JustBrowser
Tutorials12 min read

FingerprintJS Pro Bot Detection: Antidetect Browser Test Guide (2026)

JustBrowser Platform Team·
fingerprintjs-pro-testantidetect-browserbot-detectionvisitor-identificationincognito-detectionbuildinpublicsaasstudioaiworkforcebuildwithclaude

Two months ago I burned three days debugging why accounts kept getting flagged during checkout. CreepJS: 94% trust score, zero lies. BrowserScan: all green. Pixelscan: clean hardware fingerprints. The profiles looked perfect.

Then I ran FingerprintJS Pro.

Bot probability: 0.87. Incognito: detected. Automation signals: present.

The profiles were passing every free test I threw at them — and failing the one that actually mattered. FingerprintJS Pro runs on the sites where those accounts were getting blocked. The free tools don't.

I felt like an idiot. Three days of debugging, and the answer was "you're testing against the wrong detection system." Classic.

That's the gap nobody talks about. CreepJS, BrowserScan, Pixelscan — they're useful. They catch real issues. But they're not the same as FingerprintJS Pro, and platforms paying $10,000/month for commercial bot detection aren't using BrowserScan. If you're running multi-account operations on any platform that handles money — e-commerce, ad accounts, fintech, or even high-volume outbound calling — FingerprintJS Pro is probably what's actually checking you.

This walkthrough breaks down their bot-detection report. What each signal means. Which ones matter. And how to read results without panicking about false positives (because there are a lot of those, honestly).

What We're Building

By the end of this tutorial, you'll know how to:

  1. Access FingerprintJS Pro's demo environment for testing
  2. Read the botd (bot detection) response — probability scores, detection reasons
  3. Interpret incognito and tampering flags
  4. Understand visitorId stability and what it means for account linking
  5. Diagnose why your antidetect profile might fail when free tests pass

You'll need an antidetect browser profile configured and ready to test. We're using JustBrowser in the examples, but the interpretation applies to any antidetect setup.

Prerequisites

FingerprintJS Pro's demo gives you the same detection as their paid product. The only difference is you can't see full API responses — the demo summarizes results into human-readable cards. That's enough for profile verification.

Step 1: Run the Test

Open your antidetect browser profile and navigate to https://fingerprint.com/demo/. Wait for the page to fully load — FingerprintJS Pro runs asynchronously and needs 2-3 seconds to complete all checks.

Don't click around frantically while it loads. Some behavioral signals measure interaction patterns. Let the page settle.

When complete, you'll see a dashboard with several cards:

  • Visitor ID — Your persistent identifier
  • Incognito Mode — Whether private browsing is detected
  • Bot Detection — The bot probability score and classification
  • Geolocation — IP-based location data
  • Browser & Device — Detected browser, OS, device type

Each card expands with more detail. We're going to focus on Bot Detection and Incognito Mode — those are where antidetect profiles typically fail. The fingerprint-consistency stuff you've already tested on CreepJS and Pixelscan. This is different.

Step 2: Reading the Bot Detection (botd) Section

Click to expand the Bot Detection card. You'll see:

  • Bot probability: A score from 0.0 to 1.0 (1.0 = definitely a bot)
  • Classification: good, bad, or undetermined
  • Detection signals: The reasons behind the score

Here's how to interpret these:

Bot probability below 0.1: You're fine. This is normal-browser territory. Platforms using FingerprintJS Pro won't flag you on this signal alone.

Bot probability 0.1 to 0.3: Borderline. Some automation signals present but not conclusive. You might hit more CAPTCHAs than usual. Worth investigating but not necessarily broken.

Bot probability above 0.3: Red flag. FingerprintJS Pro thinks you're probably automated. This will trigger challenges, blocks, or silent flagging on sites using their service.

Bot probability above 0.7: Your profile is compromised for any site running FingerprintJS Pro. Stop deploying it.

The classification — good/bad/undetermined — is a binary interpretation of the probability score. "bad" doesn't mean malicious, it means "we think this is automation." But platforms don't always use the classification; some set their own thresholds on the raw probability.

I've seen profiles sit at 0.25 probability for months with no issues, then suddenly start getting blocked when a platform adjusted their threshold. The probability is more informative than the classification.

Step 3: Understanding Detection Signals

Expand the Bot Detection details to see specific signals. FingerprintJS Pro doesn't show everything (their detection is their product, so they're cagey), but the demo surfaces common flags:

Automation framework detected: This fires if FingerprintJS Pro sees Selenium, Playwright, Puppeteer, or WebDriver indicators. Even with stealth plugins, some signals leak. The Playwright/Puppeteer antidetect guide covers how to minimize these, but some antidetect browsers handle this at the engine level better than others.

Headless browser detected: Similar to automation, but specifically about headless mode. If you're running headed mode with proper display setup, this shouldn't fire. If it does, your profile isn't actually in headed mode — check your launch configuration.

