High-performance reverse proxy: passive TLS, HTTP/2, and TCP SYN fingerprints, injected as trusted headers for your backends.
Fingerprints are parsed by Huginn Net. The entire signature path carries the same MIT/Apache terms as the proxy itself. Use it in any commercial product without a separate licensing deal for the fingerprint logic.
Values are produced by the proxy and override any client-supplied spoofed headers.
| Header | Layer / note |
|---|---|
x-tls-ja4 (+ -r / -o / -or) | TLS ClientHello — FoxIO-LLC JA4 family (hashed & raw variants) |
x-tls-ja4-sv1 (+ -sv1r) | TLS ClientHello — stable JA4 (ephemeral extensions excluded) |
x-http2-akamai | HTTP/2 only |
x-tcp-p0f | TCP SYN via eBPF/XDP when enabled |