes with whichever detection layer breaks first. Across 31 live Cloudflare targets in May 2026, nodriver was the only tool with zero hard blocks; in strict lab fingerprint tests, Camoufox was one of just four libraries to pass. When your blocks come from the IP rather than the fingerprint, the best stealth headless browser setup is a stealth library attached to clean residential profiles whose timezone, locale and fonts match the exit address.
📌 TL;DR Executive Summary
- Core Takeaway: nodriver led live Cloudflare tests with 28 OK and no hard blocks across 31 targets; Camoufox led lab JavaScript-fingerprint tests. Choose the tool for the layer that is failing you.
- Key Risk/Challenge: A clean fingerprint on a marked datacenter IP still gets blocked, and a mismatched setup — a Linux server behind a residential proxy advertising a Linux browser signature — is gated faster than no stealth at all.
- Recommended Solution: Pair a stealth library (nodriver, Patchright, Camoufox) with managed residential profiles and matching fingerprints, then verify with CreepJS, Pixelscan and BrowserScan before touching production targets.
What Makes a Headless Browser Stealthy — and What Gets It Flagged
Headless mode is not what gets you blocked; the scaffolding around it is. Playwright, Puppeteer and Selenium each leave a trace before your first request lands: navigator.webdriver is set to true, and most libraries call Runtime.enable during initialization — a CDP handshake Cloudflare and DataDome read as a classic tell. They also check TLS and HTTP2 shape, canvas and WebGL output, WebRTC leaks and missing system fonts.
Detection runs roughly in this order, and each layer is independent of the others:
- IP reputation — ASN type, abuse history, and how many identities already came from that address.
- TLS and HTTP2 shape — JA3/JA4 cipher order and settings frames that must match the browser you claim to be.
- Control channel — CDP calls, injected scripts and init timing that only exist under automation.
- JavaScript fingerprint — canvas, WebGL, audio, fonts, hardware concurrency, screen metrics.
- Network leaks — WebRTC revealing a local or datacenter IP, a timezone that contradicts the exit IP.
| Detection layer | What the site reads | What actually fixes it |
|---|---|---|
| IP reputation | ASN type, datacenter vs residential, abuse history on the address | Residential exit IPs, rotation, one identity per address |
| TLS / HTTP2 handshake | JA3/JA4 cipher order, HTTP2 settings frames | A real browser stack, or curl_cffi for HTTP-only work |
| Control channel | Runtime.enable and Target.setAutoAttach during init | Patched CDP handshake, or raw CDP with no wrapper |
| JS fingerprint | navigator.webdriver, canvas, WebGL, audio, fonts, hardware | Engine-level spoofing that stays coherent per profile |
| Network leaks | WebRTC local IPs, timezone or locale mismatched to the exit IP | Timezone, locale, WebRTC and geolocation bound to the proxy exit |
Two rules follow. A tool only fixes the layer it targets: vanilla Playwright scored 24 OK and 5 blocked against the same targets Patchright handled with 3 blocks, and neither of them repairs a burned IP. Coherence matters more than perfection — a signal that contradicts another signal flags you harder than a single imperfection, which is what our headless browser detection methods breakdown keeps coming back to.
9 Best Stealth Headless Browsers and Frameworks, Ranked
This ranking mixes two categories on purpose: libraries you drive from code, and the profile layer they run inside. Item 1 is the environment; items 2–9 are the libraries. Both show up in the same stack, and the profile layer is where most setups quietly lose.
1. Sendwin Browser and Cloud Browser — the profile and IP layer
Send.win is not a headless library and does not claim to be one. Sendwin Browser is an anti-detect desktop app for Windows, macOS and Linux, built on a patched-Chromium engine with the Sendwin Stealth engine inside: canvas, WebGL, audio, fonts and hardware are spoofed at the engine level and kept coherent per profile, so no two profiles share a fingerprint. The same profiles run in the cloud browser on EU and US nodes from any device — a free 10-minute-per-day preview, and unlimited cloud browsing on Pro and Team.
