ScreenshotNeo

BlogAI agents

What Is a Browser Fingerprint? A Guide for AI Agents

Learn how browser fingerprints identify AI agents, which signals matter, privacy limits, and how to inspect pages without running your own browser.

By the ScreenshotNeo team1 October 20268 min read

Direct answer: A browser fingerprint is a combination of browser, device, operating-system, settings, network, and other observable characteristics that a website can use to recognize or re-recognize a visitor, user agent, or device. Unlike a cookie, the fingerprint can be inferred from requests and browser code. For AI agents, separate the browser’s technical fingerprint from the agent’s behavior: typing, scrolling, pointer movement, timing, and navigation can provide additional evidence.

W3C defines fingerprinting as a site’s ability to identify or re-identify a visiting user, user agent, or device through configuration settings and other observable characteristics. The definition is in the Privacy Working Group’s fingerprinting guidance. The guidance is endorsed by the Privacy Working Group, but the page says it is not endorsed by W3C itself or its members.

How browser fingerprinting works

A site normally combines many signals. One value rarely identifies a person by itself; the combination and how unusual it is are what make a fingerprint useful.

Pattern What the site observes Typical examples
Passive fingerprinting Information available in network requests Request headers, IP address or other network information, and protocol details
Active fingerprinting Values collected after the page runs code Viewport size, fonts, language, time zone, media devices, sensors, performance values, CSS features, and rendered graphics
Transient event correlation Related events across sessions A device posture change or a change in available media devices observed near the same time

Browser and operating-system configuration, device characteristics, environment, behavior, and timing side channels can all contribute. Embedded trackers can collect similar information from pages that include them. The Electronic Frontier Foundation’s Cover Your Tracks explanation describes practical examples such as fonts, language settings, and add-ons.

What information can be part of a fingerprint?

  • HTTP-level data: headers and network-level information that arrive with a request.
  • Browser identity: user-agent details and feature support.
  • Display and layout: screen and window dimensions, pixel ratio, color and rendering capabilities, and CSS behavior.
  • Locale: language, time zone, and related formatting settings.
  • Installed capabilities: fonts, add-ons, media devices, sensors, and APIs exposed by the browser.
  • Graphics and performance: rendered output, timing, and hardware-dependent behavior.
  • Interaction: typing cadence, scrolling, pointer movement, pauses, navigation order, and other event timing.

The available surface changes with browser versions, permissions, operating systems, extensions, privacy settings, and the page itself. A signal can also be missing, randomized, blocked, or shared by many users.

Browser fingerprints and AI agents

W3C’s Web User Agents document treats generative AI systems as web user agents when they present content, help people navigate, or carry out authorized actions. An AI agent that uses a real browser therefore exposes browser characteristics to the sites it visits.

Keep two questions separate:

  1. What browser is this? Technical signals such as headers, viewport, fonts, rendering, and available APIs answer this question.
  2. How is it behaving? Interaction timing and navigation patterns can indicate automation or distinguish one agent workflow from another.

The 2026 preprint FP-Agent: Fingerprinting AI Browsing Agents studied seven AI browsing agents and human users in a controlled sample. Its abstract reports that browser fingerprints were less distinguishing when agents shared a fingerprint, while behavioral features such as typing and scrolling helped distinguish agents from humans and from one another. This is preliminary evidence from a limited study, not a universal benchmark or a claim about every agent or website.

Inspect a fingerprint in your own browser

The following page runs locally in a browser and prints commonly exposed values. It is an inspection aid, not a complete fingerprinting system. It does not prove how a particular website identifies you, and values can be unavailable or intentionally reduced by privacy protections.

<!doctype html>
<meta charset="utf-8">
<title>Fingerprint signals</title>
<pre id="out"></pre>
<script>
const signals = {
  userAgent: navigator.userAgent,
  language: navigator.language,
  languages: navigator.languages,
  platform: navigator.platform,
  timezone: Intl.DateTimeFormat().resolvedOptions().timeZone,
  screen: {
    width: screen.width,
    height: screen.height,
    colorDepth: screen.colorDepth,
    pixelRatio: devicePixelRatio
  },
  viewport: {
    width: innerWidth,
    height: innerHeight
  },
  hardwareConcurrency: navigator.hardwareConcurrency ?? null,
  deviceMemory: navigator.deviceMemory ?? null,
  maxTouchPoints: navigator.maxTouchPoints,
  cookieEnabled: navigator.cookieEnabled,
  doNotTrack: navigator.doNotTrack ?? null,
  reducedMotion: matchMedia('(prefers-reduced-motion: reduce)').matches,
  darkMode: matchMedia('(prefers-color-scheme: dark)').matches
};
document.querySelector('#out').textContent = JSON.stringify(signals, null, 2);
</script>

Important limitations of this example

  • It intentionally avoids invasive tests such as canvas or audio rendering, device enumeration, or probing installed fonts.
  • Some properties are permission-gated, unavailable in headless browsers, or normalized by privacy-focused browsers.
  • A website can combine browser values with server-side request data and account information.
  • Behavioral evidence requires an interaction sequence; a static snapshot cannot represent it.

