Privacy-first browser diagnostic

See what your browser exposes.

Run a transparent, local-first scan of the signals ordinary websites can observe. Understand the result, then choose what to change.

Before any script ranUS · TLSv1.3

This is what a website observes from your connection alone, with no fingerprinting script — the baseline every site starts from.

Country / region
US / OH
HTTP protocol
HTTP/2
TLS version
TLSv1.3
Cloudflare data center
CMH
Network
Anthropic, PBC
User agent
Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
Reveal the IP address this site received

216.73.217.32

Every site you open receives this to deliver a response. It stays out of your Browser ID and is never stored here.

  • No account. Start immediately.
  • No scan history. The application does not store your report on a server.
  • No inflated claims. Exposure is not the same as uniqueness.

The scan uses native browser APIs, one same-origin request for connection context, and a Cloudflare STUN probe for WebRTC exposure. It never asks for camera, microphone, or location access.

Live browser test

Your browser surface

Ready
Browser ID Not scanned yet

Your short browser-only ID will appear here after the scan.

Ready to scan. Nothing runs until you press the button.

Usually takes a few seconds. Progress advances only when a real collector finishes.

Signals explained

Why browsers can look different.

Fingerprinting works by combining ordinary implementation details. No single signal automatically identifies a person; the value comes from correlation and consistency across a larger surface.

Canvas fingerprinting

A site asks the browser to draw fixed text and shapes, then reads pixels and text measurements. Fonts, graphics drivers, rasterization, color handling, and operating-system behavior can alter the result.

WebGL fingerprinting

WebGL exposes renderer strings, limits, extensions, shader precision, and deterministic drawing output. Together they can reveal details about the graphics stack even when the browser reports a generic device name.

Audio fingerprinting

An offline audio graph can produce slightly different numeric output across engines, operating systems, and hardware. This test uses generated audio only and never opens the microphone.

Font fingerprinting

Text width and glyph metrics can reveal which common fonts are available. Installed applications, language packs, and operating-system defaults all influence the detected set.

WebRTC leak detection

ICE gathering may expose local or server-reflexive addresses needed for peer-to-peer connectivity. This scan contacts stun.cloudflare.com only after you start it, then compares any public candidate with the same-origin edge address.

Method

A transparent scan, not a uniqueness database.

Independent collectors read browser APIs that ordinary first-party JavaScript can access. Each collector settles separately as successful, unavailable, blocked, timed out, or errored, so one failure does not stop the rest of the report.

Browser-only values are normalized and hashed with WebCrypto SHA-256. Network context, WebRTC addresses, permissions, storage quota, media-device information, WebGPU, timestamps, timings, and errors are excluded from the Browser ID.

The Signature consistency card cross-checks browser identity, locale, graphics, display, hardware, automation, Worker, and WebRTC observations. It is derived locally from the collected report. Network checks are labelled, and no consistency result affects the Browser ID or exposure index.

The Exposure index is a versioned heuristic based only on assessed browser surfaces. It is not a measured population-uniqueness percentage, anonymity score, percentile, or probability of tracking. Unknown and unavailable results are reported as unassessed, not treated as safe.

Primary references include MDN Web APIs, the W3C fingerprinting guidance, and EFF browser tracking education.

Privacy

Your scan stays under your control.

No server-side report history

The application does not send the collected browser report or generated Browser ID to a database.

One explicit local baseline

Comparison data is saved only after you choose it, in local storage on this device, without network or IP fields.

Scoped exports

Concise, browser-only, and full exports make network context and WebRTC addresses an explicit choice. Reports can still contain identifying data.

Disclosed WebRTC probe

After you start a scan, ICE gathering contacts stun.cloudflare.com without a cookie to check address exposure. Candidate addresses remain in this tab unless you explicitly choose a full export.

Limits

What this report cannot tell you.

This tool has no representative population database, so it cannot tell you how many other people share a value or whether a site can identify you. Results vary with browser protections, device changes, updates, and API availability.

An unavailable result is inconclusive. It may reflect missing platform support, a browser policy, a timeout, or an implementation error. It must not be read as proof of protection.

Questions

Browser fingerprint test FAQ

What is a browser fingerprint?

A browser fingerprint is a profile assembled from browser, graphics, display, hardware, locale, capability, and sometimes network signals. The combination can help a site recognize a browser without relying only on cookies.

Does a VPN hide my browser fingerprint?

A VPN changes your public IP and network location. It normally does not change canvas, graphics renderer, fonts, screen, hardware hints, browser version, timezone, or language.

Is the Browser ID permanent?

No. It reflects normalized browser-only values available during this scan. Updates, display or font changes, privacy defenses, and browser randomization can change it.

Does this site store my fingerprint?

The application does not persist the scan payload or Browser ID on a server. The optional browser-only baseline is stored in local storage only after you press its save control.

Why can the report show my public IP?

Every website receives connection metadata to return content. Network context is separated from browser signals and excluded from the Browser ID, exposure index, local baseline, and browser-only export.

Can I completely stop browser fingerprinting?

You can reduce or standardize exposed signals, but eliminating every signal often requires disabling useful features or using a hardened browser mode. Choose protections for your threat model and site-compatibility needs.

What is canvas fingerprinting?

Canvas fingerprinting asks the browser to draw fixed text and shapes, then compares the resulting pixels or measurements. Graphics hardware, drivers, fonts, and rendering behavior can make the output useful for correlation.

What is a WebRTC leak?

A WebRTC leak occurs when ICE candidate gathering reveals a public or local address that differs from the address a proxy or VPN presents to the website. Modern browsers often obscure local candidates with mDNS.

How do I reduce my browser fingerprint?

Use a browser with built-in anti-fingerprinting protection, keep it updated, avoid unusual extensions and overrides, limit unnecessary permissions, and prefer common default settings. Retest after each change.

Is browser fingerprinting legal?

Legality depends on jurisdiction, purpose, notice, consent, and how identifiers are combined or retained. This diagnostic is educational and not legal advice; organizations should obtain advice for their specific use.

Last updated July 23, 2026

Terms & Privacy Policy

Privacy Policy

The interactive scan runs in your browser. The application does not store the collected scan payload, generated Browser ID, or exported report in a server-side history.

Connection context

A same-origin edge request returns limited connection metadata already visible to the site while delivering content, such as public IP, country or region code, network organization, protocol, and Cloudflare data center. Network context is separated from browser signals and excluded from the Browser ID, exposure index, browser-only export, and local baseline.

WebRTC leak check

After you start a scan, the browser may contact stun.cloudflare.com to gather ICE candidates. The probe sends no application cookie. Candidate addresses are used for the on-page leak comparison, never enter the Browser ID or exposure index, and appear only in the full diagnostic export.

Local storage

The comparison feature stores a browser-only baseline in local storage only after you choose “Save local baseline.” Replacing it requires confirmation. Deleting it offers an eight-second in-memory undo. Imported reports are parsed locally and are not uploaded.

Infrastructure

Cloudflare processes ordinary request metadata for service delivery, security, reliability, and abuse prevention under its own terms. This application adds no third-party analytics, advertising, session replay, or fingerprint vendor SDK.

Your choices

You can decline to run the scan, avoid the full diagnostic export, delete the local baseline, or clear this site's browser storage. Questions can be sent to privacy@browserfingerprint.org.

Check the export scope

Download report