JustBrowser
Guides13 min read

Open-Source Multi-Account Browsers: What You Get, and What You Give Up

JustBrowser Platform Team·
open-source-antidetectundetected-chromedrivercamoufoxmulti-account-browserbrowser-fingerprintingbuildinpublicsaasstudioaiworkforcebuildwithclaude

A contractor I traded notes with in August had his open-source multi-account browser stack working. Forty scraper profiles on undetected-chromedriver, pinned versions, a patch file he'd carried across three jobs. Chromium shipped a stable release on a Tuesday. By Thursday every session was hitting a challenge page, and the GitHub issue he needed had fourteen people in it saying "same here" and nobody with merge rights.

He fixed it in about nine hours. Then it happened again six weeks later.

I have no standing to be smug here. I built more or less the same stack a couple of years back, told myself the profile layer was a weekend, and was still bolting pieces onto it four months later — every time I thought it was done, an account died and taught me about a signal I hadn't gated. The patch tax wasn't the part that got to me. It was never knowing what I'd missed until something broke.

None of that argues against open source. The tools did what they said. What it shows is the shape of the bill — free at the licence, invoiced in maintenance, due date set by someone else's release calendar. If you're weighing an open-source multi-account browser against a paid engine, that's the trade you're pricing. Not features. Cadence.

Three different things wear the same label

"Open-source antidetect browser" covers tools that barely belong in the same paragraph. Sorting them is most of the work.

Patched automation drivers. undetected-chromedriver, nodriver, patchright, rebrowser-patches, SeleniumBase's UC mode. These take a stock browser and driver and remove the tells automation leaves — flags, CDP side-effects, properties that scream "not a person". Not browsers, not identity tools. They make one session look unautomated.

Stealth plugin stacks. puppeteer-extra-plugin-stealth and its descendants: small JavaScript evasions applied at page load. Easiest to adopt, weakest architecture. An injected override sits on top of a real answer, and the seam is measurable — the property is enumerable when it shouldn't be, the prototype chain reads wrong, toString() on the patched function gives the game away. If I could remove one category from this post it'd be this one. Not because the projects are bad. Because they're what people reach for first, and they fail the quietest.

Actual forks. Camoufox is the serious one — Firefox, spoofing compiled into the browser's own C++ and exposed to Playwright. No injection layer, because there's nothing to inject over. Then a family with a different goal: Tor Browser, LibreWolf and Brave's farbling want you identical to everyone else or randomised per site, not unique per profile. Excellent for privacy, wrong tool for ten distinct accounts — a uniform fingerprint is shared and a reshuffling one is unstable, and account systems dislike both.

If the ground-up definitions are new, what an antidetect browser actually is covers the category. This post assumes you're deciding what to run.

What open-source multi-account browsers genuinely get you

Real advantages, stated plainly, because the vendor-written version of this skips them.

Zero licence cost. Chromium is BSD-licensed, Firefox is MPL, the tooling on top mostly permissive. Ten profiles or a thousand, the bill doesn't move.

You can read the patch. No closed product matches this. When a profile gets flagged you open the diff and know what was and wasn't spoofed, instead of filing a ticket.

It runs on Linux. Matters more than anything else here. Headless on a cheap VPS, in Docker, in CI on every pull request — where scraping fleets live, and the free tooling goes there natively.

It's native to your language. Python, Node, Go, C# — import a library and you're driving a browser. And nobody can reprice you or move a feature behind a tier.

Any team with a platform engineer and a Linux habit should take that list seriously before spending a cent. I'm not being generous for effect — against that team, on that stack, I don't think we win the comparison, and I don't think we should.

The three bills that arrive later

1. The upgrade treadmill never stops

Chromium ships fast, and every stable release can move a property or break whatever your patch depends on. A maintained project catches up in days; an unmaintained one never does, and you won't know which you picked until the week it matters. Pin versions and you're running a browser that's visibly behind — itself a signal. Don't pin, and you're one pip install from a broken fleet.

2. Everything around the engine, you build

Profile storage. Per-profile proxy binding. Per-profile DNS. WebRTC handling. Timezone and language matched to the exit IP. Cookie state that survives a restart. Warm-up, so an account isn't born into a blank history. Health checks. Sharing with a teammate without couriering a folder. None of it ships with a patched driver, and each piece is a week, then forever.

