Cached at:
09/13/26, 04:51 PM
# Session Context — what a web page knows about you
Source: [https://sessioncontext.org/](https://sessioncontext.org/)
## In plain English
What this page worked out about you, in the order it matters\. Every statement expands to the exact values it came from\.
### Collecting
None of this asks your permission\. The findings appear as soon as the last pass lands\.
- Reading the browser, screen and document
- Storage, network, devices and permissions
- Fingerprinting graphics, audio and performance
- Reducing it all to one identifier
### Try it yourself
One measurement needs your participation\. The result appears in place, below the box\.
#### Type one sentence
no permission needed
Type the sentence below\. This page measures the rhythm, not the words, then saves the pattern — type it a second time and it will say whether the same person is at the keyboard\.
thequickbrownfoxjumpsoverthelazydog
0/43characters100% accurate0wpm
## Everything above this point needed no permission\.
Not one prompt was shown, and nothing you did granted consent\. These are the capabilities that do ask first\. Each one says what it would reveal, and what this page has already worked out without it — press one to see the distance between those two\.
- #### Precise location never asked Where you are, to within a few meters — a building, not a city — from satellite, nearby wi\-fi networks and cell towers\.[How it works →](https://sessioncontext.org/methods#precise-location) Nothing on this page could work this out without asking\.
- #### Camera and microphone never asked The model name of every recording device attached to your machine, plus identifiers for them that stay the same every time you come back\.[How it works →](https://sessioncontext.org/methods#camera-and-microphone-identity) Nothing on this page could work this out without asking\.
- #### Clipboard contents never asked Whatever you last copied, in full — frequently a password, an address or a private message\.[How it works →](https://sessioncontext.org/methods#clipboard-reading) Nothing on this page could work this out without asking\.
- #### Every attached display never asked Each monitor you have plugged in: its resolution, its manufacturer label, and where it sits relative to the others on your desk\.[How it works →](https://sessioncontext.org/methods#multi-screen-details) Nothing on this page could work this out without asking\.
- #### Installed fonts never asked Every typeface on your system, straight from the operating system — the software you own, spelled out\.[How it works →](https://sessioncontext.org/methods#full-local-font-list) Nothing on this page could work this out without asking\.
- #### Idle and lock state never asked Whether you are sitting at your keyboard and whether your screen is locked — continuously, in the background, long after you stop looking at this page\.[How it works →](https://sessioncontext.org/methods#idle-and-lock-state) Known already, without asking: Whether this tab has focus, and the clicks and keystrokes inside it — only while you are actually here\.
- #### Motion sensors never asked Accelerometer and gyroscope readings, whose tiny manufacturing imperfections identify your individual handset\.[How it works →](https://sessioncontext.org/methods#motion-sensors) Nothing on this page could work this out without asking\.
The rest of this page reads your browser\. This one reaches past it\.
- #### Installed desktop applications never asked Which desktop applications you have installed — software you never told any website about\.[How it works →](https://sessioncontext.org/methods#installed-application-detection-scheme-flooding) Nothing on this page could work this out without asking\.
### Granting outlives this tab\.
Nothing has been granted here\.A permission you approve is remembered for this site, and this page cannot hand it back:`permissions\.revoke\(\)`was removed from browsers years ago and never replaced\. Only your browser can undo it — the icon at the left of the address bar, then site settings\. The same is true of every other site you have ever said yes to\.
## Every detail, as collected
The findings above are derived from these4tables\. Field names carry a definition where one helps; anything your browser withheld is grayed out\.
Hide the6fields that were not reportedPrint every field definition
Your browser sends all of this by itself, on every request, whether or not the page contains a single line of JavaScript\. Blocking scripts does not stop it\.
#### What your browser volunteered
##### Client Hints Received
1reported
This server sends Accept\-CH and Critical\-CH asking for high\-entropy hints — processor architecture, exact browser build, device model, color\-scheme preference\. The browser then volunteers them on every subsequent request, no script required\.
Client Hints ReceivedFieldValueno client hints receivedreload once — the browser must see the server's Accept\-CH before it sends them
#### The network connection underneath
##### Connection & Protocol
11reported
Facts read from the TCP socket, below the HTTP layer\. This deployment sits behind a hosting proxy, so the socket here belongs to that proxy and the headers have been re\-emitted by it: the ordering below is the proxy's, not your browser's\. Run the site directly, with no proxy in front, and this section reports your browser's own header order — a passive fingerprint that survives user\-agent spoofing\.
Connection & ProtocolFieldValueHTTP version1\.1proxy to server; your browser likely negotiated HTTP/2 or /3 at the edgetransportno \(plain HTTP\)the proxy terminated TLS; your connection to it was encryptedremote address::ffff:100\.64\.0\.18the proxy's address, not yoursremote port57774the proxy's portaddress familyIPv6local \(server\) address::ffff:10\.205\.4\.211:8080requests on this TCP connection1keep\-alive reusebytes read on socket530header count13raw header orderHost, User\-Agent, Accept, Accept\-Encoding, Accept\-Language, Sec\-Fetch\-Mode, X\-Forwarded\-For, X\-Forwarded\-Host, X\-Forwarded\-Proto, X\-Railway\-Edge, X\-Railway\-Request\-Id, X\-Real\-Ip, X\-Request\-Startre\-emitted by the proxy — not your browser's own orderrequest lineGET /
##### Server\-Derived Context
23reported· 6 not
What the server infers from the request alone\. No external lookup is performed: no IP\-geolocation service, no analytics endpoint, no third party of any kind\. None of these values is recorded — the two that are, the ETag and the CSS probe, say so in their own tables\.
Server\-Derived ContextFieldValueclient IP \(x\-forwarded\-for\)174\.137\.51\.67your real address, forwarded by the proxyproxy chain174\.137\.51\.67, 152\.233\.29\.2behind a proxyyesthe socket belongs to the proxy, so header order below is its ownx\-real\-ip174\.137\.51\.67Host requestedsessioncontext\.orgUser\-AgentMozilla/5\.0 \(Macintosh; Intel Mac OS X 10\_15\_7\) AppleWebKit/537\.36 \(KHTML, like Gecko\) Chrome/135\.0\.0\.0 Safari/537\.36UA length117reduced\-UA is about 110 charactersAccepttext/html,application/xhtml\+xmlAccept\-Encodingbr, gzip, deflatecompression supportAccept\-Language \(raw\)\*preferred language\*language count1ranked list, high entropyDNT headernot sentSec\-GPC headernot sentSec\-Fetch\-Sitenot reportedSec\-Fetch\-ModecorsSec\-Fetch\-Destnot reportedSec\-Fetch\-Usernot reportedReferernone — direct navigationUpgrade\-Insecure\-Requestsnot reportedPrioritynot reportedcookies sent0cookie namesnonecookie bytes0server time \(UTC\)2026\-09\-13T16:51:51\.708Zserver epoch ms1789318311706compare against your own clockserver uptime2189\.7 sserver timezoneUTCruntimeNode v22\.23\.2 · linux/x64
Whether this site can pick you out of a crowd and know you are the same person who visited before — without you logging in, and without relying on cookies\.
#### Cross\-site tracking
Preparing the third\-party frame…