2026-02-23 19:57:19 +01:00
<p align="center">
2026-02-26 06:17:57 +01:00
<img src="https://i.imgur.com/cqkp6fG.png" width="500" alt="CloakBrowser">
2026-02-23 19:57:19 +01:00
</p>
# CloakBrowser
[](https://www.npmjs.com/package/cloakbrowser)
[](https://github.com/CloakHQ/CloakBrowser/blob/main/LICENSE)
**Stealth Chromium that passes every bot detection test.**
2026-02-27 02:56:49 +01:00
Drop-in Playwright/Puppeteer replacement. Same API — just swap the import. Scores **0.9 on reCAPTCHA v3** , passes **Cloudflare Turnstile** , and clears **30/30** stealth detection tests.
2026-02-23 19:57:19 +01:00
2026-03-02 18:20:57 +01:00
- 🔒 **25 source-level C++ patches** — not JS injection, not config flags
2026-02-23 19:57:19 +01:00
- 🎯 **0.9 reCAPTCHA v3 score** — human-level, server-verified
2026-02-27 02:56:49 +01:00
- ☁️ **Passes Cloudflare Turnstile** , FingerprintJS, BrowserScan — 30/30 tests
2026-02-23 19:57:19 +01:00
- 🔄 **Drop-in replacement** — works with both Playwright and Puppeteer
- 📦 ** `npm install cloakbrowser` ** — binary auto-downloads, zero config
## Install
```bash
# With Playwright
npm install cloakbrowser playwright-core
# With Puppeteer
npm install cloakbrowser puppeteer-core
```
On first launch, the stealth Chromium binary auto-downloads (~200MB, cached at `~/.cloakbrowser/` ).
## Usage
### Playwright (default)
```javascript
import { launch } from 'cloakbrowser' ;
const browser = await launch ();
const page = await browser . newPage ();
await page . goto ( 'https://protected-site.com' );
console . log ( await page . title ());
await browser . close ();
```
### Puppeteer
2026-02-25 19:20:57 +01:00
> **Note:** Playwright is recommended for sites with reCAPTCHA Enterprise. Puppeteer's CDP protocol leaks automation signals that reCAPTCHA Enterprise can detect. This is a known Puppeteer limitation, not specific to CloakBrowser.
2026-02-23 19:57:19 +01:00
```javascript
import { launch } from 'cloakbrowser/puppeteer' ;
const browser = await launch ();
const page = await browser . newPage ();
await page . goto ( 'https://protected-site.com' );
console . log ( await page . title ());
await browser . close ();
```
### Options
```javascript
import { launch , launchContext } from 'cloakbrowser' ;
// With proxy
const browser = await launch ({
proxy : 'http://user:pass@proxy:8080' ,
});
// Headed mode (visible browser window)
const browser = await launch ({ headless : false });
// Extra Chrome args
const browser = await launch ({
args : [ '--window-size=1920,1080' ],
});
2026-03-02 18:20:57 +01:00
// With timezone and locale (sets --fingerprint-timezone and --lang binary flags)
2026-03-01 01:07:11 +01:00
const browser = await launch ({
timezone : 'America/New_York' ,
locale : 'en-US' ,
});
// Auto-detect timezone/locale from proxy IP (requires: npm install mmdb-lib)
const browser = await launch ({
proxy : 'http://proxy:8080' ,
geoip : true ,
});
// Browser + context in one call (timezone/locale set both binary flags AND context)
2026-02-23 19:57:19 +01:00
const context = await launchContext ({
userAgent : 'Custom UA' ,
viewport : { width : 1920 , height : 1080 },
locale : 'en-US' ,
timezoneId : 'America/New_York' ,
});
```
2026-03-01 01:07:11 +01:00
### Auto Timezone/Locale from Proxy IP
When using a proxy, antibot systems check that your browser's timezone and locale match the proxy's location. Install `mmdb-lib` to enable auto-detection from an offline GeoIP database (~70 MB, downloaded on first use):
```bash
npm install mmdb-lib
```
```javascript
// Auto-detect — timezone and locale set from proxy's IP geolocation
const browser = await launch ({ proxy : 'http://proxy:8080' , geoip : true });
// Works with launchContext too
const context = await launchContext ({ proxy : 'http://proxy:8080' , geoip : true });
// Explicit values always win over auto-detection
const browser = await launch ({ proxy : 'http://proxy:8080' , geoip : true , timezone : 'Europe/London' });
```
> **Note:** For rotating residential proxies, the DNS-resolved IP may differ from the exit IP. Pass explicit `timezone`/`locale` in those cases.