It belongs in a scraping stack because it covers what a library cannot reach. Every plan includes built-in residential proxies, timezone, locale, WebRTC and geolocation follow the proxy exit IP automatically, and you can bring your own HTTP/SOCKS5 pool. The local Automation API on Team connects Selenium, Puppeteer and Playwright to a profile that is already running with a settled identity.
- Pros: Profiles, fingerprints and residential proxies on one subscription; add-ons at $0.05 per extra profile and $6 per GB of bandwidth.
- Pros: Cloud profiles need nothing installed, and cloud sync keeps logins across devices.
- Cons: The local Automation API is Team-only ($49/mo, or $20.99/mo billed annually).
- Cons: Not a drop-in library — you still write the Playwright or Puppeteer code that drives it.
Best for: teams running many logged-in accounts and scrapers at once, where burned IPs cause more blocks than the library does.
2. nodriver — best live-target results in Python
nodriver speaks raw CDP with no WebDriver layer and no Playwright wrapper in between. Against 31 Cloudflare-protected targets in May 2026 it scored 28 OK, 3 gated and 0 blocked — the only tool in the set with no hard blocks. It is async and fast, and it skips the init handshake that gets patched libraries flagged.
- Pros: Top live-target score, no WebDriver tell, an async core that keeps scrapes quick.
- Pros: Full Chromium, so JavaScript-heavy pages render like a normal browser.
- Cons: AGPL-3.0 licensing — a real problem if you ship closed-source software and cannot isolate the process.
- Cons: Async-only API with thinner documentation; three targets were still gated.
Best for: Python teams scraping Cloudflare-protected sites who can live with AGPL-3.0, or keep nodriver in a separate service.
3. Camoufox — best for strict JavaScript fingerprint judges
Camoufox is a Firefox fork patched at the C level, so canvas, WebGL, screen and navigator APIs return consistent random values instead of scripted overrides. In a July 2026 lab test judged externally by deviceandbrowserinfo.com, only 4 of 15 open-source Python stealth libraries passed, and Camoufox was one of them. Firefox’s TLS shape is detectable, but several sites that block Chrome automation whitelist it.
- Pros: Strongest lab fingerprint results, with spoofing compiled in rather than injected at runtime; MPL-2.0 license.
- Pros: Rotating exit IPs measurably improved its pass rate in external tests.
- Cons: Heavier and slower on live targets than CDP-based Chromium tools.
- Cons: Firefox-only; migrating existing Chrome scripts is real work, as our Camoufox vs Playwright stealth comparison shows.
Best for: targets that run deep JavaScript fingerprinting rather than bot management.
4. Patchright — best drop-in upgrade for existing Playwright code
Patchright is a Playwright fork that patches the two handshake leaks, Runtime.enable and Target.setAutoAttach, while keeping the API intact. It scored 25 OK and 3 blocked in the live benchmark, and with channel="chrome" it drives a real system Chrome — 148 in those tests — so the TLS fingerprint matches the browser you claim to be. It is the most actively maintained patched Playwright fork.
- Pros: Change one import and existing scripts become meaningfully harder to flag; Apache-2.0.
- Pros: Real Chrome channel support keeps the TLS shape aligned.
- Cons: It patches the control channel only — canvas, fonts and IP are still your problem.
- Cons: Three targets still returned hard blocks, and fork maintenance lags upstream Playwright releases. Skip rebrowser-playwright entirely: last real commit September 2024, Chromium 136 bundled, a block set identical to vanilla Playwright.
Best for: teams with a working Playwright suite that want a cheap evasion upgrade without a rewrite.
