Cloud Browser Agents Keep Failing Cloudflare. Your Own Chrome Doesn't.
Two AI stories crossed my feed this morning and neither one had anything to do with a browser. Hyperscalers signing natural gas deals to power the next datacenter buildout. Kog publishing numbers on squeezing more inference throughput out of GPUs people already own. Enormous capital, pointed squarely at the compute layer.
And then a friend messaged me a screenshot of his cloud browser agent stuck on a Cloudflare interstitial, spinning, for the fourth time that day.
Datacenter IPs are the loudest thing in the room
Every hosted browser agent runs from somewhere: AWS, GCP, Fly, Hetzner, a Browserbase pool. Those ASN ranges are published, catalogued, and scored by every anti-bot vendor that matters, and the score is not flattering. Cloudflare, DataDome, and Akamai all treat “request originating from a known cloud provider” as a strong prior toward automation, because that prior is correct the overwhelming majority of the time.
The address your agent calls from has probably been used for scraping this week by someone who isn’t you. That’s the whole ballgame on the first hop.
Your home connection is different. Comcast, BT, whoever. Residential ASN, low request volume, geolocation that matches the timezone the browser reports. Nothing to flag.
No cookies, no history, no benefit of the doubt
A fresh headless Chrome has an empty cookie jar. So the site sees a visitor with no session, no prior visits, no device-trust cookie, and it responds the way it responds to strangers: full login wall, then 2FA, then a code sent to a phone the agent can’t read.
That’s where most of these runs die. Not on the reasoning, not on the model, on step one.
Fingerprints
The third layer is the one people underestimate, because it’s dozens of small signals rather than one big flag. navigator.webdriver returns true unless someone patched it. The user agent string says HeadlessChrome, or it doesn’t and the rest of the profile contradicts it anyway. WebGL reports SwiftShader or llvmpipe as the renderer, since there’s no GPU in that container, and that string alone is nearly diagnostic. Audio output devices: zero. Installed fonts: a stock Debian image ships maybe thirty, your laptop has three hundred, and font enumeration has been a fingerprinting staple since long before anyone cared about AI agents. Screen dimensions that never change and don’t match any real display. Scrollbar width of zero. Battery API missing. Timezone set to UTC while the IP geolocates to northern Virginia. Mouse paths that move in perfectly straight lines with no overshoot, no jitter, no pause before the click.
Stealth plugins exist to paper over all of this, and they work until the next detection update, at which point somebody files an issue and waits. It’s an arms race that the side with the traffic data wins on a rolling basis. Hardening a headless profile to look human is real engineering effort spent producing a worse version of something you already have running on your desk.
Because you do already have it. It’s the window you’re reading this in.
So what actually loads the page?
The browser where you’re logged in. That’s it, that’s the fix, and it’s unglamorous enough that people keep skipping past it while shopping for a hosted runtime.
Dassi sits in the Chrome side panel and drives the tab you already have open. Same profile, same cookies, same residential IP, same GPU, same fonts, same everything, because none of it is being simulated. There’s no fingerprint to spoof when the fingerprint is genuinely yours. Gmail loads. Your CRM loads. The internal dashboard behind SSO loads, because the SSO session is already sitting there in the cookie jar. We’ve written about the login half of this problem before and it’s the same shape: cloud agents start every task as a stranger, and the web treats strangers accordingly.
What I’m not claiming
A local agent doesn’t make CAPTCHAs vanish. Some sites throw a challenge at everyone on certain routes, and you’ll click the checkbox yourself, which takes two seconds. A handful of sites detect extension-driven DOM manipulation and object to it. Rate limits still apply, and running your own browser isn’t a license to behave like a crawler on someone else’s server. If you hammer a site from your home IP you’ll get blocked from your home IP, and you’ll deserve it.
There’s something a little funny about the industry pouring gas turbines and GPU clusters into the agent problem while the actual blocker for most people is a JavaScript challenge that resolves instantly in a browser that already exists. The compute got cheaper. The trust didn’t, and trust is the thing that was scarce.
Cheapest residential proxy on the market is the one you’re already paying Comcast for.