unmask

unmask

Self-hosted bot defense — built into nginx, or in front of any HTTP server.

Bye 24/7. — Reclaim sysadmin QOL from bot alerts.

open source self-hosted signed packages or one container

demo

unmask in one minute

A first visit, a scraper, the crawlers that pass, one click on AI crawlers, and the log that says why. Press play — pause, scrub back or go fullscreen with the player controls.

what it does

core features

01

The more suspicious, the harder the challenge

An ordinary visitor gets a proof-of-work that runs by itself: no click, no puzzle, and a signed cookie keeps them passed for days. A visit that looks automated, or that matches a rule you set (a network, a country, a request rate), goes on to unmask's own behavioral CAPTCHA: built in, with no third-party service, no site key and nothing sent out. A block happens only where you choose one. The challenge page carries your logo and speaks the visitor's language.

Proof-of-work → behavioral CAPTCHA → block only if you choose · no third-party CAPTCHA

02

SEO-safe

Googlebot / Bingbot / GPTBot / ClaudeBot and the other search and AI crawlers pass by default, so you start on the side that never costs you rankings. Where a vendor publishes its crawler IP ranges, the crawler is recognised by address, and a borrowed name is challenged like anyone else. 600+ crawler patterns are built in: one click turns away AI training crawlers while AI search fetches still pass, and any single crawler can be allowed or challenged on its own.

Default = zero ranking accidents · refuse AI training, keep AI search, in one click

03

TLS fingerprint (JA4): a new IP does not hide a bot

JA4 is a fingerprint of the client's TLS handshake. It follows the tool (curl, a python client, a headless browser), not the IP, country, VPN or User-Agent it wears, and unmask can ban the fingerprint itself, so a new address does not shed the ban. It is one layer among several: unmask combines it with the network (ASN), country, request rate, honeypot paths and the shared ban list, and each rule is a few clicks in the web admin.

Fingerprint · network · country · rate · honeypot · shared bans, layered

04

Native nginx speed, or one container

On nginx, a returning visitor's cookie is checked inside the nginx worker itself: one in-process check, no subrequest, no extra hop, so it can sit in front of a busy site as is. For any other server, the gateway container is nginx with the module and the daemon in one image: one docker run or one compose service in front of Apache, Node or any HTTP server.

nginx dynamic module · one-container gateway

05

Fail open

If unmask stops, nginx keeps serving. Already-passed clients stay on the cookie fast path — and visitors who haven't passed yet skip PoW / CAPTCHA entirely and still get the page they asked for (the site behaves as if unmask wasn't installed). "Defense degrades, the site stays up" by default — no more entire-site outages from a bot-mitigation glitch.

Fail-open by default, however you deploy it

06

Self-hosted, your data stays put

Everything runs on your boxes, managed from one web admin: a dashboard, the log that says why each request was challenged, one-click bans. Challenge verdicts / cookies / IPs / JA4s / event logs all stay inside your perimeter — no user behavior leaks to a third-party SaaS. No vendor lock-in. GDPR-friendly out of the box.

By default no visitor data leaves your servers · No third-party "data processor agreement" to draft

who and what it protects

use cases

01

Automated attacks, AI-driven ones included, cut at the edge

Many scanners and exploit bots that rake over wp-login.php, .env, xmlrpc.php, and known-CVE paths are non-browser clients that don't run JS. unmask meets them at the edge with layered detection (TLS fingerprint, network, rate, honeypot paths) plus PoW / CAPTCHA, turning the automated probing away up front. An address that passed in a real browser can only fetch so much; past the cap it gets the CAPTCHA or is refused.
Even as AI makes finding flaws and launching attacks cheaper and faster, keeping a cost on automated, high-volume access cuts the brute-force / scan / login attempts that ever reach your app.

Fewer attempts reach your app — less risk of a breach or a data leak · one layer of defense-in-depth

02

Spot surges and attacks early, act sooner

A sudden surge, one source hammering the site, or a scraper hauling off your data shows up on the dashboard and the stats: where traffic comes from (country, ASN), what it is (JA4, UA) and what was stopped, over the last 30 days. A burst of challenges or a honeypot ban can also reach you by mail or webhook (Slack, Discord, …). Once the hunt page shows who it is, ban the fingerprint or put a rule on the whole network (ASN) right there.

The sooner you notice, the sooner you act · no separate monitoring tool

03

Don't route all traffic through a SaaS just for bot defense

Mainstream bot defense is SaaS-shaped: every request runs through the vendor's plane, bringing privacy, cost, and the blast radius of vendor outages along with it. unmask adds a few include lines to your existing httpd — nothing sits in front — or only your own container does, and by default no visitor data leaves your servers.

For orgs that need data sovereignty / privacy / an OSS-only line (regulated, public sector, self-hosted ops). Install or uninstall in a few config lines.