5. SeleniumBase UC mode — best for challenge and CAPTCHA pages
SeleniumBase’s UC mode drives Chromium with a recompiled driver and a CDP mode built for challenge pages, plus solver support for common CAPTCHAs. It is the Python pick most often recommended for sites that interrupt you with an interstitial instead of blocking you outright. The trade-off is weight: roughly 220 MB of memory per instance, against about 150 MB for Playwright Stealth.
- Pros: Best CAPTCHA and challenge-page handling among open-source Python options.
- Pros: A mature Selenium base you can reuse for ordinary automation.
- Cons: Heaviest memory footprint on this list and slower startup.
- Cons: Solver support varies by challenge type.
Best for: Python projects that hit interstitials and CAPTCHA walls rather than silent blocks.
6. CloakBrowser — best Chromium fork with source-level patches
CloakBrowser is a patched Chromium fork carrying 49 C++ modifications made at the source level, shipped as a bundled binary with a Playwright-compatible API. It scored 26 OK, 3 gated and 2 blocked in the same live benchmark — ahead of vanilla Playwright, behind nodriver. Because the patches are compiled in, there is no runtime script for a site to spot.
- Pros: Source-level patching behind a familiar API, with an MIT-licensed wrapper.
- Pros: Strong live-target results without writing raw CDP code yourself.
- Cons: The macOS arm64 build was still pinned to Chromium 145 as of March 2026, and that gap widens with each Chrome release.
- Cons: Bundled binaries mean large downloads and slower updates on every machine.
Best for: teams that want Chromium-level patching behind a familiar API and can plan around build lag.
7. curl_cffi — best when you never needed a browser
curl_cffi 0.15.0 impersonates Chrome 145/146’s TLS and HTTP2 shape from a 6.4 MB Python wheel with no browser and no JS engine. It tied a 130 MB patched Chromium fork on live targets, which says something uncomfortable about how much of “stealth” is really handshake fidelity. There is no DOM, so it only works where your data sits in the initial HTML or a JSON endpoint.
- Pros: Tiny, fast, correct TLS shape, MIT license, easy to containerize.
- Pros: No browser process means no automation artifacts to leak.
- Cons: No JavaScript execution, so client-rendered data is out of reach.
- Cons: Still dies on a burned IP, and some sites challenge non-browser clients on headers alone.
Best for: high-volume static pages and API endpoints where a full browser is wasted memory.
8. Bright Data Scraping Browser — best managed cloud option
Bright Data’s Scraping Browser runs Chrome in the cloud; you connect over wss://brd.superproxy.io:9222 with your own automation library. It layers automatic IP rotation, TLS JA4 alignment and a built-in Turnstile solver over the browser, and consumes 0 MB of local memory. Pricing tracks minutes, concurrency and egress, so the cost curve looks nothing like a fixed subscription.
- Pros: No local infrastructure; rotation, TLS alignment and solving handled for you.
- Pros: Concurrency a single machine could never reach, billed by use.
- Cons: Egress and minute costs are easy to underestimate — verify current rates on the vendor’s pricing page before committing.
- Cons: Lock-in; your scripts depend on their endpoint and session model.
Best for: spiky workloads where paying per minute beats maintaining browser fleets and proxy pools.
9. Vanilla Playwright and Puppeteer — the baseline, not a stealth tool
Playwright drives Chromium, Firefox and WebKit from one API with Python, JS/TS, Java and .NET bindings, and version 1.63 ships Chromium 153, Firefox 155 and WebKit 26.6 (release notes). Puppeteer is the Chrome DevTools team’s Node library and runs headless by default. Both are excellent automation tools and both are detectable as shipped: navigator.webdriver is set and the CDP handshake is untouched.
- Pros: Best-in-class APIs, auto-waiting, cross-browser coverage and four language bindings.
- Pros: Every stealth fork builds on this layer, so the skills transfer directly.
- Cons: 24 OK and 5 blocked on live Cloudflare targets — the weakest measured showing.
