August 16, 2026 · By YasKad
CloakHQ/CloakBrowser

CloakBrowser: a custom Chromium build for automation with a coherent fingerprint

CloakHQ/CloakBrowser · 31,693★ · 2,635 forks

Everything worth knowing about CloakHQ/CloakBrowser: a wrapper for Python, JavaScript and .NET that downloads its own Chromium build and keeps the Playwright or Puppeteer APIs intact.


What CloakBrowser is

CloakBrowser is a Chromium browser distributed together with wrappers for Python, JavaScript and .NET. Its pitch is to replace the ordinary Playwright or Puppeteer executable with a Chromium binary carrying C++ source-level modifications, without changing the programming model of those clients. The repository claims 71 modifications targeting signals such as canvas, WebGL, audio, fonts, GPU, screen, WebRTC, network timing, automation, and input behavior via CDP.

Interconnected Python, JavaScript, and .NET icons linked by data streams, representing CloakBrowser's multi-language wrappers.

The project distinguishes two layers: the binary modifies browser characteristics, while the wrapper keeps automation options such as persistent profiles, proxy, timezone, locale, and humanize=True. According to its documentation, it does not include a CAPTCHA-solving service or proxy rotation: the user supplies their own proxy provider and keeps using the automation API they already know.

Futuristic blueprint of the Chromium engine with 71 highlighted nodes representing the source-code modifications to canvas, WebGL, audio, and WebRTC.

The origin: a recent organization and repository

The GitHub API dates the creation of CloakHQ/CloakBrowser to February 22, 2026. The owning account is the CloakHQ organization; PyPI likewise identifies CloakHQ as the package maintainer. No launch post, individual author’s public profile, or interview was retrieved that would allow the project to be attributed to a specific person, so that authorship is not inferred.

The narrative that the README and the official site do document starts from a technical tension: they present stealth libraries based on JavaScript injection or option tweaks as fragile against Chrome updates. The alternative they propose is compiling the modifications directly into Chromium and keeping an interface compatible with Playwright and Puppeteer. This is the vendor’s positioning, not an independent demonstration of superiority.

Philosophy and principles

  • Compatibility before a new API: the official migration flow replaces the Playwright bootstrap with from cloakbrowser import launch and keeps new_page() and goto().
  • Fingerprint and behavior as distinct problems: the binary’s patches cover browser signals, while humanize=True adds mouse curves, variable-timing keystrokes, and scrolling.
  • Contextual configuration: when using a proxy, geoip=True attempts to align timezone and locale with the exit IP; the README recommends visible-window mode and a residential proxy for strict targets.
  • Verifiable distribution: the wrapper claims to verify downloads with a pinned Ed25519 signature; the README also offers GPG checks, GitHub attestation, and Cosign for the Docker image.

Digital silhouette protected by holographic shields deflecting scanning beams aimed at canvas, fonts, GPU, and network timing.

World map with a residential proxy route and panels showing GeoIP, timezone, and locale synchronized.

Ed25519 cryptographic seal protecting a binary core, surrounded by the PyPI, npm, NuGet, and Docker logos.

How it works

  1. The Python, JavaScript, or .NET package is installed; on first launch it downloads and caches a roughly 200 MB binary for the platform.
  2. launch() starts that binary and returns a browser object compatible with Playwright; the JavaScript adapter also has a path for Puppeteer.
  3. Options can configure proxy, timezone, locale, geoip, headless, humanize, Chromium arguments, and the binary version.

Robotic hand operating a mouse with curved trails mimicking human movement, alongside data on variable keystroke timing and scrolling.

  1. For persistent sessions, launch_persistent_context() keeps cookies, local storage, and cache in a profile directory. For remote service, cloakserve exposes CDP and assigns separate processes per fingerprint seed.

Server rack with isolated browser windows in different colors, each with its own profile and fingerprint.

The README publishes its own table of tests against more than 30 detection services and states concrete results, such as 0.9 on reCAPTCHA v3 for the Pro version versus 0.1 for conventional Playwright. These are vendor measurements, dated July 2026, not a study reproduced by an independent source retrieved during this investigation.

Chromium shield deflecting bot-detection scanners, with a reCAPTCHA v3 score of 0.9 against 0.1.

Official and semi-official status

No evidence was retrieved that CloakBrowser has been accepted into an official Playwright, Puppeteer, Microsoft, or Chromium marketplace, nor of an endorsement from those vendors. It is published as a package maintained by CloakHQ on PyPI (cloakbrowser), npm (cloakbrowser), NuGet (CloakBrowser), and as the cloakhq/cloakbrowser image on Docker Hub. PyPI marks the project’s data as verified by its platform; that account verification is not equivalent to technical certification by Playwright or Chromium.

In practice it is a commercial-and-open-source adapter: the wrapper code is under MIT, while the README carves out a separate license for the compiled binaries. Binaries v146 and earlier are offered without redistribution rights; v148 and later require a Pro subscription to download, according to the project-linked BINARY-LICENSE.md.

