What's New
Rotating exits is the part everyone automates. The browser signature underneath them usually never moves.
Single and Proxy Finder now take four optional fields that decide which browser your request presents: browser, os, version, and profile. The catalogue behind them is public at GET /api/profiles and needs no API key. Right now it holds 79 profiles across Chrome, Edge, Safari, Firefox and Tor, on Windows, macOS, Android and iOS.
And when you don't name one, Proxy Finder will change it for you. But only after a site has twice proved it doesn't want the one you sent.
How It Works
Three of the fields are for humans and one is for machines.
browser, os and version narrow the catalogue, and you can send any subset of them. os matches on the family, so asking for macOS accepts every macOS release in the list, while asking for the exact release label narrows to that one. When several profiles still fit, the newest version wins, because being current is the entire point. Old majors are what blocklists key on.
curl -X POST https://eu.api.foura.ai/api/single/ \
-H "X-API-Key: YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"method": "GET",
"url": "https://example.com/listing/42",
"browser": "Safari",
"os": "iOS"
}'
That resolves to the newest Safari on iOS in the catalogue, and it sends the User-Agent, the client hints and the header order that go with it, in that order. Header order is itself a signal, so nothing gets sorted on the way out.
profile is the fourth field: an exact id from the catalogue, for code that must keep sending the same client after a newer version lands. Proxy Finder takes all four inside its request object. Full parameter list is in the API reference, and the Playground reads the same catalogue, so its dropdowns can only offer what your code can ask for. The same four fields ride inside foura_single and foura_proxy on the MCP server, so an agent can retry as another browser instead of handing back a bare 403.
Two things this deliberately refuses to do.
A combination the catalogue can't present is an error that names what's available for that browser. Falling back to a default would send a client you didn't choose and can't see in the response. A profile choice with unblocker: false is refused too, because that flag is what carries the headers (what that flag actually does). Half a profile is worse than none.
The catalogue itself is measured, not typed up. A script fires every profile through the real request path and records what actually went on the wire. That matters more than it sounds: between two recent majors of one browser, the placeholder brand string changed and the brand order flipped, and that's exactly the kind of detail a detection service reads.
Impact
Here's the part we didn't expect.
A default is a shared default. The client your request presents when you ask for nothing is the one that every request which asked for nothing presents, and a defense that wants to key on something cheap keys on exactly that. It fails in a way that looks like nothing else, too: a site that refuses one browser refuses it at every exit you own. You spend the whole retry budget proving the same client is unwelcome.
We measured it three times, on three vendors, and it was the same shape each time.
A property portal behind PerimeterX turned down nine attempts on the default. Changing only the platform the request claims (same everything else, same pool) returned the page six times out of six. A supplements retailer behind Akamai refused the default and served two other browser families without complaint. A financial news site behind DataDome answered the default with a 401 and a 774-byte interstitial, while three other profiles pulled the real page, about 760 KB of it, twelve times each. We ran that one forward and backward to be sure the order wasn't doing the work.
So Proxy Finder rotates the browser family now, not just the exit. Two independent exits have to refuse before it moves, because one refusal is one exit's opinion. Then it steps along a ladder that starts with the smallest possible change, the platform, and only then tries other families.
It costs nothing. The rotation changes what a retry sends, never whether a retry happens, so requests and credits per task come out exactly where they were.
For Power Users
The rotation stays out of your way, and the rules for that are worth knowing.
It never fires when you named a profile yourself. It also never fires when you sent your own user-agent or cookie header, and that one is the important one: a clearance cookie is bound to the client that earned it, so rotating the signature underneath a working session replay would break a request that was succeeding. Pin what you want and it stays pinned.
Not every failure counts as evidence for moving the profile, either. A recognised defense vendor counts. So does a bare refusal status (401, 403, 429, 503) with no vendor named, and that one turned out to matter. One task came back with eight status rejections and nothing recognised on any of them: real refusals the rotation was ignoring, because it trusted only the detector. A missing page or a country block doesn't count. Those are answers about your URL and your geography, not about your client.
You can see all of it. A successful Proxy Finder response carries profile only when we chose it, never when you did. A failed task carries attemptReport.profilesTried: the families it sent, in first-use order, with default for a request that went out untouched. Without that field, "we tried four browsers and every one was refused" and "we never changed the browser" look identical from outside.
One habit worth stealing: when you're testing whether a profile helps, hold everything else still. Scrapfly's 2026 rundown of fingerprint testing tools puts it well, that changing three variables between runs tells you something worked but not which change mattered. Same target, same exit, one field different. That's also how every number above was produced.
What's Next
The candidate ladder only grows by measurement, one target at a time. A family gets added after we've watched it open a target the default couldn't, not because it looked like a good guess, and the catalogue gets re-measured on every engine bump rather than carried forward.
That's the uncomfortable shape of this problem. The best client signature is a moving target, tracking it is ongoing work rather than a thing you ship once, and whatever won last quarter is on somebody's list by now. Which is why it's a field you set and a catalogue you can read, instead of a number we picked for you.