- Cons: Community plugins age badly. puppeteer-extra-stealth patches known vectors, but Cloudflare and DataDome update faster than the community patches do, so gains last weeks. Lightpanda, the Zig-based CDP engine, uses far less memory but ships no stealth support.
Best for: internal automation and testing where nobody is actively trying to detect you.
Stealth Headless Browser Comparison Table
The live numbers come from the May 2026 run against 31 Cloudflare-protected targets, three runs each — 651 verdicts from one residential IP, in headed mode — plus the July 2026 lab test judged externally by deviceandbrowserinfo.com.
Automate Best Stealth Headless Browser With Send.win
Send.win pairs isolated, fingerprint-managed browser profiles with a full Automation API, so your scripts run in profiles that look and behave like real, separate users:
- Selenium, Puppeteer & Playwright support – drive any profile programmatically (Team plan)
- Isolated profiles – each with its own fingerprint, cookies, and storage
- Built-in residential proxies – with automatic timezone, locale, and WebRTC matching
- Desktop app for Windows, macOS & Linux – plus cloud sessions when you don’t want a local install
Try the instant cloud browser demo — no install, straight from your browser. Then compare plans: a 30-day free trial with no credit card, and paid plans from $6.99/month billed annually.
| Tool | Type | Stealth approach | Measured result | Cost |
|---|---|---|---|---|
| Sendwin Browser + cloud | Patched-Chromium profiles, desktop or cloud | Engine-level fingerprint spoofing per profile, built-in residential proxies | Not in this benchmark — different layer | 30-day free trial, Pro $19/mo, Team $49/mo |
| nodriver | Python, raw CDP | No WebDriver layer, no wrapper | 28 OK / 3 gated / 0 blocked | Free, AGPL-3.0 |
| Camoufox | Firefox fork, C-level patches | Spoofed canvas, WebGL and navigator values, kept consistent | Passed the July 2026 lab isBot referee | Free, MPL-2.0 |
| Patchright | Playwright fork | Patches Runtime.enable and Target.setAutoAttach | 25 OK / 3 blocked | Free, Apache-2.0 |
| CloakBrowser | Chromium fork, 49 C++ patches | Source-level removal of automation signals | 26 OK / 3 gated / 2 blocked | Free, MIT wrapper |
| SeleniumBase UC | Python + Selenium, CDP mode | Recompiled driver, challenge modes, solvers | Not in the live set; ~220 MB per instance | Free, open source |
| curl_cffi | Python HTTP client | Chrome 145/146 TLS and HTTP2 impersonation | Tied a 130 MB patched Chromium fork | Free, MIT |
| Bright Data Scraping Browser | Managed cloud Chrome | Auto IP rotation, JA4 alignment, Turnstile solver | Vendor-rated, 0 MB local memory | Usage-based; verify current pricing |
| Playwright / Puppeteer | Automation frameworks | None by default | 24 OK / 5 blocked | Free, open source |
| Lightpanda | Zig CDP engine, beta | None — DOM, V8 and CDP only | No stealth or anti-bot support | Beta |
Read the table by layer, not by rank: a tool that wins on live Cloudflare targets can lose a deep JS fingerprint audit, which is exactly what happened between the two 2026 test sets. The May 2026 Cloudflare benchmark is worth reading in full before you commit to a winner.
The Layer No Benchmark Measures: IP Reputation vs Fingerprint
Every number above came from one residential IP, and that is not a footnote — it is why self-run benchmarks over-promise. The tool and the IP cover different layers and neither compensates for the other: a clean fingerprint on a marked datacenter IP still gets blocked, and an inconsistent pair, such as a Linux server behind a residential proxy advertising a Linux browser signature, is gated faster than no stealth setup at all.
Rotation matters for the same reason. Repeated runs from one address let a recognizable signature, like Firefox’s, accumulate reputation until the IP itself becomes the flag. Spreading load across residential exits with matched timezone and locale keeps each identity clean, and external tests have shown rotation improving Camoufox’s pass rate. Send.win handles that by default: timezone, locale, WebRTC and geolocation follow the proxy’s exit IP on every profile, and each profile keeps its own cookie jar, so sessions do not bleed between runs.
