dsh-antibrow is a free, open source data extraction & web scraping project written in JavaScript and released under MIT. It has 697 GitHub stars, 0 forks and 132 open issues, and was last pushed 26 days ago. On this registry it ranks #124 of 133 tracked projects in Data Extraction & Web Scraping, with 5 head-to-head comparisons available.

What is dsh-antibrow?

dsh-antibrow is a DeepSeek Harness plugin that hands an AI agent a browser with a persistent, engine-level spoofed identity, built for automation that has to log in and stay logged in.

What it is

dsh-antibrow is a plugin for the DeepSeek Harness agent ecosystem that gives the agent a real browser rather than a bare automation handle. The browser it exposes is AntiBrow, a Chromium fork whose fingerprint configuration lives at the engine level and is driven through the standard Playwright API, so an agent already fluent in Playwright needs no new surface. SDK documentation is published at antibrow.com/docs, and dated detection measurements — including the checks that fail — are published at antibrow.com/reports.

The concrete problem it addresses is that every other browser plugin in the ecosystem hands the agent a fresh Chromium on each run: the session dies with the process, the fingerprint is a stock automation build patched from page scripts, and traffic leaves from the operator's own machine. Anything behind a login therefore breaks, and re-logging-in on every run is precisely what a site treats as suspicious. Within DeepSeek Harness, dsh-antibrow replaces the plain Playwright plugin for any workflow where identity must persist between runs.

Key capabilities

  • Unlimited local profiles on the free tier, one persistent profile per name, each living on disk rather than on a plan.
  • 16 model-facing tools exposed under mcp__antibrow__*, covering sessions, profiles, proxies, page control and live view, all reachable from Code Mode as ordinary async calls.
  • Engine-level spoofing of user agent, platform, screen, fonts, canvas, WebGL and audio, answered by the engine before any page script runs, leaving no injected script for a detector to find.
  • Android device emulation through a single argument — "deviceType": "android" — producing touch points, mobile client hints, a phone viewport and phone GPU from a captured device.
  • WebAuthn passkeys stored with the profile rather than the machine's keychain, so a passkey registered in one run still signs in on the next.
  • Residential proxy egress with timezone, locale and reported network profile derived from the proxy's real exit, plus a last-session restore so the agent resumes where it stopped.
  • start_live_view streams the running agent's browser to a dashboard for watching long unattended runs.

Who uses it and how

  • Operators running agents that must check a mailbox, watch a dashboard, or keep a marketplace account warm across repeated unattended runs.
  • Teams giving every account, marketplace or persona its own isolated profile, so the agent never has to reason about which cookie jar it is holding.
  • Workflows where the browser's egress must leave from a residential proxy rather than the operator's own IP, with the reported timezone and language following that exit.
  • Scenarios needing cross-machine work: profiles synced between machines, or exported as a file and imported elsewhere for a human to finish by hand in the desktop app.
  • Environments needing the same profile on Windows, macOS or Linux, on x86_64 or arm64.

Getting started

Install the plugin into DeepSeek Harness with dsh plugin --profile add dsh-antibrow, then address the tools by their mcp__antibrow__* names.

How it compares

Among the DeepSeek Harness browser options named in the project's own materials, dsh-antibrow is the counterpart to a plain Playwright plugin: that alternative starts a new browser every run, shares a single data directory across parallel identities, patches the fingerprint from page scripts, and exits from your own IP, whereas dsh-antibrow persists profiles, isolates them per agent or account, spoofs inside the engine, and exits through a residential proxy.

When to use it — and when not

Pick it when a run needs a durable login, a coherent fingerprint story, or a phone-shaped session; skip it for reading a plain public page, where a stock browser is sufficient. Note that while profiles themselves are free and local, syncing them across machines and the managed residential proxies are paid parts of the plan, and minting identities from captured real-device fingerprints requires a paid plan. With 132 open issues open against a single initial fork and no forks recorded, potential adopters should read the issue tracker and the detection reports at antibrow.com/reports before committing to it.

project readme (upstream, from github) — read inline

dsh-antibrow

A DeepSeek Harness plugin that gives the agent a browser with an identity.

The browser is AntiBrow: a Chromium fork with fingerprint configuration at engine level, driven through the standard Playwright API. SDK docs are at antibrow.com/docs, and the dated detection measurements - including the checks that fail - are at antibrow.com/reports.

dsh plugin --profile <name> add dsh-antibrow

Why not a plain browser plugin

Every other browser plugin hands the agent a fresh Chromium. That is fine for reading a public page and useless for anything behind a login: the session dies with the process, the fingerprint is a stock automation build, and the traffic leaves from your machine.

A plain Playwright plugin dsh-antibrow
Identity between runs new browser every time one persistent profile per name
Logins gone when the process ends cookies and passkeys persist, optionally synced across machines
Fingerprint stock build, patched from page scripts spoofed inside the engine, before any page script runs
Egress your own IP residential proxy, with timezone, language and reported connection following its exit
Parallel identities one data directory to share one isolated profile per agent or per account
Tabs start from nothing last session restored, so the agent resumes where it stopped

The difference shows up the first time an agent has to be someone: check a mailbox, watch a dashboard, keep a marketplace account warm. A browser with no memory has to log in again on every run, and logging in again is exactly what a site treats as suspicious.