Behavior anomaly: This one's infuriating. It means FingerprintJS Pro's ML model found something weird in your browser behavior, but they won't tell you what. Could be timing patterns, could be mouse movement artifacts, could be rendering timing. I've spent hours staring at this flag with nothing to go on — it's basically FingerprintJS Pro saying "we know something's off but we're not telling." The fix is usually "use a different antidetect solution" because you can't fix what you can't identify.

JavaScript environment tampering: FingerprintJS Pro detected modifications to native JavaScript objects. This is the same thing CreepJS catches with prototype tampering, but FingerprintJS Pro's detection goes deeper. Native-engine antidetect browsers don't trigger this because they modify values at the C++ level, not JavaScript. Extension-based tools almost always fail here.

Inconsistent browser fingerprint: Your fingerprint components don't match each other. A browser claiming to be Chrome 126 on Windows but with macOS-only fonts, for example. This overlaps with what Pixelscan catches, but FingerprintJS Pro's cross-validation is trained on more data.

If you see "No bot signals detected" — congratulations. Your profile passes. Move on.

Step 4: The Incognito Detection Card

This one surprises people. FingerprintJS Pro can detect private browsing mode with high accuracy.

Why does this matter for antidetect profiles? Most antidetect browsers don't run in incognito by default — they use normal mode with isolated storage per profile. So incognito detection usually isn't the issue.

But some configurations accidentally enable it. And some operators intentionally use incognito thinking it adds privacy. It doesn't — it adds a detection signal.

The incognito detector checks:

  • FileSystem API availability: Chrome in incognito has limited filesystem access
  • Storage quota differences: Incognito mode reports different quota values
  • Memory pressure indicators: Some browsers behave differently under incognito

If FingerprintJS Pro flags incognito: true and you didn't intentionally enable it, check your profile settings. Something's misconfigured. Normal antidetect profiles should show incognito: false.

If you did intentionally enable incognito — stop. Seriously, I see this advice floating around forums and it drives me crazy. It's adding a detection signal that provides no benefit. Your profiles are already isolated at the antidetect-browser level. Incognito mode on an antidetect profile is security theater that actively hurts you.

Step 5: Visitor ID Stability

The Visitor ID card shows a hash that FingerprintJS Pro generates for your browser. This is their alternative to cookies — it persists even when you clear storage, because it's derived from your fingerprint.

For antidetect testing, here's what matters:

Same profile, same visitor ID: Good. Your fingerprint is stable across sessions.

Same profile, different visitor ID: Bad. Something in your fingerprint is changing between sessions. This could be your antidetect browser randomizing values that should be stable, or your proxy IP changing aspects of the fingerprint. Check the timezone/geolocation proxy mismatch guide if your proxy setup varies.

Different profiles, same visitor ID: Very bad. Your profiles aren't actually different — they share enough fingerprint components to be linked. This defeats the purpose of antidetect.

Run the same profile twice and compare visitor IDs. Run two different profiles and compare. First should match. Second should differ. If either fails, your profile isolation isn't working.

Step 6: Common Errors and Fixes

Error: Bot probability 0.5+ despite passing CreepJS

Cause: FingerprintJS Pro's ML detection catches behavioral and timing signals that CreepJS doesn't test.

Fix: This usually means your antidetect browser has automation artifacts. Try a fresh profile with default settings. If it still fails, the browser itself may have detectable automation patterns. Consider testing alternatives — native-engine antidetect browsers like JustBrowser tend to have lower baseline bot scores because they're modified at the Chromium source level.

Error: "JavaScript environment tampering" detected

Cause: Your antidetect browser uses JavaScript injection to override fingerprint values. FingerprintJS Pro detected the injection.

Fix: You can't fix this with configuration. The fix is architectural — use an antidetect browser that modifies fingerprints at the engine level (C++ modifications) rather than JavaScript overrides. This is the fundamental difference between native-engine and extension-based antidetect tools.

Error: Incognito detected when not using incognito

Cause: Your profile configuration enables something that mimics incognito behavior — limited storage, disabled features, etc.

Fix: Check your profile's storage settings. Enable full storage APIs. Make sure you're not running in a restricted mode that limits filesystem access.

Error: Visitor ID changes between sessions on same profile

Cause: Your fingerprint has unstable components. Canvas hash might be randomizing, timezone might be shifting with your proxy, or something in your navigator object isn't persisting.

Fix: Check your profile's fingerprint stability settings. Values should be deterministic per profile. If using a rotating proxy, ensure timezone/geolocation stay consistent or configure your antidetect browser to override them. For automation workflows, pair with JustAnalytics to track session consistency across test runs without adding more fingerprint signals.

Error: Passing FingerprintJS Pro but still getting blocked

Cause: FingerprintJS Pro isn't the only detection layer. Sites also use IP reputation, behavioral analysis, TLS fingerprinting, and their own custom rules.