Collecting signals from an automated agent

If you operate an agent, collect only the information necessary for the task, document the purpose, and avoid treating a fingerprint as a person’s identity. A simple browser-side record can be sent to your own endpoint:

const record = {
  capturedAt: new Date().toISOString(),
  userAgent: navigator.userAgent,
  language: navigator.language,
  timezone: Intl.DateTimeFormat().resolvedOptions().timeZone,
  viewport: [innerWidth, innerHeight],
  pixelRatio: devicePixelRatio
};

await fetch('/agent-observation', {
  method: 'POST',
  headers: {'content-type': 'application/json'},
  body: JSON.stringify(record),
  credentials: 'same-origin'
});

Do not use this pattern to secretly identify people. A legitimate agent should tell the user what data it sends, keep retention short, and provide a way to clear local state where appropriate.

What reduces fingerprinting risk?

W3C groups mitigations into four broad approaches:

  1. Reduce the exposed surface: limit APIs and values to the entropy needed for the feature.
  2. Increase the anonymity set: make many users appear alike through common configurations and normalized values.
  3. Improve detection: make fingerprinting easier to observe and investigate.
  4. Clear local state: provide practical ways to reset stored information.

These approaches reduce exposure but do not guarantee that fingerprinting becomes impossible. The surface spans browser features and network layers, so eliminating it with one broadly deployed technical change is unlikely.

Cookies, VPNs, and private browsers

Deleting cookies removes cookie state, not the browser characteristics a site can observe again. A VPN can change or obscure some network information, but it does not prevent correlation through browser signals. EFF presents Tor Browser as an example of a browser designed to reduce fingerprintability; treat it as a mitigation, not a promise of anonymity. Cover Your Tracks can show what its test observes, but one result is not proof of universal anonymity or tracking immunity.

When comparing defenses, ask:

  • How much of the browser and network surface is reduced?
  • Do sessions blend into a larger anonymity set or become individually randomized?
  • Which compatibility or functionality is lost?
  • Can the remaining signals be detected and reset?
  • Are you evaluating browser signals, network signals, or both?

Or skip the browser setup

If your agent only needs a clean image or PDF of a page, ScreenshotNeo handles the browser capture through one API request. Before capture it accepts cookie and consent banners and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be disabled. Bot checks and CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing status.

See the ScreenshotNeo API documentation for all options, including full-page and element capture, device presets, dark mode, custom CSS and JavaScript, waits, blocking rules, headers, cookies, user agents, authorization, time zones, geolocation, transparent backgrounds, resizing, caching, signed links, asynchronous jobs, webhooks, bulk capture, usage data, and PDF output.

cURL

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python

import requests

r = requests.get(
    "https://api.screenshotneo.com/v1/shot",
    params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"},
    timeout=90,
)
r.raise_for_status()
open("shot.webp", "wb").write(r.content)

Node.js

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`ScreenshotNeo returned ${res.status}`);
const fs = await import('node:fs/promises');
await fs.writeFile('shot.webp', Buffer.from(await res.arrayBuffer()));

ScreenshotNeo is the first screenshot API to try when you need clean shots, billing only for clean results, and a paid plan starting at $5 for 3,000 shots. Its MCP server provides take_screenshot, get_page_info, and capture_pdf tools for Claude, Cursor, and other MCP clients. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.

Troubleshooting

Problem Likely cause Fix
Every session appears unique Rare combinations of viewport, fonts, extensions, or rendering values Use a common browser configuration, reduce exposed APIs, and avoid unnecessary extensions.
Clearing cookies changes nothing The site is using observable browser or network characteristics Review the exposed surface and reset other local state; cookies alone are not a complete mitigation.
A VPN does not stop correlation Only network location changed Evaluate browser signals separately from IP information.
Values are missing in automation Headless mode, permissions, or browser privacy settings Handle missing values explicitly and never treat null as a stable identity.
Agent is flagged despite a common fingerprint Behavioral or timing features differ from human interaction Review the workflow, request pacing, and authorization. Do not assume a browser fingerprint explains every decision.
Screenshot request returns an error Invalid access key, malformed URL, or a page that cannot load Check the key and URL, inspect the HTTP status and X-Page-Verdict/X-Billed headers, and retry only transient failures.

Performance, reliability, and cost considerations

  • Performance: Active fingerprinting adds page JavaScript and rendering work. Collect the minimum signals needed and avoid repeated probes.
  • Reliability: Signals vary with browser updates, permissions, privacy settings, extensions, and device conditions. Store provenance and timestamps rather than assuming permanent identifiers.
  • Privacy: A fingerprint can become identifying when joined with account or other data. Limit access, retention, and cross-site sharing.
  • Evaluation: A single test or study cannot establish universal uniqueness. The cited agent study covered seven agents in a controlled preprint experiment.
  • Capture cost: With ScreenshotNeo, clean shots are billed; bot checks, blank pages, timeouts, failed loads, and cache hits are not. Choose a cache TTL and async jobs when repeated or long-running captures make sense.

FAQ

Is a browser fingerprint the same as an IP address?

No. An IP address is network-level information. A fingerprint combines network observations with browser, device, environment, and sometimes behavior.

Can an AI agent avoid having a fingerprint?

An agent can reduce or normalize exposed signals, but a browser that accesses a site still presents some observable characteristics. Avoid promising perfect invisibility.

Does changing the user agent create a new identity?

Changing one value can make a combination less consistent and may itself look unusual. Fingerprinting is based on combinations, not a single string.

How many signals are needed?

There is no universal threshold. The usefulness of a fingerprint depends on the values available, how common the combination is, what other data the site has, and whether sessions can be correlated.

Is the seven-agent result a general benchmark?

No. It is the sample size of one early preprint study with controlled tasks, not an estimate of the number of AI agents or a ranking of detection systems.

Sources