What it brings

  • Unlimited profiles, on the free tier. Not five, not fifty - profiles live on your disk, not on a plan, and creating one costs nothing. Give every account, every marketplace, every persona its own browser and stop reasoning about which cookie jar the agent is holding. Syncing them between machines and the managed residential proxies are the paid parts; the profiles themselves never are.
  • 16 tools for the model: sessions, profiles, proxies, page control, live view. All under mcp__antibrow__*, all reachable from Code Mode as ordinary async calls.
  • An Android phone, from the same API. One argument - deviceType: 'android' - and the agent is a phone: touch points, mobile client hints, phone viewport, phone GPU. See below.
  • Engine-level spoofing. The user agent, platform, screen, fonts, canvas, WebGL and audio are answered by the engine itself. Nothing is injected into the page, so there is no injected script for a detector to find.
  • A coherent story, not a pile of overrides. Timezone, locale and the reported network profile are derived from the proxy's real exit, because a US IP that reports Shanghai time is a contradiction a page can check in one line.
  • Passkeys survive. WebAuthn credentials are stored with the profile, not in the machine's keychain, so a passkey registered on one run still signs in on the next - and, with sync on, on another computer.
  • Watch it work. start_live_view streams the agent's browser to a dashboard, so a long unattended run is something you can look at instead of guess about.
  • Identities from real machines. On a paid plan a profile can be minted from a captured real-device fingerprint rather than a generated one - a whole coherent row off one physical machine, not a field-by-field invention.
  • Four builds, three operating systems: Windows, macOS, and Linux on both x86_64 and arm64. The same profile runs on any of them.
  • Portable, and not only to agents. Export a profile as a file and import it on another machine; leave it unsynced and it is still there, in the desktop app, for a human to open and finish by hand. The agent's browser and yours can be the same browser.

The phone

{ "profile": "shop-mobile", "deviceType": "android", "temporary": true }

Android profiles are built from whole captured devices - the screen, the GPU report and the client hints agree with each other because they came off the same physical phone, and the plugin picks a row rather than assembling one. Three of them ship inside the package, so a free-tier agent can create an Android profile with no network round trip at all.

The device type is fixed when the profile is created and never drifts afterwards: a profile that was a phone stays that phone. Android needs engine 151 or newer - if none is available the launch fails rather than quietly handing you a desktop browser that claims to be a phone.

Measured

On a macOS host, through a US residential proxy, 2026-08-15, engine 151:

Check Result
whoer.net disguise 90%
creepjs headless signal 0%
creepjs stealth signal 0%
creepjs platform hints Arial, "Segoe UI" - no font from the host
Reported platform vs user agent agree (Win32 / Windows)
Timezone vs proxy exit agree (America/Los_Angeles)

The 10% whoer deducts is WebRTC, which had no route to a STUN server on that run. Reproduce all of it with tests/smoke - the harness is in this repository, and it fails loudly rather than printing a number nobody checks.

Install

dsh plugin --profile <name> add dsh-antibrow
export ANTI_DETECT_BROWSER_KEY=<key>
dsh --profile <name>

The tools

Sessions launch_browser close_browser list_sessions
Profiles list_profiles create_profile delete_profile
Proxies list_proxies claim_proxy
Page navigate click fill evaluate get_content screenshot
Live view start_live_view stop_live_view

launch_browser takes a profile name and creates it on first use. Pass temporary: true for automation work: those profiles are local-only and stay out of the desktop app's list, while still persisting on disk.

Before you rely on it

  • One browser at a time on a free key. The concurrency limit is carried by the license and counted per machine, across every application using the same engine. Fan an agent out into parallel sessions only on a plan whose limit covers them, or the extra launches are refused.
  • The engine downloads on first launch (190-320 MB depending on platform), into a shared cache directory. The first launch_browser of a fresh install pays for that; later ones do not.
  • A persistent identity is a real identity. Two agents driving one profile at once is the same mistake as two people sharing one browser: last one to close wins. Give each its own.

Configuration

The bundle inserts one row, mcp-antibrow, configuring the harness's MCP client against the anti-detect-browser CLI. Override it from your profile's own cordis.patch.yml by targeting that id - a patch replaces the row's whole config, so restate every key you keep:

- id: mcp-antibrow
  config:
    serverName: antibrow
    transport: stdio
    command: npx
    args: ['-y', 'anti-detect-browser@^2.19.1', '--mcp']
    env:
      ANTI_DETECT_BROWSER_KEY: !!js process.env.MY_OWN_VAR
      ANTI_DETECT_BROWSER_CACHE_DIR: /var/lib/antibrow

Turn it off without uninstalling:

- id: mcp-antibrow
  disabled: true

To run the SDK from a checkout instead of npm, use the overlay this package ships:

export ANTIBROW_SDK_CLI=<checkout>/dist/cli.js
dsh --profile <name> --patch node_modules/dsh-antibrow/cordis.patch.local.yml

Compatibility

Verified against dsh 0.1.0-rc.6 and anti-detect-browser 2.19.1, 2026-08-15. DeepSeek Harness is a developer preview and says it will break compatibility; this line is the claim, and it rots without a re-test.

The SDK version floor is real: 2.19.1 is the first release whose close path ends the browser process instead of only dropping the debugging connection. On an older one a closed session leaves the browser running, which keeps that profile's directory locked - the next launch of it dies before the debugging connection is ready - and holds a concurrency slot for the rest of the run.

Links

License

MIT

Frequently asked questions

Is dsh-antibrow free to use?

dsh-antibrow is open source under the MIT licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does dsh-antibrow do?

DeepSeek Harness plugin: give your agent a browser with a persistent identity - engine-level fingerprint spoofing, unlimited free local profiles, Android device

What is dsh-antibrow written in?

dsh-antibrow is primarily written in JavaScript. Its source is publicly available at https://github.com/antibrow/dsh-antibrow, and it has 697 GitHub stars.