Fix: FingerprintJS Pro passing is necessary but not sufficient. Layer your testing: IPHey for IP reputation, BrowserScan and Pixelscan for hardware fingerprints, CreepJS for prototype tampering, and FingerprintJS Pro for commercial bot detection. If all pass but you're still blocked, the issue is likely behavioral or IP-based.

Step 7: Putting It Together

Here's the full verification workflow I use now:

  1. IPHey — 3 seconds. Is the proxy IP blacklisted? If yes, stop.
  2. BrowserScan — 5 seconds. Any WebRTC leaks? Timezone/geo mismatches?
  3. Pixelscan — 10 seconds. Hardware fingerprint consistency.
  4. CreepJS — 15 seconds. Prototype tampering, trust score.
  5. FingerprintJS Pro — 5 seconds. Commercial bot detection, incognito flags.

Total time: under one minute. I know it feels excessive — I thought the same thing before I lost three days to a problem a 60-second workflow would have caught. Each test catches different things. FingerprintJS Pro is the commercial reality check — it's what real platforms use.

If your profile fails steps 2-4, fix those first. If it passes those but fails FingerprintJS Pro, your antidetect browser has architectural detection issues that can't be fixed with settings. For click fraud verification and ad verification workflows, ClickzProtect can help validate the traffic side while you're verifying profiles.

Next Steps

Once your profiles pass FingerprintJS Pro cleanly:

  1. Document your passing configuration — Screenshot or note every setting. When something breaks later, you'll want to compare.
  2. Set a monthly re-test schedule — FingerprintJS Pro updates their ML models regularly. A profile that passes today might fail next month.
  3. Test under load — A single-profile test is different from running 50 profiles simultaneously. Behavioral patterns might differ. For payment processing across profiles, consider VeloCards to manage virtual cards per identity.

And honestly? If you're failing FingerprintJS Pro consistently while passing free tools, that's a signal about your antidetect browser choice. I wasted months on an extension-based tool before accepting this. Not all antidetect browsers are built the same. Extension-based tools fail FingerprintJS Pro's JavaScript tampering checks almost universally. Native-engine tools — the ones that modify Chromium source code — pass because there's no tampering to detect. The fingerprint values are genuine at every layer.

Seven-day free trial, full access, cancel inside the week and you're not charged: worth testing if you're hitting walls elsewhere.

Frequently Asked Questions

What's the difference between FingerprintJS Pro and free fingerprint tests?

FingerprintJS Pro is a commercial detection service used by real platforms — banks, e-commerce, ad networks. Free tools like BrowserScan and Pixelscan test your fingerprint passively. FingerprintJS Pro actively tries to detect automation, tampering, and bots using ML models trained on billions of real requests. Passing free tools doesn't mean you'll pass FingerprintJS Pro.

Does FingerprintJS Pro detect incognito mode?

Yes. FingerprintJS Pro has a dedicated incognito detection feature that checks browser behavior patterns — filesystem API availability, storage quota differences, and other signals that differ between normal and private browsing modes. Most antidetect browsers run in non-incognito mode by default, so this usually isn't a problem unless you've explicitly enabled incognito on your profiles.

Why does FingerprintJS Pro flag my profile as a bot when CreepJS passes?

CreepJS and FingerprintJS Pro test different things. CreepJS focuses on fingerprint consistency and prototype tampering. FingerprintJS Pro's botd system uses machine learning trained on behavioral signals, timing patterns, and automation indicators that CreepJS doesn't check. A profile can be fingerprint-consistent but still trigger behavioral bot flags.

How often should I test profiles against FingerprintJS Pro?

Test every new profile template before deployment. FingerprintJS Pro updates their detection models regularly — sometimes weekly. Re-test production profiles monthly and immediately after any configuration change. If accounts that were working start getting challenged more frequently, run FingerprintJS Pro to check whether their detection has caught up to your setup.


Try JustBrowser

Native Chromium antidetect browser — not extension-based. Real C++ engine patches at the canvas / WebGL / audio / font / screen layer, so 40+ identity parameters are genuine, not faked. REST API for Playwright, Puppeteer, Selenium. $9.99/month or $99.99/year. 7-day free trial, card required — cancel any time in the seven days and you are not charged. Unlimited profiles.

Get started → · How it differs from Multilogin / GoLogin / AdsPower

Ready to manage multiple accounts?

Seven days free, then $9.99/month — one plan, everything included.

We'd like to use Google Analytics, a Google service, to understand how our website is used. It sets two cookies in your browser and runs only if you click Accept. You can change your choice at any time with Cookie settings. Cookie Policy

Sign-in cookies and the cookie that remembers this choice are always on; the website needs them to work.

Google Analytics, a Google service, helps us understand how our website is used. It sets two cookies, _ga and _ga_TVZHQ99TZW. It is now onoff in this browser. If your browser sends a Global Privacy Control or Do Not Track signal, it stays off. Cookie Policy