{"repo":"okasi/bot-signal","free":true,"listed":false,"github":"https://github.com/okasi/bot-signal","clone":"git clone https://github.com/okasi/bot-signal.git","description":"TypeScript bot detection: catch WebDriver, headless Chrome, Playwright/Puppeteer, robotic mouse/typing, datacenter IPs, JA3 TLS mismatch & timezone spoofing — browser + Node.","language":"TypeScript","stars":556,"topics":["anti-bot","automation-detection","behavioral-analysis","bot-detection","browser-fingerprinting","cybersecurity","fraud-protection","geoip","mouse-movement","security"],"license":"MIT","category":"security-tools","readme_excerpt":"bot-signal Bot detection for JavaScript and Node.js — detect headless Chrome, Playwright, Puppeteer, Selenium and scripted input. bot-signal is an open-source, TypeScript-first bot detection library that scores three independent layers: instant browser checks (automation artifacts, native tampering, cross-realm and GPU contradictions, CDP), behavioral analysis of mouse, touch, scroll and typing, and server-side IP reputation, TLS/JA3 fingerprint and timezone validation. Start with one isHuman() call, or read every weighted signal yourself. No API keys, no external service, no data leaves your infrastructure. Quick start · Detection modes · Signals · API · Examples · FAQ --- Why bot-signal? Most bot-detection snippets are copy-pasted checks that rot quickly. The bot-signal package gives you a maintained, typed, testable toolkit that covers the full stack: Live demo — run instant and behavioral checks in your browser. Layer Runs where Catches ------- ------------ --------- Instant Browser (sync/async) Automation artifacts, native tampering, realm/UA/GPU inconsistencies, CDP Behavioral Browser (over time) Robotic mouse/scroll/typing, synthetic events Server Node = 22 Datacenter IPs, AbuseIPDB, TLS fingerprint mismatch, timezone spoofing - No API keys — GeoIP and IP blocklists are bundled and updated weekly (note: the full package is 1.8 MB tarball / 16 MB unpacked primarily due to the blocklist data) - TypeScript-first — full types, ESM + CJS, sideEffects: false - Bundler-safe —","default_branch":null,"files":null,"tree":[],"storefront":"/r/okasi","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/okasi/bot-signal/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}