Skip to content

What is font fingerprinting?

Font fingerprinting works out which typefaces a system has. The classic method measures the pixel dimensions of text drawn in candidate fonts — if the metrics differ from a fallback, the font is installed. Newer APIs can enumerate fonts more directly.

The installed set (and how each renders) correlates strongly with OS, language and configuration, so it's a meaningful slice of a fingerprint — and a coherence trap: a “Windows” persona should expose a Windows-like font set and metrics, not a Linux one.

There are two ways to ask whether a font is installed, and they should agree. A page can measure text drawn in the font, or it can load the font by name with new FontFace(x, 'local("Segoe UI")'). On Windows both questions go to the same font collection. A look-alike font installed to make widths plausible does not carry the real name, so it measures as present and still fails to load.

Some of the font surface cannot be chosen at all. The operating system's own font scaler sizes every glyph, DirectWrite on Windows and FreeType on Linux, and its rounding shows in plain text widths. Clearcote keeps the font list and metrics coherent with the operating system it runs on; presenting a different one leaves the host's scaler and font manager readable underneath. The measurements are in the font stack under the user agent, and the broader picture in anatomy of a fingerprint.

Clearcote puts this into practice

An open-source Chromium with fingerprint control compiled into the engine. A drop-in for Playwright & Puppeteer.

Free for one browser with GitHub. No card.