JA3 fingerprint
A JA3 fingerprint is a hash computed from selected fields of the TLS ClientHello, taken in the order the client sent them.
A JA3 fingerprint is a hash computed from selected fields of the TLS ClientHello, taken in the order the client sent them. It turns a handshake into one short string that a server can match against a list, without decrypting anything or waiting for a request.
#What goes into the hash
The fields are the TLS version, the offered cipher suites, the extension identifiers, the supported elliptic curves and the curve point formats. Order is part of the input, not an accident of it, which is why two clients that support identical features can still hash differently.
All of this arrives in the first flight of the connection, in the clear. That is the point: classification finishes before your user agent or any other header is read.
#Why the same client can hash differently
RFC 8701 defines GREASE, a set of reserved values that a client may insert into its cipher suite, extension and named-group lists to keep servers tolerant of unknown values. Those values are chosen from a reserved set and may vary between connections. An implementation that hashes them along with everything else produces a different fingerprint each time, which looks like rotation and is not.
Implementations therefore strip GREASE values before hashing. Whether a given detector does so is not something you can read from the outside; you can only observe whether your hash is stable across connections.
#The family, not the one hash
| Name | Computed from |
|---|---|
| JA3 | The client’s ClientHello |
| JA3S | The server’s ServerHello, so a pair can be matched |
| Later successors | Sorted inputs and additional fields, to resist GREASE and reordering |
Newer schemes exist precisely because JA3 proved brittle. Treat the name as shorthand for the technique rather than as the specific hash in use anywhere.
#Commonly confused with
TLS fingerprinting is the technique; JA3 is one encoding of it. An HTTP/2 fingerprint is derived after the handshake, from frames rather than from the ClientHello, and the two are frequently checked together by an anti-bot system.