PQ CRYPTA PLATFORM

๐Ÿ  Main

๐Ÿ“ฐ News

๐Ÿ‘ค Account

โŸจ QUANTUM ERROR PORTAL โŸฉ

Navigate the Error Dimensions

PQ Crypta Logo

JA4 Fingerprint Directory

What this edge classifies traffic against, plus what it actually sees — decoded and named, not just listed

6828 fingerprints
179 curated
6649 seen live
4009 browsers
202 API clients
914 scanners

Showing all 6828 fingerprints. Page 69 of 69. JSON

Fingerprint Type Tier Class Identified as
t13i1513h2_8daaf6152771_b77322f6088b JA4 seen live1× Unclassified Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
t13i1513h2_8daaf6152771_b7a99e67b1e5 JA4 seen live1× Unclassified Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
t13i1513h2_8daaf6152771_b81965684095 JA4 seen live1× Unclassified Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
t13i1513h2_8daaf6152771_df29c376febd JA4 seen live1× Unclassified Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
t13i1513h2_8daaf6152771_f0baea1b3350 JA4 seen live1× Unclassified Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
t13i1514h2_8daaf6152771_4ab3e390d7e5 JA4 seen live1× Unclassified Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
t13i1514h2_8daaf6152771_56a286331089 JA4 seen live1× Unclassified Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
t13i1514h2_8daaf6152771_6e438e904768 JA4 seen live1× Unclassified Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
t13i1514h2_8daaf6152771_76ab02fbf0c2 JA4 seen live1× Unclassified Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
t13i1514h2_8daaf6152771_8868437b8b45 JA4 seen live1× Unclassified Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
t13i1514h2_8daaf6152771_9c397acbd780 JA4 seen live1× Unclassified Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
t13i1514h2_8daaf6152771_a119e46ba42c JA4 seen live1× Unclassified Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
t13i1514h2_8daaf6152771_b9c352a595c8 JA4 seen live1× Unclassified Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
t13i1514h2_8daaf6152771_cd4096077622 JA4 seen live1× Unclassified Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
t13i1514h2_8daaf6152771_cf6e1259dba2 JA4 seen live1× Unclassified Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
t13i1514h2_8daaf6152771_f27a46184afd JA4 seen live1× Unclassified Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
t13i1514h2_8daaf6152771_fae72dc20b90 JA4 seen live1× Unclassified Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
t13i1515h2_8daaf6152771_0eb9bc577cc8 JA4 seen live1× Unclassified Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
t13i1515h2_8daaf6152771_55449e25bcac JA4 seen live2× Unclassified Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
t13i1515h2_8daaf6152771_7f650891f045 JA4 seen live1× Unclassified Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
t13i1515h2_8daaf6152771_d85f6c676370 JA4 seen live1× Unclassified Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
t13i1515h2_8daaf6152771_ec7d4e755158 JA4 seen live1× Unclassified Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
t13i1515h2_8daaf6152771_f5728d627f6c JA4 seen live1× Unclassified Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
t13i1516h2_8daaf6152771_9d0d4a7883f6 JA4 seen live2× Unclassified Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
t13i1516h2_8daaf6152771_ce66b3a31f3e JA4 seen live1× Unclassified Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
t13i1516h2_8daaf6152771_e7524cb1b1c7 JA4 seen live1× Unclassified Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
t13i1517h2_8daaf6152771_68e2f8e9952f JA4 seen live1× Unclassified Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
t13i1713h1_ab0a1bf427ad_ea1f8af03a23 JA4 seen live2× Unclassified Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.

JA3 and JA4, and why the difference matters here

A TLS fingerprint identifies a client by how it is built, not by anything it claims. The cipher suites it offers, the extensions it sends, the order they appear in — all of that is decided by the TLS library and its configuration, and none of it is affected by changing a User-Agent string.

JA3 hashes the whole ClientHello into one MD5. It works, but it throws away every bit of structure: two fingerprints that differ by one cipher look no more related than two from unrelated software.

JA4 keeps the structure. The first component is plain text you can read without a lookup table — transport, TLS version, whether a server name was sent, how many ciphers and extensions, which ALPN. The second and third hash the ciphers and the extensions separately. That separation is what lets this directory group a scanner's twelve fingerprints into one family, because they share an extension hash while their cipher hashes differ.

How this database is used

It is not a reference list. The proxy loads it at startup and consults it on every TLS handshake, matching JA4 first and falling back to JA3, and the classification it returns feeds blocking, rate limiting and per-route allowlists. Two further checks run alongside it:

Replay detection flags one fingerprint appearing from many addresses inside a window — a single client build spread across a botnet. Drift detection flags a fingerprint whose cipher or extension composition changes while its hash stays put, which is the signature of something trying to wear another client's identity.

Directory generated 2026-10-07T13:00:03+00:00. Want to know your own? The Handshake Mirror reports it, along with the rest of your connection.