3. Verification is on you, and so is the clock

No checker results, no regression suite — you find out a patch regressed when accounts start dying, the most expensive possible detector. That's the part that still irritates me about running it yourself: the feedback loop goes through dead accounts. Nothing tells you. You infer it, late, from a ban wave.

And nine hours on a Thursday, twice a quarter, plus the profile layer, has a rate. Do that multiplication before calling anything free.

Patched driversStealth pluginsCamoufox (fork)Commercial engine
Removes automation markersYesPartlyYesYes
Engine-level spoofing (not injected)NoNoYesYes
Coherent identity set per profileNoNoPartlyYes
Profile store + state managementBuild itBuild itBuild itIncluded
Per-profile proxy + DNSBuild itBuild itBuild itIncluded
Runs headless on LinuxYesYesYesNo
Licence cost$0$0$0Subscription

Read the Linux row before the price row. It settles more of these arguments than the price does.

The coherence problem, concretely

Four failure modes I've watched trip real setups. Three of them I shipped myself at some point, so read this as confession rather than lecture. It's the fourth bill, and the biggest.

Canvas noise against a real GPU string. Jitter the canvas but leave WEBGL_debug_renderer_info reporting the actual card, and you've built a machine whose rendering changes while its hardware doesn't. More identifying than either signal alone.

Fonts filtered in one place out of three. Most JavaScript approaches override the measurement trick and stop. A determined enumerator still has the Font Access API and @font-face local(). Real gating covers all three together — an engine-level job, not a shim.

Headless defaults nobody checked. A headless session has no real window, so screen and viewport geometry follow headless defaults — profiles that should look like people on laptops report numbers that read as a server, and nobody notices because the script only sees the DOM. True of any API-started browser, ours included: send {"headless": false} when a session must look like a person's.

TLS, which happens before any of your JavaScript runs. Your handshake has a stable shape per build, offered in the first packet, outside anything a page script can patch. ClickzProtect — our sibling product, on the detection side — has the difference between browser and TLS fingerprinting written up. Independent identifiers: beating one buys nothing on the other.

For the full inventory of what gets read, the detection signals glossary is the reference — and cookieless tracking from the analytics side is worth an hour, written by people whose job is identifying returning visitors without cookies.

Deciding, in order

  1. Count your accounts per platform. One? Stop here. A patched driver if you're automating, nothing if you're not. Don't buy identity tooling for a problem you don't have.
  2. Name where it has to run. If the answer is "a Linux box in CI", the free stack is your stack — that decision is already made, and no Windows/macOS app changes it.
  3. Price your own hours, and check who maintains the thing. Weeks of platform work plus a recurring patch tax, against a subscription. Look at the last commit date and whether one person holds the keys.
  4. Test with the checkers before committing. CreepJS, IPHey, BrowserLeaks, Whoer — then again after the next browser release. That delta is the maintenance cost, measured rather than guessed.
  5. Sort the proxy first, always. A flagged address poisons every layer above it, free or paid.

Things people learn at month three

Four things worth knowing before you need them, whichever route you take.

Attaching a debugger over CDP can leave observable traces in the page depending on how the client behaves — the leak class rebrowser-patches addresses. Read its notes even if you never use it.

Don't create a fresh context to get a clean page. new_context() in Playwright builds an incognito context outside the profile, so your identity and cookie work isn't applied. Use the existing context and its first page. And browser.close() only disconnects your client — the profile keeps running until something stops it.

Selenium needs ChromeDriver matched to the browser core's major, or Selenium Manager fetches a driver for the machine's own Chrome and the attach fails.

And resist rotating a fingerprint that's working — a stable identity that ages is the goal. The automation and API glossary covers the vocabulary; the concurrency and rate-limit notes matter past a handful of profiles.

Where a commercial engine actually differs

Not "it's better" — specifically what's in the box that an open-source multi-account browser leaves you to assemble.

JustBrowser is a custom Chromium engine with the spoofing written in C++ and compiled into the core, patched with every upstream release. Real C++ engine patches at the canvas / WebGL / audio / font / screen layer, across 40+ identity parameters. navigator.webdriver returns false — not undefined, false — whether or not automation flags are set, and font sets are gated to the spoofed platform at engine level across all three enumeration paths.