The ecosystem

CloakHQ repositories

The query against the organization’s public repository API identified these companions:

  • CloakHQ/chromium-stealth-builds: precompiled patched Chromium binaries; the main project states it downloads them automatically. It had 19 stars and 4 forks.
  • CloakHQ/CloakBrowser-Manager: a self-hostable web manager for isolated profiles and unique fingerprints, presented as a free alternative to Multilogin; 855 stars and 198 forks.
  • CloakHQ/crawl4ai and CloakHQ/crawlee-python: forks hosted by the organization of crawling tools; their API descriptions don’t demonstrate a direct dependency, though CloakBrowser’s README includes integration examples with Crawl4AI and Crawlee.
  • CloakHQ/awesome-playwright: a curated list of Playwright projects; 11 stars and 2 forks.

Integrations, forks, and extensions

The README offers examples for browser-use, Crawl4AI, Crawlee, Scrapling, Stagehand, LangChain, Selenium, undetected-chromedriver, and agent-browser. The documented pattern is to start CloakBrowser with --remote-debugging-port=9242 and connect the other tool over CDP, or to retrieve the executable with ensure_binary() and the options with get_default_stealth_args().

The forks API showed, among the highest-starred, SayanDey322/CloakBrowser with 10 stars and several copies with one or two. All of them kept the same description as the original; no documentation was retrieved establishing them as a port, translation, extension, or alternative maintenance line. Nor was a non-English translation or a substantive community port identified as verifiable during this measurement.

Repo numbers

Measurement: August 6, 2026, GitHub API and page.

MetricValue
Stars29,669
Forks2,435
Real subscribers139
Commits visible on the page277
Open issues visible165
Open pull requests visible20
Main API languagePython
Code licenseMIT
CreatedFebruary 22, 2026
Last API pushAugust 5, 2026
Latest PyPI release0.5.5, August 5, 2026
Latest binary release retrieved on GitHubchromium-v150.0.7871.114.4-pro, July 31, 2026

The top contributors returned by the API were Cloak-HQ (225 contributions), dependabot[bot] (15), evelaa123 (13), honor2030 (4), and eofreternal (3). watchers_count in GitHub’s general response duplicates the star count, which is why subscribers_count is reported here as real subscribers. The API returned open_issues_count=185; the field can mix issues and open pull requests, consistent with the 165 and 20 that the page reports separately.

Docker Hub showed more than 100,000 downloads for the image, with no further precision. The official site showed 226,900 downloads for npm; no verifiable PyPI download counter or a monthly or weekly figure from those registries was retrieved.

How to contribute

Contribution is described briefly: the README invites opening issues and pull requests and states that maintainers respond quickly. No CONTRIBUTING.md, branching workflow, pull-request template, or specific evaluation harness was retrieved. The repository does contain tests/, examples, and GitHub workflows; no contribution policy that the project does not document is attributed to the latter.

How the community received it

The retrievable external evidence is limited and should be read with caution:

  • The Hacker News thread 47949500, posted by syabro on April 29, 2026, presented syabro/snitchmd, a container that combines CloakBrowser and rs-trafilatura to convert Cloudflare-protected URLs into Markdown. It got 8 points and 1 comment. The opening text describes CloakBrowser as one of two pre-existing pieces and warns that it does not solve interactive CAPTCHAs; it documents an integration use case, not an independent review. The only retrieved question, from sc0rp10, asked what the difference from Playwright was, with no follow-up assessment retrieved.
  • YouTube returned third-party videos, not selected by the vendor. Among them, a video from Indie Hacker News about pricing for automation and open-source tools (about 23,000 views, two months before the query), and another from Codedigipt presenting CloakBrowser as an automation tool (4,800). Their titles are promotional; their existence and visible view counts do not prove the conclusions they suggest.
  • No additional direct Hacker News threads were retrieved when searching for the exact name. Reddit returned an access challenge on queries for r/programming, r/webscraping, and r/LocalLLaMA; X required login. No Product Hunt page, verifiable mentions on Dev.to, Hashnode, podcasts or newsletters, nor an awesome-* list including the project were retrieved either. These absences describe the limits of the search, not a quality judgment.

CloakBrowser versus other approaches

ApproachVerifiable overlapDocumented difference
PlaywrightCloakBrowser returns objects and uses methods compatible with Playwright.Playwright uses its standard browser; CloakBrowser downloads its own Chromium with patches and fingerprint options.
PuppeteerThe JavaScript package offers cloakbrowser/puppeteer.The README recommends Playwright for reCAPTCHA Enterprise because it attributes intermittent automation leaks to CDP in Puppeteer; this is a vendor caveat.
playwright-stealthBoth aim to reduce automation signals in Playwright flows.CloakBrowser characterizes playwright-stealth as JavaScript injection, versus its C++ modifications; no independent benchmark of that comparison was retrieved.
undetected-chromedriverBoth relate to Chromium automation and anti-detection.The README offers an integration example and frames it as a Selenium option, not as a replacement for the native Playwright API.
CloakBrowser-ManagerUses CloakBrowser’s isolated profiles and fingerprints.It is a web profile manager, while the main repository is the binary and the automation libraries.

