Maskbreak is free.
All of it.
Maskbreak tells your site whether a visitor is hiding behind a VPN, proxy, Tor or cloud server — naming the service when it is known — and whether their browser is a bot or a fake. There are no plans, no tiers and no card: one API key gets all of it, 1,000 visitor checks an hour.
- Visitors hiding their connection — VPNs, residential proxies, Tor and cloud servers, with the service named when it is known (Proton VPN, Bright Data, AWS) rather than guessed
- AI crawlers and scrapers — the ones taking your content to train on, and the ones pretending to be browsers to do it
- Bots and automation — headless browsers, Puppeteer and Playwright, scripted signups, checkout and inventory bots
- Multi-accounting — one device wearing many accounts, linked per-customer and hash-only, so trial farming and bonus abuse stop being invisible
- Fake browsers — Kameleo, GoLogin, Multilogin and the other antidetect tools, caught by the fact that they are spoofing at all rather than by any one fingerprint
If your problem is one of those, the answer below is the whole product. There is no better version of it behind a paywall.
Free during open beta. No card required. At least 30 days’ notice before paid changes.
Get your API key- 1,000 requests / hour per API key — enough for most production signup, login and checkout flows
- Every check, nothing held back: VPN and proxy detection with the service named when known, Tor and cloud-server detection, fake-browser, bot, emulator and tampering checks
- Device intelligence — stable visitor ID, tampering score, device-to-account linking
- Webhooks to Slack, Discord or your own endpoint
- Hosted MCP server so AI agents can screen addresses on your key
- Dashboard, CSV export, recent activity, IP lookup
- 2FA and a reviewable session list with per-device revocation
- Official Node, Python and PHP SDKs, and deterministic test tokens so your fraud paths run in CI
- Support by email at support@maskbreak.com
Past the hourly limit you get an HTTP 429 with Retry-After. Never a surprise invoice, because there is no invoice. Best-effort uptime targeting 99.9%, measured on the public status page.
No hourly limit for hospitals, public health, government, election offices, emergency services, universities and the non-profits that fight abuse.
See who qualifies and apply- No hourly cap on
/v1/evaluateand/v1/lookup— the 1,000-an-hour limit is removed from the key you already have, nothing to rotate - The same product as above, because there is no other one: every signal, the DPA, the SDKs, the dashboard
- Institutional email domains (.gov, .edu, .nhs.uk and the like) are fast-tracked; everyone else is verified by registry and website within a business day
- Under attack right now? Say so on the form — the cap comes off the existing key first and verification follows
- What we ask: protect your own services, no surveillance of individuals, no resale. No logo rights, no case-study obligation, no expiry
Companies that outgrow the free tier are not left out: the startup and enterprise evaluation program unlocks up to a million evaluations a month.
Free does not mean undocumented. These exist and are self-serve.
- Data Processing Agreement aligned to UK and EU GDPR Article 28, with the applicable transfer terms
- Sub-processor list with a dated change log
- Security whitepaper — architecture, data handling, retention
- Service level terms and the status page
- No certifications yet. Maskbreak is pre-audit for SOC 2 Type II and holds no SOC 2, ISO 27001, HIPAA BAA or PCI DSS attestation. Said plainly because a questionnaire will ask.
Common questions
If we're missing something, email support@maskbreak.com.
What does Maskbreak actually do?
Your website asks Maskbreak about a visitor at signup, login or checkout. Maskbreak answers whether that visitor is hiding behind a VPN, proxy, Tor or cloud server — naming the service when it is known — and whether the browser is a bot or a fake, then returns allow, review or block. A VPN on its own returns review; proxies, Tor, bots and tampered browsers return block. Your code decides what to do with that answer.
Does it detect VPNs and proxies?
Yes. On a live visit Maskbreak identifies VPN, proxy, Tor and datacenter connections and names the service (for example Proton VPN or Bright Data) when it is known. A normal home or mobile connection adds nothing to the risk score.
What happens when I pass 1,000 requests in an hour?
You receive an HTTP 429 response with a Retry-After header indicating seconds until the limit resets. Your existing valid evaluations continue to be served — no broader account effects. The hour rolls forward; no monthly quota involved.
What counts as a request?
One server-side call to /v1/evaluate or /v1/lookup counts as one request. Loading the client SDK on your pages does not count — only your backend calls do. The deterministic test_* tokens are never billed, and the public sk_test_sandbox key for CI never touches your quota at all.
Is a Data Processing Agreement available?
Yes — self-serve. Our DPA is aligned to UK GDPR / EU GDPR Article 28, includes the applicable international-transfer terms and a current named sub-processor list, and is published at maskbreak.com/dpa, where it binds on acceptance with no signature required. A PDF is available for vendor files, and a countersigned copy from support@maskbreak.com. Our Cookie Policy separately describes providers used by the public website.
Why is it free? What is the catch?
Maskbreak is free during open beta, with 1,000 visitor checks per hour and no credit card required. This is not a promise of free access forever. If we introduce paid plans or change the free allowance, we will email affected users at least 30 days in advance, as set out in our Terms of Service. There are no retroactive charges.
Is the free version limited compared to some paid one?
No, because there is no paid one. Nothing is tier-locked: the same signals, the same verdict engine, the same device intelligence and the same SDKs. The only ceiling is the rate limit.
What if I need more than 1,000 requests an hour?
Email support@maskbreak.com and say roughly what you are doing and what volume you expect. The limit is an anti-abuse backstop rather than a sales gate.
Is there a version with no rate limit at all?
For public-interest organisations, yes. Hospitals and health systems, public health and medical research, government at any level, election authorities, emergency and crisis services, universities and registered non-profits fighting abuse can apply on the public-interest program page to have the hourly cap removed from their key. Institutional email domains are fast-tracked and the answer takes a business day. For everyone else the free tier is 1,000 requests an hour and the enterprise evaluation program covers larger volumes.
What compliance certifications do you hold today?
None. Maskbreak is in open beta and is pre-audit for SOC 2 Type II. We do not currently hold SOC 2, ISO 27001, HIPAA BAAs, or PCI DSS attestation, and we will not claim otherwise. Roadmap detail (selected audit firm, scope, timeline) is shared with serious enterprise prospects under NDA.
Where is data hosted?
Application infrastructure runs on Railway; the primary database is Turso (managed libSQL). The full sub-processor list — with a dated change log and 30-day advance notice — is published at /sub-processors. Custom data residency arrangements (EU-only, US-only) are available for enterprise customers on request.
How do I report a security issue?
Email support@maskbreak.com with the subject prefix [SECURITY]. Full scope, response targets, and safe-harbour terms are documented at /responsible-disclosure.
Ready when you are.
An API key takes about a minute, and there is nothing to pay at the end of it.