2026-02-23 19:57:19 +01:00
### Utilities
```javascript
2026-02-25 19:20:57 +01:00
import { ensureBinary , clearCache , binaryInfo , checkForUpdate } from 'cloakbrowser' ;
2026-02-23 19:57:19 +01:00
// Pre-download binary (e.g., during Docker build)
await ensureBinary ();
// Check installation
console . log ( binaryInfo ());
// Force re-download
clearCache ();
2026-02-25 19:20:57 +01:00
// Manually check for newer Chromium version
const newVersion = await checkForUpdate ();
if ( newVersion ) console . log ( `Updated to ${ newVersion } ` );
2026-02-23 19:57:19 +01:00
```
## Test Results
| Detection Service | Stock Browser | CloakBrowser |
|---|---|---|
| **reCAPTCHA v3** | 0.1 (bot) | **0.9** (human) |
| **Cloudflare Turnstile** | FAIL | **PASS** |
| **FingerprintJS** | DETECTED | **PASS** |
| **BrowserScan** | DETECTED | **NORMAL** (4/4) |
| **bot.incolumitas.com** | 13 fails | **1 fail** |
| `navigator.webdriver` | `true` | ** `false` ** |
## Configuration
| Env Variable | Default | Description |
|---|---|---|
| `CLOAKBROWSER_BINARY_PATH` | — | Skip download, use a local Chromium binary |
| `CLOAKBROWSER_CACHE_DIR` | `~/.cloakbrowser` | Binary cache directory |
2026-02-27 02:56:49 +01:00
| `CLOAKBROWSER_DOWNLOAD_URL` | `cloakbrowser.dev` | Custom download URL |
2026-02-25 19:20:57 +01:00
| `CLOAKBROWSER_AUTO_UPDATE` | `true` | Set to `false` to disable background update checks |
2026-03-02 18:20:57 +01:00
| `CLOAKBROWSER_SKIP_CHECKSUM` | `false` | Set to `true` to skip SHA-256 verification after download |
2026-02-23 19:57:19 +01:00
## Migrate From Playwright
```diff
- import { chromium } from 'playwright';
- const browser = await chromium.launch();
+ import { launch } from 'cloakbrowser';
+ const browser = await launch();
const page = await browser.newPage();
// ... rest of your code works unchanged
```
## Platforms
| Platform | Status |
|---|---|
2026-02-25 19:20:57 +01:00
| Linux x86_64 | ✅ Available |
2026-02-27 02:15:36 +01:00
| macOS arm64 (Apple Silicon) | ✅ Available |
| macOS x86_64 (Intel) | ✅ Available |
2026-02-23 19:57:19 +01:00
| Windows | Planned |
2026-02-27 02:15:36 +01:00
**On Windows?** You can still use CloakBrowser via Docker or with your own Chromium binary by setting `CLOAKBROWSER_BINARY_PATH=/path/to/chrome` .
2026-02-25 19:20:57 +01:00
2026-02-23 19:57:19 +01:00
## Requirements
- Node.js >= 18
- One of: `playwright-core` >= 1.40 or `puppeteer-core` >= 21
2026-03-01 06:10:23 +01:00
## Troubleshooting
**reCAPTCHA v3 scores are low (0.1– 0.3)**
Avoid `page.waitForTimeout()` — it sends CDP protocol commands that reCAPTCHA detects. Use native sleep instead:
```javascript
// Bad — sends CDP commands, reCAPTCHA detects this
await page . waitForTimeout ( 3000 );
// Good — invisible to the browser
await new Promise ( r => setTimeout ( r , 3000 ));
```
Other tips for maximizing reCAPTCHA scores:
- **Use Playwright, not Puppeteer** — Puppeteer sends more CDP protocol traffic that reCAPTCHA detects ([details ](#puppeteer ))
- **Use residential proxies** — datacenter IPs are flagged by IP reputation, not browser fingerprint
- **Spend 15+ seconds on the page** before triggering reCAPTCHA — short visits score lower
- **Space out requests** — back-to-back `grecaptcha.execute()` calls from the same session get penalized. Wait 30+ seconds between pages with reCAPTCHA
- **Use a fixed fingerprint seed** (`--fingerprint=12345` ) for consistent device identity across sessions
- **Minimize `page.evaluate()` calls** before the reCAPTCHA check fires — each one sends CDP traffic
2026-02-27 02:56:49 +01:00
## Links
- 🌐 [Website ](https://cloakbrowser.dev )
- 🐛 [Bug reports & feature requests ](https://github.com/CloakHQ/CloakBrowser/issues )
- 📦 [PyPI (Python package) ](https://pypi.org/project/cloakbrowser/ )
- 📖 [Full documentation ](https://github.com/CloakHQ/CloakBrowser#readme )
- 📧 Contact: cloakhq@pm .me
2026-02-23 19:57:19 +01:00
## License
MIT — see [LICENSE ](https://github.com/CloakHQ/CloakBrowser/blob/main/LICENSE ).