Skip to content

How to Check JA3, JA4 and JA4H Fingerprints of iPhone App Traffic

See the JA3/JA4 TLS fingerprint of every HTTPS connection and the JA4H fingerprint of every request on iPhone, decoded section by section.

2 min readHTTPS Capture

Anti-bot systems, CDNs and fraud detection services often identify clients by how they connect, not only by what they send. The best-known methods are the JA3 and JA4 TLS fingerprints, and JA4H for HTTP requests. HTTPS Capture calculates all three for the traffic on your iPhone. You can see how Safari, an in-app browser or an SDK appears to a server, and compare clients side by side.

What the fingerprints mean

  • JA3: a hash of the TLS ClientHello, built from the TLS version, cipher suites, extensions, supported groups and EC point formats. It is widely used, but it changes when browsers shuffle the order of extensions.
  • JA4: a newer, readable TLS fingerprint such as t13d1516h2_8daaf6152771_e5627efa2ab1. It covers the transport and TLS version, whether SNI is present, the cipher and extension counts, the ALPN value, and sorted hashes of ciphers and extensions. Extension order does not affect it.
  • JA4H: a fingerprint of each HTTP request, built from the method, HTTP version, cookie and referer presence, header count, language, and hashes of header names and cookies.

See the fingerprints

  1. Capture traffic from the app or website you are interested in.
  2. Open an HTTPS request and go to the Overview tab.
  3. Under Client Fingerprints you will find:
    • JA4 for the TLS connection (HTTPS and WSS)
    • JA4H for the request itself (HTTP, HTTPS, WS and WSS)

Tap a fingerprint to open its detail page.

Read the details

The TLS Fingerprint page explains every part of JA4. It shows the transport, offered TLS version, SNI, ALPN, and the cipher and extension hashes. Observed ClientHello lists the actual cipher suites, extensions, supported groups and signature algorithms. You can copy JA4, JA3 or the JA3 raw string.

The HTTP Fingerprint page breaks JA4H down into its prefix and hashed parts. It also shows the observed header order and the cookie names, so you can see why two requests got different fingerprints.

Practical uses

  • Debug “bot detected” blocks: compare the fingerprint of your app’s HTTP library with Safari’s.
  • Check an SDK or a WebView: see whether embedded browsers connect differently from the system browser.
  • Verify a TLS library change: after updating a networking stack, check that the ClientHello still looks as expected.
  • Learn TLS: see which cipher suites and extensions real iOS apps offer.

Notes

  • Fingerprints describe the connection from the app to HTTPS Capture’s local proxy. That is the app’s own ClientHello, which is what you want to study. The proxy’s onward connection to the server uses its own TLS settings.
  • Hosts that are passed through without decryption, such as pinned apps and Apple system domains, still go through, but no HTTP-level JA4H is available for them.

HTTPS Capture

Capture and decrypt HTTPS traffic on iPhone

App Store

Ready to try it?

HTTPS Capture · Capture and decrypt HTTPS traffic on iPhone

Free on the App Store