onionwright · use cases
Legitimate work that gets flagged as a bot.
Everything on this page is authorised — your own app, your own accounts, your own listings — and every one of it gets caught anyway, because bot detection cannot tell authorised automation from the kind it is built to stop. That is the whole gap onionwright closes: it lets legitimate automation run without reading as a machine. It is not a way to get into something you are not allowed into.
What teams run it for
End-to-end testing across many accounts
The job. You test your own web app's sign-up, login and checkout flows continuously, across dozens of seeded accounts, on a schedule.
Why it gets caught. The WAF or bot-detection you deployed in front of your own app does its job too well — it flags the test automation exactly as it would flag an attacker, so your green build depends on a browser that does not read as a bot.
What changes. The test browser clears the engine-level tells and drives input with human timing, so the run exercises the real path a user takes instead of a challenge page.
An agent running the SaaS tools you already pay for
The job. An AI agent logs into an internal tool with no API — a billing portal, an ops dashboard, a vendor system — and exports a report, reconciles an invoice, or files a ticket, unattended.
Why it gets caught. You are a paying user doing your own work, but the tool flags headless automation on principle: an instant-jump cursor, zero dwell before a click, events marked untrusted. One 'you look like a bot' challenge in the middle of the night ends the run.
What changes. A session that moves like a person completes the multi-step task overnight and is still signed in by morning — the AI-agent case the whole product is built around.
Monitoring your own listings
The job. A brand watches its own product pages across the marketplaces it sells on — price accuracy, MAP compliance, that a listing is live and correct — at a cadence a person could not keep up.
Why it gets caught. Marketplaces treat repeated programmatic visits as scraping and rate-limit or block them, even when you are checking your own storefront on data you are permitted to read.
What changes. Visits that look like an ordinary shopper on a real host keep the check running, so a delisted product or a broken price is caught in hours rather than at the next manual audit.
Operations an agent must finish unattended
The job. A long, multi-step workflow runs overnight or on a schedule — filling forms, uploading files, waiting out slow pages, retrying failures — on accounts you own.
Why it gets caught. The longer a session runs, the more behavioural signal it emits. A detector that samples over time reads the machine-perfect rhythm and challenges mid-way, and an unattended agent has no one to solve the challenge.
What changes. Human motor timing and a coherent identity that persists across restarts let the session survive the length of the job, which is the difference between an agent that finishes and one that stalls at 3am.
Where this is the wrong tool
The line is authorisation, and it is not a soft one. onionwright is for automation you have the right to run — your property, your accounts, work you have permission to do. It is not for getting into accounts you do not control, defeating a site’s security, or evading a block that exists to keep you out. We do not build platform-specific bypass modules, and if that is the goal this is the wrong product. The honest version of the pitch is narrow on purpose: it removes the automation tells that flag legitimate work.
Fit your scenario?
If your case is one of these at team scale — many sessions, your own deployment, a coherent identity per account — that is an enterprise conversation. Tell us the shape of the work and we reply with a scope. If you first want to see what it actually clears, the measured results are here.
Start a conversation