Session persistence is the part most guides skip. Reusing cookies from the same exit IP looks like a returning user; restarting with an empty jar from that address every time looks like a script, however good the fingerprint is.
Licensing, Maintenance and Pacing Traps
Licensing sinks more commercial projects than fingerprints do. nodriver is AGPL-3.0, unlike the MIT-licensed undetected-chromedriver it grew out of, so shipping it inside a closed product needs isolation or legal review. Patchright is Apache-2.0 and Camoufox is MPL-2.0 — both friendlier for commercial use.
Maintenance calendars are the second trap. Patched forks lag upstream: rebrowser-playwright still bundles Chromium 136 against Patchright’s Chrome 148, and CloakBrowser’s macOS arm64 build sat on Chromium 145 as of March 2026. If nobody on your team tracks upstream releases, you are running an outdated fingerprint and calling it stealth.
Pacing is the third. A passing tool still fails when you hammer it: fixed intervals, parallel bursts from one identity and requests that ignore a site’s own rate hints trip heuristics that have nothing to do with fingerprints. Slow down, keep one identity per account, and rotate deliberately rather than constantly.
Wiring a Stealth Stack Into a Managed Profile
The pattern that works with Send.win is simple: let the profile own the fingerprint and the IP, and let Playwright own the logic. Start the profile in Sendwin Browser, copy the CDP endpoint from the profile’s automation settings, and connect to it — you attach to a browser already running with a settled identity, instead of launching a fresh, sterile Chrome.
from playwright.sync_api import sync_playwright
CDP_URL = "http://127.0.0.1:PORT" # copy it from the profile's automation settings
with sync_playwright() as p:
browser = p.chromium.connect_over_cdp(CDP_URL)
context = browser.contexts[0] # the profile's existing context
page = context.new_page()
page.goto("https://example.com", wait_until="domcontentloaded")
print(page.title())
browser.close() # closes the connection, not the profile
Puppeteer follows the same shape, with one difference worth remembering: disconnect() leaves the profile running so you can reuse its session later.
const puppeteer = require('puppeteer-core');
const CDP_URL = 'http://127.0.0.1:PORT'; // copy it from the profile's automation settings
(async () => {
const browser = await puppeteer.connect({
browserURL: CDP_URL,
defaultViewport: null, // keep the profile's real window metrics
});
const [page] = await browser.pages();
await page.goto('https://example.com', { waitUntil: 'domcontentloaded' });
console.log(await page.title());
await browser.disconnect(); // leaves the profile running
})();
The same pattern works for Selenium, and the local Automation API that exposes these endpoints is a Team-plan feature. Nothing here invents a protocol: standard CDP is what every automation library already speaks.
How to Test Whether Your Stealth Browser Is Passing
Run every candidate against bot.sannysoft.com, Pixelscan, BrowserScan and CreepJS before pointing it at production targets. Compare the tool’s internal score with an external judge — in the July 2026 lab test the internal probe matched the external verdict 92% of the time, which makes a single score useful but not final. Test in the order sites check: IP reputation, then TLS, then JavaScript.
Re-test after every Chrome or Firefox major release. A setup that passed in May can fail in September when the fork you rely on still bundles an older engine, and you will not notice until a target starts returning interstitials. Keep those four test sites in a script and run them weekly — the headless browser detection bypass checklist covers what each one exposes.
Self-Hosting vs a Cloud Scraping Browser
The build-vs-buy question in 2026 is about operations, not detection. Self-hosting gives you control, no per-minute billing and full visibility into what your browser sends. Managed cloud browsers move Chrome off your machines and connect over CDP, billing by minutes, concurrency and egress — cheaper for spiky workloads, more expensive for constant ones.
