Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Websites do not identify bots with one magic header. They assess a request using signals such as its User-Agent, requested Client Hints, and browser characteristics that may contribute to a fingerprint. Those signals can suggest what software is making a request, but none alone proves that it is automated. Sites may also ask a visitor to complete a CAPTCHA or another trust check—an interaction that measures something different from a browser header.

What does a website mean by an automated visitor?

“Bot” can refer to very different clients: a search crawler, a monitoring script, a browser controlled by an automation framework, or software sending HTTP requests without a conventional browser. A site may care about different things in each case. A crawler may be expected to follow indexing rules; a service may want to reduce abusive traffic; a developer may simply be checking whether a page loads.

From the website’s perspective, the immediate evidence is what reaches its server and how the request behaves. A request header can describe a claimed client, and browser-exposed characteristics can help distinguish one client from another. Neither is a definitive label saying “human” or “bot.” The technical documentation from MDN explains these mechanisms; it does not establish how commonly particular sites combine them or what rules any specific site uses.

What signals can a site examine?

User-Agent: a claim about the requesting software

An HTTP request can include a User-Agent header. Its value may identify the requesting application and describe an operating system, vendor, or version. A site can use that information to adapt a response or as one input to a wider assessment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

It is not verified identity. A client can send a different string, browser strings can include multiple tokens, and strings can change. MDN describes browser-string detection as difficult and error-prone. User-Agent reduction also limits some of the details supporting browsers expose, in part to address privacy concerns. A site that needs to know whether a feature is available should use feature detection rather than infer capability from a browser’s name.

Client Hints: requested details about the client

Client Hints are request headers a server can proactively request. Depending on the browser and what the site requests, they can describe selected device, network, user-agent, or preference characteristics. Some hints are lower entropy; additional information may depend on a request by the server.

That makes Client Hints a way to obtain selected client characteristics, not a universal automation detector. They can also add information relevant to fingerprinting, so collecting more detail has a privacy cost. A hint is not an attestation that a request came from an unautomated person.

Fingerprinting: combining differentiating details

Fingerprinting means building up data points that can help differentiate clients. Examples discussed by MDN include browser details, installed fonts, and cookie contents. A website may be able to use several observations together even when no single one uniquely identifies a visitor.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A fingerprint is not an infallible, fixed serial number. Browsers can limit access to some information or introduce variation to make fingerprinting harder. What a site can observe depends on the browser, its protections, and the page’s access to relevant features. It would be inaccurate to assume that every site collects every possible attribute, or that one particular attribute identifies a person.

Trust checks: asking for a separate signal

A site can require an action such as solving a CAPTCHA, verifying an email address, or making a purchase to establish trust for a particular purpose. These checks do not turn a User-Agent into proof of identity; they add a different kind of evidence or interaction to the site’s decision.

MDN describes the Private State Token API as experimental. In certain contexts, it can let a site that has established trust convey a cryptographic token without sharing the user’s identity or enabling cross-site tracking. MDN cautions that Private State Tokens are not a replacement for CAPTCHAs or other trust-establishing mechanisms. Their experimental status and browser support can change, so check current implementation details before relying on them.

How certain is each signal?

Signal What it can tell a site What it cannot establish by itself Privacy or scope consideration
User-Agent The client’s claimed application and possibly operating system, vendor, or version. That the claim is genuine, or that the visitor is human or automated. Detailed strings can contribute to fingerprinting; reduction limits some exposed details.
Client Hints Selected client characteristics requested by the server, as supported by the browser. A definitive automation verdict. Requested details can add fingerprinting information.
Fingerprinting A combination of data points that may distinguish one client from others. An infallible, permanent identity or proof of automation. Browser restrictions and variation can limit or alter available details.
CAPTCHA or other trust check Whether a visitor completed a particular interaction or trust-establishing step. That every other request signal is authentic, or that all abuse is impossible. It is a separate trust mechanism, not a request-header identity check.

