Skip to content
Detection & blocking

What is TLS Fingerprint?

An identifier derived from how a client opens a TLS connection, which distinguishes real browsers from HTTP libraries before any request is read.

The first message of a TLS handshake lists the client's supported versions, cipher suites and extensions in an order that is specific to each TLS library. Formats such as JA3 and JA4 condense that message into a short fingerprint.

A proxy does not change it. For HTTPS the proxy only tunnels the connection, so the website sees the proxy's IP combined with your client's fingerprint — and a Python or Node default fingerprint looks nothing like Chrome's.

Bot-management systems use it to block or rate-limit clients regardless of how many IPs they rotate through. Real browsers, or clients that impersonate a browser handshake, avoid the mismatch.