EnvTrace Browser Fingerprint Methodology

EnvTrace Current version 1.0 Last reviewed

EnvTrace Browser Fingerprint Test evaluates whether the fingerprint signals exposed by the current browser form a coherent browser environment.

The assessment looks at five areas:

  • Identity Consistency
  • API Integrity
  • Graphics & Hardware
  • Cross-context Consistency
  • Stability

The result includes:

  • a fingerprint consistency score
  • assessment coverage
  • results for the five assessment dimensions
  • specific signals that need review
  • the raw fingerprint data exposed by the browser

A higher score means that fewer obvious conflicts were found among the checks that could be completed.

Browser fingerprint signals visible to websites

When a browser loads a webpage, it exposes a range of browser and device characteristics.

EnvTrace currently reads and evaluates signals including:

  • User-Agent
  • browser and version
  • operating system
  • Platform
  • Client Hints
  • screen dimensions
  • Device Pixel Ratio
  • CPU thread count
  • device memory
  • touch capability
  • language
  • timezone
  • Canvas
  • WebGL Vendor
  • WebGL Renderer
  • Audio
  • detected fonts
  • WebRTC
  • automation-related signals

Some identity-related values are also collected separately from the main page, an iframe, and a Web Worker so EnvTrace can compare what different execution contexts report.

These signals form the basis of the fingerprint assessment.

Fingerprint consistency score

The fingerprint consistency score ranges from 0 to 100.

It summarizes how well the browser signals available during the current assessment agree with one another.

The score starts at 100. When EnvTrace finds a clear conflict or a signal that needs review, the score is reduced according to the strength of the evidence and the assessment dimension involved.

Current findings can fall into categories such as: strong conflict, strong evidence, needs review, and observation. Observations are recorded but do not necessarily reduce the score.

Each category of checks also has a deduction cap so that one underlying issue does not reduce the score repeatedly through multiple closely related rules. The final score is composed from five assessment dimensions.

Five assessment dimensions

Identity Consistency

Identity Consistency checks whether the browser identities exposed through different interfaces agree with one another. The assessment can compare:

  • User-Agent
  • browser brand
  • browser version
  • operating system
  • Platform
  • Client Hints
  • mobile indicators
  • other browser identity signals

For example, if the User-Agent reports Windows and both Platform and Client Hints also indicate Windows, those signals support the same browser identity.

If separate interfaces report clearly conflicting browser, operating-system, or device identities, EnvTrace records a finding that needs review.

Current weight: 30%

API Integrity

API Integrity checks whether browser interfaces exposed to the page show obvious implementation anomalies. Current checks can include:

  • automation-related indicators
  • whether selected APIs still behave like native browser implementations
  • unusual overrides on Navigator properties
  • clear differences when similar information is read through different interfaces
  • signs that selected browser properties may have been modified in an unusual way

This dimension asks whether the browser APIs visible to the page behave consistently with the rest of the browser environment.

A single API signal does not determine whether the entire browser profile is problematic. EnvTrace evaluates these signals together with other evidence.

Current weight: 25%

Graphics & Hardware

Graphics & Hardware checks whether the browser's reported device identity agrees with graphics and hardware information visible to the page. Current signals can include:

  • WebGL Vendor
  • WebGL Renderer
  • operating system
  • device type
  • CPU thread count
  • Device Memory
  • screen dimensions
  • Device Pixel Ratio
  • touch capability

If the operating system, graphics stack, and device form factor contain a clear contradiction, EnvTrace records it as a finding that needs review.

EnvTrace focuses on stronger conflicts rather than treating a single GPU name, memory value, or thread count as proof that the whole browser environment is invalid.

Current weight: 20%

Cross-context Consistency

The same browser identity can sometimes be observed from more than one JavaScript execution context.

EnvTrace compares selected signals available from the main page, an iframe, and a Web Worker.

If the same browser profile exposes clearly different platform, browser, or system identities across these contexts, EnvTrace records a cross-context inconsistency.

This dimension is intended to answer whether different execution contexts inside the same browser see the same browser identity.

Current weight: 15%

Stability

Stability checks whether selected fingerprint signals remain consistent during the same assessment.

EnvTrace currently repeats selected measurements such as Canvas, Audio, and WebGL.

If repeated reads during the same page session produce unexpected changes, the result may be recorded as a stability issue.

EnvTrace can also compare the current browser with a previously stored result on the same device.

Changes between separate tests are currently treated mainly as observations because normal events can also change fingerprint signals, including browser updates, browser profile changes, operating-system changes, and privacy features implemented by the browser.

