one check
Your TLS fingerprint
What your browser sends before a line of JavaScript runs, read by a service that accepts the connection itself.
Opening a connection to read your TLS fingerprint
What is a TLS fingerprint?
Before a page loads, your browser opens an encrypted connection with a greeting that lists the ciphers, extensions and protocols it supports. Every browser version sends its own recognisable greeting, and a server can read it before a single line of JavaScript runs, which is why detection systems start there.
What is JA3, and why does it keep changing?
JA3 turns that greeting into one hash, taking the extensions in the order they were sent. Since version 110 Chrome shuffles that order on every connection, so the same browser produces a new JA3 each time and the value can no longer tell two browsers apart. The comparison above shows it for your own browser.
What is JA4?
JA4 sorts the ciphers and extensions before hashing, so a shuffled order gives the same value. Its first block stays readable: protocol, TLS version, whether a server name was sent, the number of ciphers and extensions, and the first application protocol (the JA4 specification (opens in a new tab)).
Why does the header order matter?
Each browser sends its HTTP headers in a fixed order, and an HTTP library sends them in its own. A request that claims to be Chrome but orders its headers like a Python library contradicts itself before the page has loaded.
Does a TLS fingerprint identify me?
It describes your browser type, not you. In a measurement of 11.8 billion connections the single most common one covered 16.5 % of them.
What this one page cannot tell you
Measured on a request from the page rather than a navigation, so the TLS values are the ones a site sees and the header order is not.
The interesting part is usually not a single value but the disagreement between two. The full check reads all five layers and shows you where they contradict each other.