Quick usage guide

Installation and first launch

Python requires Python 3.9 or higher, per PyPI:

pip install cloakbrowser
python -m cloakbrowser info

The first startup downloads and caches the Chromium binary. For JavaScript, the README documents npm install cloakbrowser playwright-core; for Puppeteer, npm install cloakbrowser puppeteer-core. On .NET: dotnet add package CloakBrowser. Without installing anything locally, the official test is:

docker run --rm cloakhq/cloakbrowser cloaktest

Common workflows

  1. Replacing a Playwright bootstrap: change the import to from cloakbrowser import launch, run browser = launch(), open browser.new_page(), and navigate with page.goto(...).
  2. Using a proxy and geographic context: launch(proxy="http://user:pass@proxy:port", geoip=True, headless=False, humanize=True). The documentation recommends a residential proxy, visible-window mode, and humanization for targets with strict detection.
  3. Keeping a session: launch_persistent_context("./my-profile", headless=False) creates a profile; repeating the same path restores cookies and local storage. Playwright state can also be saved with launch_context(storage_state="state.json") and context.storage_state(path="state.json").
  4. Serving CDP in Docker: docker run -d --name cloak -p 127.0.0.1:9222:9222 cloakhq/cloakbrowser cloakserve, followed by pw.chromium.connect_over_cdp("http://localhost:9222") from Playwright. The port is bound to localhost because CDP gives full control over the browser.

Essential configuration

  • CLOAKBROWSER_LICENSE_KEY or ~/.cloakbrowser/license.key: enables downloading Pro binaries; python -m cloakbrowser login obtains or stores the key.
  • proxy and geoip=True: configure IP and timezone/locale alignment; GeoIP makes HTTP calls through the proxy to resolve its exit point.
  • headless=False and humanize=True: show the browser window and enable modeled mouse, keyboard, and scroll interactions.
  • launch_persistent_context("./my-profile"): a profile directory for persistent cookies and cache.
  • CLOAKBROWSER_RELEASE_CHANNEL=preview or release_channel="preview": selects the latest available preview build; info explains whether it has reverted to stable.

Common pitfalls and fixes

  • Blocked despite the patches: the README attributes many cases to IP reputation, geographic configuration, or headless mode. It proposes a residential proxy, geoip=True, headless=False, and humanize=True; on headless Linux, installing Xvfb and using DISPLAY=:99.
  • Font-based detection on Linux: for Kasada or Akamai, the project notes that fonts may be missing and affect emoji rendering; it points to its Linux font configuration. Windows metrics tuning requires a Chromium 148+ build and installed Windows fonts.
  • New sessions flagged over HTTP/2: the README suggests warming up a persistent profile once with args=["--disable-http2"] and reusing it, limiting that option to sites that need it.
  • Exposed CDP: don’t publish port 9222 without authentication. The official example uses 127.0.0.1; a reverse proxy must forward Host, X-Forwarded-Host, and X-Forwarded-Proto so the WebSocket URLs remain reachable.
  • uvloop on a web server: the documentation recommends --loop asyncio with Uvicorn to avoid subprocess pipe blocking.

Integrations and migration

Migrating from Playwright is a matter of one import and one bootstrap call. For frameworks that connect to Chromium — browser-use, Crawl4AI, and Scrapling — the README documents starting launch_async(args=["--remote-debugging-port=9242"]) and pointing the client at http://127.0.0.1:9242. The binary’s fingerprint works over CDP; humanization does not, unless patchBrowser and resolveConfig are imported from cloakbrowser/human in JavaScript. There are also examples for Selenium, Stagehand, LangChain, agent-browser, and AWS Lambda.

Use cases and who this repository can help

  • Teams already automating tests or web flows with Playwright can trial a low-code-change replacement: the browser keeps the usual page and context operations, while adding binary selection, profiles, and proxy options.
  • Monitoring, extraction, or QA services with persistent sessions can save cookies, local storage, and cache through a profile directory, or use cloakserve as an internal CDP endpoint for several clients. They must protect CDP access, since the documentation warns that it allows executing JavaScript and reading pages or files.
  • Teams connecting browser agents or crawlers to CDP have explicit paths for browser-use, Crawl4AI, Scrapling, and other tools. The project is especially relevant if those integrations need to control binary, fingerprint, proxy, locale, and timezone from a central point.
  • Container operators can run the Docker image for a cloaktest trial, package their own script, or deploy cloakserve. Real-world usefulness against a specific target must be validated legitimately and while respecting the target site’s terms of service, access limits, and privacy.

Resources


Note: this article combines the README, CHANGELOG, and repository pages, the GitHub, PyPI, and Docker Hub APIs, the official site, Hacker News, and YouTube results consulted on August 6, 2026. Figures and availability change over time.

Comments