Around it: per-profile proxy routing (HTTP, HTTPS, SOCKS5) with a tester reporting exit IP, ISP name, city, timezone, latency and blocklist reputation. Per-profile DNS-over-HTTPS pointed at Cloudflare, Google, Quad9 or your own resolver. WebRTC protection. Cookie warm-up across 127 curated sites in six categories. Profile health scoring. Owner, admin, member and viewer roles. Encrypted export using AES-256-GCM. For automation, a local REST API on 127.0.0.1:36542, Bearer-authenticated from the app's AI page, with CDP for Playwright, Puppeteer and Selenium — local only, and the reference at justbrowser.app/docs is generated from the app's real route registrations, so it can't drift.

Checker results we publish, reproducible rather than asserted: CreepJS 0% stealth and 0% headless, Whoer 90–100%, IPHey Trust "Good", BrowserLeaks no WebRTC leak.

The limits, stated rather than buried. Windows x64 and macOS on Apple Silicon only — no Linux build, so the VPS pattern the free tooling is good at isn't available here. No mobile app, no mobile identities. One plan at $9.99/month or $99.99/year with unlimited profiles, unlimited cloud sync and free team seats; the only free option is a 7-day trial that wants a card. A free seat runs profiles the owner shares with it and nothing else — no cloud sync of its own, no API, no AI tab.

Stop paying and your profiles stay on your machine and keep launching. You can keep up to five local profiles; cloud sync, team sharing and the API pause until you resubscribe.

Frequently Asked Questions

Is there a genuinely good open-source antidetect browser?

Camoufox is the honest answer — a Firefox fork with the spoofing patched into the browser's own C++ rather than injected as JavaScript, and driveable from Playwright. Architecturally it's the right idea, and the only free project here doing engine-level work instead of shimming over real answers. What it doesn't ship is the product layer: no profile store, no per-profile proxy or DNS plumbing, no cloud sync, no team sharing, no warm-up, no health scoring. You get the hard part free and build the rest — which is where the weeks go.

Can't I just use undetected-chromedriver instead of paying for an antidetect browser?

For a single account, or scraping a site that isn't fighting back, often yes — and you should, rather than buying what you don't need. Where it stops is multi-account identity. Patched drivers remove automation markers; they don't give profile two a different canvas, GPU string, font set, screen geometry and timezone from profile one. Ten sessions are ten clean-looking sessions from one identifiable machine, which is the exact pattern linking systems look for.

Does open source mean it's harder to detect?

It cuts both ways, and the second edge is sharper than people expect. You can read the patch and know precisely what it does — real value no closed product matches. So can the detection vendor. A published evasion is a published signature, and the stealth plugin ecosystem has watched modules get fingerprinted by the side-effects the evasion itself introduced.

What actually runs on a Linux server, and what doesn't?

This is where the free route wins outright and we won't pretend otherwise. Patched drivers, stealth stacks and Camoufox all run headless on a Linux box or in CI, which is why scraping fleets live there. JustBrowser doesn't — Windows x64 and macOS on Apple Silicon only, no Linux build and none on the roadmap, so a VPS deployment isn't a path. Worth separating two things: there's no Linux build, but a Linux identity is generatable — an x86_64 Linux fingerprint runs fine from a Mac or Windows host. The OS you present isn't the OS you run on.


Try JustBrowser

Antidetect browser on a custom Chromium engine, always current with upstream — not extension-based. Real C++ engine patches at the canvas / WebGL / audio / font / screen layer, so 40+ identity parameters are genuine, not faked. REST API for Playwright, Puppeteer, Selenium. One plan: $9.99/month or $99.99/year — unlimited profiles, free team seats, 7-day free trial.

Get started → · How it differs from Multilogin / GoLogin / AdsPower

Ready to manage multiple accounts?

Seven days free, then $9.99/month — one plan, everything included.

We'd like to use Google Analytics, a Google service, to understand how our website is used. It sets two cookies in your browser and runs only if you click Accept. You can change your choice at any time with Cookie settings. Cookie Policy

Sign-in cookies and the cookie that remembers this choice are always on; the website needs them to work.

Google Analytics, a Google service, helps us understand how our website is used. It sets two cookies, _ga and _ga_TVZHQ99TZW. It is now onoff in this browser. If your browser sends a Global Privacy Control or Do Not Track signal, it stays off. Cookie Policy