Skip to main content
All Kernel browsers ship with anti-detection optimizations by default — you don’t need stealth mode for this baseline. Enabling stealth mode adds two managed services on top:
  1. Default proxy — traffic routes through an ISP proxy from a shared Kernel pool, providing a stable exit IP for the session.
  2. Automatic CAPTCHA solver — solves reCAPTCHAs, Cloudflare challenges, and similar tests automatically.
Both are opt-out so you can bring your own where it makes sense.
Web Bot Auth (WBA) adds a verifiable signing identity that participating sites can recognize and allow. KERNEL’s WBA token is a separate opt-in feature, enabled selectively on request for Startup Plan and Enterprise Plan customers. Enabling stealth mode alone doesn’t opt you in. Request WBA access.

IP Rotation Behavior

The default stealth proxy provides a static exit IP for the session — all connections within the session exit through the same IP address. A new session may exit through a different IP from the shared pool. If you need the same IP across sessions, create an ISP proxy and attach it with proxy_id. If you override the default with a residential proxy, exit IPs may change between connections. See Residential routing and IP behavior for details. To turn on stealth mode, set its flag when instantiating Kernel browsers:

Bring your own proxy or CAPTCHA solver

Anti-detection is the platform default, so you can freely mix in your own networking or CAPTCHA tooling. Common patterns:
  • BYO proxy, keep CAPTCHA solver — launch a stealth browser with your own proxy via proxy_id. Replaces the ISP default; CAPTCHA solver stays loaded.
  • BYO proxy, no CAPTCHA solver — launch a non-stealth browser with your own proxy_id. Full anti-detection config, no managed proxy or CAPTCHA extension.
  • Managed proxy, no CAPTCHA solver — launch a non-stealth browser with a defined managed proxy via proxy_id. Full anti-detection config with a Kernel managed proxy and no CAPTCHA extension enabled.
  • Disable the default proxy at runtime — on a running stealth browser, set disable_default_proxy to route directly while keeping the CAPTCHA solver.

Stealth with your own proxy

To run a stealth browser through your own proxy instead of the managed ISP default, pass both stealth: true and a proxy_id when creating the session. The CAPTCHA solver stays loaded; your proxy replaces the ISP default.
If you’re looking for proxy-level configuration with Kernel browsers, see Proxies.

CAPTCHA handling behavior

Below are tips for working with Kernel’s Stealth Mode auto-CAPTCHA solver across different challenge types and automation frameworks.

Anthropic computer use

Anthropic Computer Use stops when it encounters a CAPTCHA. Use Kernel’s auto-CAPTCHA solver by adding this to your prompt: "If you see a CAPTCHA or similar test, just wait for it to get solved automatically by the browser."

Cloudflare challenge

When encountering a Cloudflare challenge, our auto-CAPTCHA solver will attempt to handle it. Once the “Ready” message appears on the screen, continue with your intended browser actions (e.g., entering credentials and submitting a login attempt).
After the “Ready” message appears, don’t click the Cloudflare CAPTCHA checkbox — this can interfere with the solver.

hCaptcha (beta)

KERNEL can also attempt to solve supported hCaptcha challenges automatically. The hCaptcha solver is in beta and isn’t enabled for every organization by default. To turn it on, contact support with the website or workflow you’re testing, your expected volume, and whether you already use stealth mode, profiles, or custom proxies.