A changed value is therefore not automatically treated as an error.

Current weight: 10%

Assessment coverage

Not every browser supports the same APIs. Browser version, privacy settings, permissions, and runtime conditions can also prevent some signals from being read.

EnvTrace therefore does not treat missing data as equivalent to passed.

Coverage shows how much of the planned fingerprint assessment had enough data to complete a determination.

The score and coverage should be read together.

For example, 98 / 100 · Coverage 96% means that few obvious conflicts were found among the completed checks, while a small number of checks did not have enough data to run.

Signals that need review

Below the overall result, EnvTrace lists the specific findings that need further review. Each finding can describe:

  • which signal triggered the rule
  • which values conflict
  • which assessment dimension it belongs to
  • the strength of the evidence
  • why the finding was recorded

Examples can include:

  • User-Agent and Client Hints reporting different platforms
  • Platform conflicting with the reported operating system
  • a graphics environment that clearly conflicts with the reported device identity
  • the main page and Worker reporting different platform identities
  • core fingerprint signals changing unexpectedly during the same assessment

The individual findings are more useful for diagnosis than the overall score alone.

Raw browser fingerprint data

EnvTrace also displays the browser information actually exposed to the page. This can include:

  • browser
  • User-Agent
  • operating system
  • Platform
  • Client Hints
  • screen
  • Canvas
  • WebGL
  • Audio
  • fonts
  • language
  • timezone
  • hardware information

These raw signals are the inputs used by the assessment. If a finding needs further investigation, the underlying values can be reviewed here.

The score helps locate a problem. The raw signals help explain it.

What this test is useful for

Browser Fingerprint Test can be used with standard browsers as well as configured or modified browser profiles, including antidetect browsers, privacy-focused browsers, separate browser profiles, browser automation test environments, virtualized browser environments, and browsers with selected properties modified.

For a configured browser profile, the main question is:

After the browser has been configured, do the identity, API, graphics, hardware, and execution-context signals visible to a website still agree with one another?

Changing only the User-Agent does not mean that every other browser signal changes with it. Platform, Client Hints, WebGL, screen, hardware, and other interfaces may still expose different information.

EnvTrace surfaces these browser-side conflicts when they are observable from the page.

What a score of 100 means

A score of 100 means no obvious conflicts were found among the fingerprint checks that had enough data to run.

It does not mean:

  • the browser cannot be identified by a website
  • a third-party platform will necessarily accept the environment
  • an account cannot be restricted
  • the browser exactly matches a specific physical device

Third-party websites and platforms may use information that EnvTrace cannot observe, including:

  • server-side request signals
  • TLS and network-protocol characteristics
  • account history
  • login history
  • behavioral data
  • device history
  • correlations across multiple visits
  • private detection rules

EnvTrace evaluates only the browser fingerprint signals that are observable from the current webpage.

How this differs from Environment Consistency

Browser Fingerprint Test primarily asks whether the browser is internally consistent. This includes browser identity, API behavior, graphics and hardware, execution contexts, and stability.

Environment Consistency asks whether the browser environment aligns with the current network environment. Examples include:

  • browser timezone compared with the current network environment
  • browser language compared with the exit country
  • WebRTC public addresses compared with the current exit IP
  • device signals considered alongside the wider environment

A browser profile can therefore be internally consistent while still being inconsistent with the network environment it is using. These assessments answer different questions.

How to read a browser fingerprint result

A useful order is:

  • Check the fingerprint consistency score to see whether the browser contains obvious internal conflicts.
  • Check coverage to see how much of the assessment actually ran.
  • Review flagged signals to understand exactly which rules were triggered.
  • Check the five dimensions to see where the findings are concentrated.
  • Review the raw fingerprint data to see what the website actually observed.

If the browser itself appears consistent, the next step is to review whether it also aligns with the current IP, timezone, language, and WebRTC environment in the Environment Consistency assessment.

Method version

Version 1.0 defines the current browser fingerprint assessment across five dimensions:

  • Identity Consistency
  • API Integrity
  • Graphics & Hardware
  • Cross-context Consistency
  • Stability

It also defines the fingerprint consistency score, assessment coverage, signals that need review, and raw browser fingerprint information.

This methodology will be versioned when there is a material change to the collected signals, assessment rules, dimension weights, important thresholds, or the meaning of the results.

Visual changes, wording corrections, and implementation changes that do not affect the meaning of the assessment do not necessarily require a version update.