# Anti-Detection

What go-browser changes so automated Chrome looks closer to a regular browser, and where that stops.

## Launch flags

| Flag | Effect |
|---|---|
| `disable-blink-features=AutomationControlled` | Chrome does not advertise automation through Blink |
| `user-agent` | `Option.UserAgent`, or `DefaultUserAgent` (Chrome 124 on Linux x86_64) |
| `window-size=1280,960` | A desktop-sized window, matching the default viewport |
| `window-position=-32000,-32000` | Headed windows only: placed off screen |

## Injected stealth script

`Option.StealthJS` is registered with `EvalOnNewDocument`, so it runs before any page script in every document the tab loads. The embedded default does four things:

| Property | Value presented to the page |
|---|---|
| `navigator.webdriver` | `undefined` |
| `navigator.plugins` | Three entries: Chrome PDF Plugin, Chrome PDF Viewer, Native Client |
| `navigator.languages` | `["en-US", "en"]` |
| `window.chrome` | `{ runtime: {} }` |

Setting `StealthJS` replaces the default entirely; it does not append to it.

## Behavior

### Human-like scrolling

Scroll passes wait 150ms plus up to 300ms of random jitter and scroll smoothly over 300ms instead of jumping, see [Page Loading](/core-concepts-snapshots).

### Headed fallback

When a site still answers 403, 429 or 503, or serves a challenge page, a host with a GUI retries once with a headed browser, which passes checks that target headless Chrome. See [Fetch Routing](/core-concepts-routing).

## Limits

Anti-detection is limited to the flags, the stealth script, scroll pacing and the headed fallback. It is not a guarantee against every protection: TLS fingerprinting, CAPTCHA and behavioral scoring are not addressed.
