High-performance reverse proxy: passive TLS, HTTP/2, and TCP SYN (eBPF) fingerprints, injected as trusted headers for your backends.
100% open source. Fingerprints come from Huginn Net; proxy and signature path are both MIT/Apache. No proprietary fingerprint stack, no extra license for commercial use.

Values are produced by the proxy and override any client-supplied spoofed headers.
| Header | Layer / note |
|---|---|
x-tls-ja4 (+ -r / -o / -or) | TLS ClientHello: FoxIO-LLC JA4 family (hashed & raw variants) |
x-tls-ja4-sv1 (+ -sv1r) | TLS ClientHello: stable JA4 (ephemeral extensions excluded) |
x-http2-akamai | HTTP/2 only |
x-tcp-p0f | TCP SYN via eBPF (XDP or TC) when enabled |