JA4 was released by FoxIO in 2023, led by one of JA3's authors, to fix what broke JA3: browsers that shuffle their TLS extensions. JA4 sorts cipher suites and extensions before hashing, so the shuffle no longer matters, and it adds a readable prefix. A typical value:
t13d1516h2_8daaf6152771_806a8c22fdea
Reading the first block
t: TLS over TCP (qmeans QUIC).13: the highest TLS version offered, 1.3.d: the client sent a domain in SNI (imeans it connected to a bare IP).15and16: the number of cipher suites and extensions, ignoring GREASE values.h2: the first ALPN value, here HTTP/2.
The two hashes after the underscores cover the sorted ciphers and the sorted extensions with signature algorithms. You can often tell a script from a browser by the prefix alone: an HTTP/1.1 ALPN and unusual counts do not look like any current browser.
JA4 is one of a family, called JA4+, that also fingerprints servers, HTTP requests and other protocols.
Why it matters with proxies
A proxy tunnels your TLS handshake without touching it, so your JA4 is the same through every proxy you own. If a site blocks a JA4 your HTTP library produces, a different IP will not help; a client that reproduces a browser's handshake will. Some anti-bot and CDN vendors expose JA4 in their rules, which is one reason fingerprint blocks show up in Cloudflare errors.
How to see yours
curl -s https://tls.peet.ws/api/all
Look for the ja4 field. TLS fingerprinting with curl_cffi shows measured values for requests, curl_cffi and Chrome.