# Stealth practices

How Reduck keeps your agent's browser automation from being detected as a bot, on your own Chrome or on a managed browser, and what you should do to keep the risk low.

Some sites protect themselves from being automated (X, LinkedIn, Amazon, etc.) using key signals: IP, browser fingerprints,
cookies and behavior.

Reduck is designed to minimize detection risks in both modes, extension with your own Chrome and managed browsers.

This page presents what we have built to minimize your agent being detected as a bot, then what you
should do on your side.

## What Reduck does

### On your own Chrome

Scripts run in the Chrome you use every day, through the [Reduck extension](https://docs.reduck.ai/#quick-start).
Sites see the same browser they always see from you:

| Signal            | An agent's own browser          | Your Chrome through Reduck           |
| ----------------- | ------------------------------- | ------------------------------------ |
| IP                | Datacenter                      | Your home or office connection       |
| Browser           | Automated, often headless       | Your real Chrome and its fingerprint |
| Cookies           | None                            | Your sessions                        |

So detection risk is minimal.

A script runs in your Chrome profile, with its sessions and cookies, so your agent works where you
are already signed in:

- No sign-in to script and no password to hand over. Your usual 2FA still works.
- No profile copy, no debug port, no "allow remote debugging" switch.
- Your cookies never leave your machine.

The extension connects out to Reduck, so this holds wherever your agent runs, in a terminal, in
Docker or on a server: your Chrome only needs to be open.

### On a managed browser

A [managed browser](https://docs.reduck.ai/core-concepts/#browser) runs in Reduck's cloud, 24/7, without your Chrome. 

- **Network**: we have a region by default, and a residential proxy as an option.
- **Browser**: we serve stealthy browsers.

## What you should do

Reduck lowers the risk; it does not remove it. A site judges what is done with your account, not
only the browser it is done from.

- **Pace your runs on one site.** Too many requests in a short time look like a bot from any
  browser, and a site answers them with a 429, a captcha or a restriction on the account. Each
  device runs 4 scripts at a time by default: lower it for a strict site at
  [reduck.ai/devices](https://reduck.ai/devices). See [Parallel runs](https://docs.reduck.ai/core-concepts/#parallel-runs).
- **Use an account you can afford to have restricted.** A script acts as you, with your account,
  under the site's rules. On a site that limits automation, start with small volumes.
- **On a managed browser, pick a residential proxy in the site's country** for a site that blocks
  datacenter IPs.
- **Use managed browsers for read only public pages**. If the content of the page can be retrieved with a managed browser without being logged in, prefer doing this for adversarial pages, like a Reddit post.
