JA4 was released by FoxIO in 2023, led by one of JA3's authors, to fix what broke JA3: browsers that shuffle their TLS extensions. JA4 sorts cipher suites and extensions before hashing, so the shuffle no longer matters, and it adds a readable prefix. A typical value:

t13d1516h2_8daaf6152771_806a8c22fdea

Reading the first block

  • t: TLS over TCP (q means QUIC).
  • 13: the highest TLS version offered, 1.3.
  • d: the client sent a domain in SNI (i means it connected to a bare IP).
  • 15 and 16: the number of cipher suites and extensions, ignoring GREASE values.
  • h2: the first ALPN value, here HTTP/2.

The two hashes after the underscores cover the sorted ciphers and the sorted extensions with signature algorithms. You can often tell a script from a browser by the prefix alone: an HTTP/1.1 ALPN and unusual counts do not look like any current browser.

JA4 is one of a family, called JA4+, that also fingerprints servers, HTTP requests and other protocols.

Why it matters with proxies

A proxy tunnels your TLS handshake without touching it, so your JA4 is the same through every proxy you own. If a site blocks a JA4 your HTTP library produces, a different IP will not help; a client that reproduces a browser's handshake will. Some anti-bot and CDN vendors expose JA4 in their rules, which is one reason fingerprint blocks show up in Cloudflare errors.

How to see yours

curl -s https://tls.peet.ws/api/all

Look for the ja4 field. TLS fingerprinting with curl_cffi shows measured values for requests, curl_cffi and Chrome.