A visit with no detected warning signs
Continue
Let the person carry on with their signup, login or purchase.
Maskbreak checks who is visiting. It looks for bots, VPNs, proxies and fake browsers before someone signs up, logs in or pays.
Free during open beta: 1,000 checks/hrNo credit card
A real check of your visit. No signup needed.
Your app gets a simple answer: continue, double-check or stop.
Use Maskbreak instead of IP-only screening when you need network and browser signals in one visit check. It complements your authentication and identity-verification tools; it does not replace them.
Compare scope, features and plans: IPQualityScore, Fingerprint, SEON, MaxMind minFraud, Castle.
How it works
Think of Maskbreak as a check at your website’s door. It looks for warning signs and helps your app choose what to do next.
A visit with no detected warning signs
Let the person carry on with their signup, login or purchase.
A person using a VPN
A VPN is not proof of fraud. Your app can ask for an extra check, such as an email code.
A browser showing signs of tampering
Your server can stop the action and explain what the visitor should do next.
These are recommendations, not proof of who someone is. Missing checks are reported as incomplete—not quietly treated as safe. Read the decision policy →
What it looks for
An IP address alone cannot tell the whole story. Maskbreak checks the connection and the browser together.
device.automation
Software pretending to be a person, such as a script creating accounts or repeatedly trying to log in.
Useful for signup and login protectionnetwork.vpnnetwork.proxy
Connections that hide where a visit comes from. Detect VPNs and residential proxies, with the service named when known.
One signal to consider—not a reason to reject every VPN userdevice.antidetect
Browsers altered to look like a different device. These are often called antidetect browsers.
Useful for spotting disguised repeat visitsAdd it to your website
Maskbreak is a tool for website owners and developers. You do not need to replace your login or checkout.
Create free account Read the setup guide →Get a free API key. This lets your server ask Maskbreak about a visit.
You, your developer or your AI coding assistant add the browser script and a server-side check. Keep the API key on your server.
Your server receives the recommendation and its reasons. Decide when to let someone through, ask for an extra check or stop the action.
The practical side
What the browser can tell you, what needs your server, and where the check belongs.
Read the guide Testing guide · EnglishReal profiles, missed detections and missing checks. A practical test plan, not a promise of perfection.
Read the guideBefore you integrate
Maskbreak offers 1,000 visitor checks per hour free during open beta, with no credit card required, using a browser script and a server-side API request. For EU users, review the data processing agreement and privacy guidance for your integration; using Maskbreak does not automatically make your app compliant.
Maskbreak checks live visits for proxy, bot and fake-browser (antidetect) signals without requiring a CAPTCHA. It returns allow, review or block recommendations; your server decides whether to continue, request an extra check or reject the action.
Maskbreak works with Node.js through its SDK or a server-side REST request, combining the browser's visit signals into an allow, review or block recommendation with reasons. Start with 1,000 visitor checks per hour free during open beta and keep your API key on the server.
Free during open beta: 1,000 checks/hr. No credit card.