Memory makes the trade-off concrete: Playwright Stealth runs around 150 MB per instance, Puppeteer Extra Stealth about 180 MB and SeleniumBase UC about 220 MB, so a hundred concurrent sessions is a real server bill wherever you host them. Cloud also solves something local headless browsers cannot — a long-lived session that survives a reboot and stays signed in. Our headless browser vs cloud browser breakdown covers the rest. Send.win sits in that space with a free 10-minute daily cloud preview, unlimited cloud browsing on Pro and Team, and local desktop profiles when you want everything on your own machine.
🏆 Send.win Verdict
Send.win does not replace nodriver, Camoufox or Patchright — it fixes the layers they cannot. If your stealth library keeps getting 403s from addresses that have been used too many times, the library is not the problem: the IP and the profile identity are. Sendwin Browser gives each profile its own engine-level fingerprint and a built-in residential proxy, on the desktop app or in the cloud, with timezone, locale and WebRTC following the exit IP automatically.
Try Send.win free today — 30 days for $0 with 10 isolated profiles, 10 built-in residential proxies and 1 GB of bandwidth; Pro starts at $6.99/mo billed annually, and the Automation API for Selenium, Puppeteer and Playwright comes with Team.
Frequently Asked Questions
What is the best stealth headless browser in 2026?
There is no single winner, because the two 2026 test sets measure different layers. nodriver took 28 OK out of 31 live Cloudflare targets with zero hard blocks, Camoufox passed a strict lab JavaScript-fingerprint referee, and Patchright is the cleanest drop-in upgrade for existing Playwright code. All of them fail on a burned IP.
Can Playwright bypass Cloudflare and DataDome?
Not as shipped. Vanilla Playwright sets navigator.webdriver and calls Runtime.enable during initialization, and it scored 24 OK with 5 blocked in the May 2026 run. Patchright patches those handshake leaks, cutting that to 3 blocks, and drives a real Chrome channel so the TLS fingerprint matches.
How do anti-bot systems detect headless browsers?
Most often they read navigator.webdriver and CDP artifacts, then TLS and HTTP2 fingerprint mismatches, canvas and WebGL fingerprints, WebRTC leaks and missing system fonts. IP reputation is evaluated before any JavaScript runs, which is why a perfect browser can still be blocked at the edge.
Do stealth plugins still work in 2026?
Partially, and never permanently. puppeteer-extra-stealth patches known detection vectors, but Cloudflare and DataDome update faster than the community patches do, so any gain is measured in weeks. Compile-level forks and raw CDP clients hold up longer, and every “still works” claim is a point-in-time observation.
Is nodriver or Camoufox better for scraping?
nodriver for live Cloudflare-style targets and speed, Camoufox for strict JavaScript fingerprint judges. Camoufox is heavier and slower on live targets, but rotation across residential IPs improved its pass rate in external tests. If AGPL-3.0 does not fit your product, that alone decides the question.
Which headless browser handles CAPTCHA best?
SeleniumBase UC mode is the usual Python pick, with challenge modes and solver support built in, and Bright Data’s managed browser bundles a Turnstile solver. Treat CAPTCHA as a separate problem from fingerprint quality: a passing fingerprint and a clean residential IP reduce how often you see a challenge in the first place.
Is curl_cffi enough without a browser?
For static HTML and JSON endpoints, often yes. It sends a Chrome-shaped TLS and HTTP2 handshake from a 6.4 MB wheel and tied a 130 MB patched Chromium fork on live targets. It cannot run JavaScript, so anything client-rendered still needs a real browser engine.
Should I self-host headless browsers or use a cloud scraping browser?
Self-hosting gives you control and no per-minute billing; managed cloud gives you rotation, TLS alignment and concurrency without infrastructure, at the cost of egress and minute-based pricing that changes often. Test both against your real targets and measure cost per successful page, not cost per request.