The table compares the roles described in MDN’s technical documentation, not a measured ranking of detection accuracy. A site’s decision can depend on context and a combination of evidence; the available material does not establish a universal formula or threshold.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can a website tell if you are using browser automation?

It may infer that a request is automated, but the signals described here do not make that conclusion certain. An automation-controlled browser still makes web requests and may expose headers or browser characteristics. A site can assess what it receives and may challenge the visitor, but a User-Agent or fingerprint alone is not proof that a particular automation tool is in use.

Likewise, a normal-looking header does not prove that a request is from a person using a regular browser. Headers are claims or descriptions, while fingerprinting combines observations and trust checks ask for a different kind of signal. Avoid treating any single visible value as a definitive answer.

If you operate a site, use the signal that matches the actual need. To adapt layout or behavior to an available browser capability, use feature detection. To communicate indexing preferences, use crawler directives. If you need to establish trust, choose an appropriate trust mechanism rather than treating an identification header as authentication.

What crawler headers and directives actually do

From: administrator contact, not authentication

The HTTP From header can provide an email address for the administrator controlling a robotic user agent. MDN warns not to use it for access control or authentication. A request carrying an address is not thereby verified as belonging to the organization or person named.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

X-Robots-Tag: indexing instructions for cooperative crawlers

X-Robots-Tag communicates indexing directions to search crawlers. Only cooperative robots follow such rules, and a crawler must access a resource before it can see the directive. It is not a general bot-blocking mechanism and does not verify a crawler’s identity.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

For developers: interpret capture failures carefully

A browser automation or screenshot job can fail for reasons unrelated to a bot verdict: a blank response, a load timeout, a consent banner obscuring content, a CAPTCHA, or a page that does not finish loading. A screenshot is evidence of what the capture client received, not proof of why the website returned that result. Record the response, page state, and relevant headers before drawing conclusions; do not assume every failed capture means a site detected automation.

If you need to inspect a page visually, use an authorized capture method and respect the site’s access rules. ScreenshotNeo is a website screenshot API and MCP server for developers. It can help with capture workflows, but it does not make a site’s bot assessment certain or replace permission to access a page.

Or skip the browser setup

One GET request can request an image or PDF capture through ScreenshotNeo’s API. For example, this cURL request saves a WebP screenshot of Stripe:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Equivalent Python:

import requests

r = requests.get(
    "https://api.screenshotneo.com/v1/shot",
    params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"},
    timeout=90,
)
open("shot.webp", "wb").write(r.content)

Equivalent Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

ScreenshotNeo accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; those steps can be turned off. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits cost nothing, and response headers report the page verdict and billing status. Its MCP server provides take_screenshot, get_page_info, and capture_pdf tools for Claude, Cursor, and other MCP clients. The Free plan includes 1,000 shots per month without a card; paid plans start at $5 for 3,000 shots. See ScreenshotNeo for the service and the documentation for request details. Sign up for 1,000 free screenshots a month, with no card required.

Common misreadings to avoid

  • “The User-Agent says Chrome, so it must be Chrome.” The value can be changed or misleading; it is not authenticated identity.
  • “A fingerprint uniquely identifies every visitor.” A fingerprint combines differentiating details, and browser protections can limit or vary what is exposed.
  • “A CAPTCHA proves the browser is human.” It is a trust check, not a guarantee about every request or a replacement for broader judgment.
  • “Robots directives stop every bot.” Indexing directives are for cooperative crawlers and are not access control.
  • “A screenshot failed, therefore automation was detected.” Load failures, blank pages, challenges, and other page conditions can all affect a capture; the failure alone does not establish the cause.

Frequently Asked Questions

Does a website have to use JavaScript to identify automated traffic?

No single method is required by the mechanisms described here. User-Agent and Client Hints are HTTP request headers, while fingerprinting may combine browser-exposed data. The cited documentation does not establish which combination a particular site uses.

Does X-Robots-Tag tell a site that a visitor is a bot?

No. It gives indexing directions to cooperative crawlers; it does not authenticate the sender or serve as a general bot detector.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.