Free tool

JA4 fingerprint decoder

Paste a JA4 or JA4_r and read what the client offered in its TLS handshake.

One handshake, three parts

t13d1516h2_8daaf6152771_e5627efa2ab1

  • tTCP
  • 13TLS 1.3
  • dServer name
  • 15Cipher suites
  • 16Extensions
  • h2HTTP/2
  • Cipher hash
  • Extension hash

Decode a fingerprint

Try

Runs in your browser. Nothing you paste is sent anywhere.

Format

Three parts, one handshake

  1. t13d1516h2

    Readable: protocol, version, SNI, cipher count, extension count, first ALPN value.

  2. 8daaf6152771

    Cipher suites, sorted, then SHA-256 cut to 12 characters.

  3. e5627efa2ab1

    Extensions, sorted, without SNI and ALPN, then the signature algorithms in order, hashed the same way.

JA3 vs JA4

Why JA4 replaced JA3

FieldJA3JA4
HashOne MD5 of every fieldReadable prefix plus two short SHA-256 hashes
Extension orderHashed as sent, so Chrome's shuffled order gives a new JA3 per connectionSorted first, so the order does not matter
Readable without a lookupNoProtocol, version, SNI, counts, ALPN
QUICNo markerStarts with q
LicenseBSD 3-ClauseBSD 3-Clause (JA4 only)

Where it comes from

Get the JA4 of a request

Only whoever terminates TLS sees the ClientHello. Script in the page never does.

  • Cloudflare

    Bot Management puts it in cf.bot_management.ja4 for rules and request.cf.botManagement.ja4 in Workers.

  • AWS WAF

    Rules can match on the JA4 fingerprint, and the WAF logs record it.

  • Your own proxy

    Anything that terminates TLS can compute it and pass it on in a header such as X-JA4.

  • Wireshark

    FoxIO's plugin adds JA4 columns to packet captures.

Agentscan

JA4 next to every verdict

Send the JA4 with each Agentscan check. It is stored with the verdict, the address and the network, so the log shows which TLS client sat behind each request.

  • Behind Cloudflare Bot Management, our Worker reads it and sends it for you.
  • Anywhere else, put it in the ja4 field or an X-JA4 header.
  • No edge, no JA4: the log says so instead of guessing one.
Agentscan check with a JA4
curl -X POST https://ipscanner.io/v1/agentscan/check \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "ip": "203.0.113.7",
    "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36",
    "ja4": "t13d1516h2_8daaf6152771_e5627efa2ab1"
  }'

FAQ

JA4 fingerprints, answered

What is a JA4 fingerprint?

A short string that describes a TLS ClientHello: the protocol and version the client offered, whether it sent a server name, how many cipher suites and extensions it listed and its first ALPN value, followed by two hashes of those lists. FoxIO published it in 2023 as the successor to JA3.

What does t13d1516h2 mean?

TLS over TCP, version 1.3, a domain name in SNI, 15 cipher suites, 16 extensions and HTTP/2 as the first ALPN value. Every JA4 starts with a part like this, and it is the only part you can read without a lookup.

How is JA4 different from JA3?

JA3 is one MD5 of the handshake fields in the order they were sent. Chrome started shuffling its extension order in 2023, which gives the same browser a new JA3 on every connection; JA4 sorts the lists first, so it stays put, and it keeps a readable prefix.

Can a JA4 be faked?

Yes. Tools such as curl-impersonate and uTLS copy a browser's ClientHello, so a browser JA4 on its own does not prove a browser. It is most useful when it disagrees with something else, such as a Chrome user agent arriving with a Python handshake.

Can I reverse the hashes in a JA4?

No. Parts b and c are SHA-256 hashes cut to 12 characters. To see the cipher suites and extensions behind them, log the JA4_r, which keeps the lists in clear.

Where do I get the JA4 of a request?

From whatever terminates TLS: your CDN, load balancer or reverse proxy. JavaScript in the page cannot read it, because the handshake is over before any script runs.

Is JA4 free to use?

JA4, the TLS client fingerprint, is BSD 3-Clause. The other JA4+ methods (JA4S, JA4H, JA4X, JA4T and the rest) are under the FoxIO License 1.1, which sets conditions on commercial use, so read it before building those into a product.