Skip to content
All fingerprint checksCapability surfaces

form-factor-gated APIs match the form factor the client hints claim

Check id platform-gated-apis-vs-form-factor

What an ordinary browser yields

A client-hint claim of mobile comes with none of the desktop-only APIs; a claim of desktop comes with them.

What a detector infers

Some Web APIs are not compiled for every platform, so their presence is a fact about the binary rather than about the user agent. EyeDropper, navigator.keyboard and windowControlsOverlay are desktop-only in Chromium and simply do not exist on Chrome for Android; the client-hint mobile bit, by contrast, is a value the browser reports and a spoof can rewrite in one line. Two independent sources for one fact, so a disagreement locates the lie: a desktop binary presenting a phone, or a mobile build claiming a desktop. This row scores that gate only. The wider platform-gated list — BarcodeDetector, navigator.managed, virtualKeyboard — is measured and shown beside the verdict but never scored, because naming which OS ships which of them is precisely the kind of availability table that rots between milestones, and a stale table would convict honest browsers. That is the same discipline the hyphenation row applies: report the reading, do not manufacture a verdict from a list that has to be maintained.

How to resolve it

These surfaces are decided when the binary is built. If the client hints say mobile, run a mobile build — the presence of a desktop-only API cannot be edited away from inside the page, and deleting it would trip the global-object rows instead.

Read in the wild by

FakeBrowser (collector)

Reads BarcodeDetector and BluetoothUUID as part of its window presence matrix, alongside the legacy-engine members — platform-gated surfaces collected specifically so a replayed persona can present the right ones.

dumpWindowProps() key list, script/dumpDD.js

kkoooqq/fakebrowser script/dumpDD.js

Every attribution traces to a published artifact. See the sources and their limits.

Nearby checks in Capability surfaces

See all 13 checks in Capability surfaces
Who builds this test

Clearcote is a browser built for fingerprint coherence

It is a Chromium fork, maintained by the same people who wrote this reference. It ships as a compiled browser rather than as a stealth script injected into someone else's — which is a description of how it is built, and is not an argument about how it behaves on this check.

This audit takes no position on how Clearcote scores on Capability surfaces checks, on this one, or anywhere else. It has no baseline corpus of other people's fingerprints to rank you against and no vendor scoreboard — nearly every check is self-referential, asking one browser the same question through two independent APIs and reporting whether both answers can be true at once. It runs identically on any browser, including ours. Run it on yours and read the result yourself.

See the other checks in Capability surfaces — the family platform-gated-apis-vs-form-factor belongs to.