Skip to main content

curlpro

An HTTP client with a browser's network fingerprint: the TLS ClientHello, the HTTP/2 and HTTP/3 frames, header order and header case.

pip install curlpro
import curlpro

with curlpro.Session("chrome-151-windows") as s:
    r = s.get("https://example.com")
    print(r.status, r.text[:200])

Neither Go nor a compiler is needed: the native library and all 48 profiles are already inside the wheel, and the profiles load themselves.

Why another one

The existing clients keep their browser profiles in compiled code: a new Chrome comes out every four weeks, and each time that means editing C or Go, rebuilding and releasing. Here a profile is data, and it can be registered at runtime:

curlpro.register_profile({
    "name": "chrome-152-windows",
    "based_on": "chrome-151-windows",
    "headers": {"user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) ... Chrome/152.0.0.0 ..."},
})

Your own fingerprint, without a request

What a server would see is computed locally, from the same ClientHello bytes that would go on the wire. No network, no oracle:

with curlpro.Session("chrome-151-windows") as s:
    fp = s.fingerprint()
    print(fp.ja4)       # t13d1516h2_8daaf6152771_806a8c22fdea
    print(fp.akamai)    # 1:65536;2:0;4:6291456;6:262144|15663105|0|m,a,s,p

Checked against 48 captures: JA4 48/48, JA3N 48/48, Akamai 48/48.

audit() answers the second question — the one people actually lose days to. Not "does my fingerprint look right" but "does anything here disagree with anything else", because that is what gives a client away:

for finding in s.audit():
    print(finding)

Personas

Profile, proxy, device, headers and cookies — one identity, one file:

p = curlpro.Persona.new("chrome-151-windows", proxy="http://user:pass@host:8080")
p.save("accounts/user42.json")

p = curlpro.Persona.load("accounts/user42.json")
with p.session() as s:
    s.get("https://example.com/")
p.save()          # the cookies moved on; the identity did not

requests compatibility

import curlpro.requests as requests

r = requests.get("https://example.com/", timeout=10)

Existing code changes one import. It is a subset, and it says so: an argument the shim cannot honour is refused with a reason rather than ignored.

What is inside

A thin ctypes wrapper over a native library written in Go: the handshake is driven by uTLS, HTTP/2 by fhttp, QUIC by uquic.

The fingerprint is checked against tls.browserleaks.com: Chrome 151 gives t13d1516h2_8daaf6152771_806a8c22fdea — the same JA4 as the live browser.

Boundaries

The library covers the network layer. It does not forge the JS fingerprint (canvas, WebGL, navigator) — that is the browser's level, and the answer there is Playwright. Matching the network fingerprint is necessary but not sufficient: modern systems score JA4 together with JA4H, JA3S/JARM and behaviour.

Cleartext http:// and ws:// work too. There is no ClientHello and so no TLS fingerprint there, but the HTTP/1.1 half of the profile still applies — the header order and case — and that is all a plain-HTTP peer can see anyway. The point is not masking: a caller whose own service speaks plain HTTP, a solver or an internal API, should not need a second HTTP client beside this one.

HTTP/1.1, HTTP/2, HTTP/3 and WebSocket are supported, along with cookies, redirects, proxies (HTTP CONNECT and SOCKS5), multipart, streaming reads and uploads, and an asynchronous API.

# WebSocket: the handshake follows the profile's template, permessage-deflate works
with curlpro.Session() as s:
    with s.websocket("wss://echo.websocket.org/", max_message_size=1 << 20) as ws:
        ws.send("hello")         # str   -> a text frame
        ws.send(b"\x00\xff")     # bytes -> a binary one
        for message in ws:       # until the server closes: curlpro.WebSocketClosed;
            print(message)       # a silence timeout is CurlProError with .code == "timeout"

# A large file goes as a stream rather than through memory
with curlpro.Session() as s:
    s.post("https://example.com/upload", body_file="archive.zip")

# The connection is reused between requests, as a browser's is. keep_alive=False
# gives every request its own — needed when a balancer pins a client to one node.
with curlpro.Session(keep_alive=False) as s:
    s.get("https://example.com/")

The HTTP/3 fingerprint is checked against Chrome 144 on quic.browserleaks.com:

with curlpro.Session("chrome-151-windows", http3=True) as s:
    print(s.get("https://quic.browserleaks.com/fp").json()["h3_text"])
    # 1:65536;6:262144;7:100;51:1;GREASE|GREASE|984832|m,a,s,p

The QPACK dynamic table is supported by a decoder of our own: the profile advertises a capacity as Chrome does, and a server that uses it gets parsed.

JA4H can be left out of the build: it is the one component under a different licence (FoxIO License 1.1, patent-pending), and -tags nofoxio excludes it while leaving every other fingerprint intact. fingerprint().ja4h_available says which build is in use. The wheels here are built with it.

Install

pip install curlpro

Nothing to compile: the native library and all 48 profiles travel inside the wheel. Wheels are built for Linux (x86-64 and ARM64, glibc 2.28+), macOS 13+ (Intel and Apple Silicon) and Windows x64. The macOS 13 floor is not ours to choose: that is what Go 1.27 requires, and the native part is built with it.

Platforms outside that list — Alpine and other musl distributions, Windows on ARM, older glibc or macOS — have no wheel. There the source archive is built by hand, and Go and a C compiler are required: pip install alone would leave the package without its native part, and the failure would come at the first call rather than at install time.

pip download curlpro --no-binary :all: --no-deps
tar -xzf curlpro-*.tar.gz && cd curlpro-*/go
CGO_ENABLED=1 go build -buildmode=c-shared -o ../curlpro/lib/libcurlpro.so ./lib

The library is looked up through CURLPRO_LIBRARY, then in curlpro/lib/, then in dist/.

Full documentation and sources — github.com/int3re/curlpro.

Release files for curlpro 0.4.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for curlpro 0.4.3
File Size Uploaded
curlpro-0.4.3.tar.gz 324.5 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for curlpro 0.4.3
File
curlpro-0.4.3-py3-none-win_amd64.whl Python 3 none Windows x86-64 Details
curlpro-0.4.3-py3-none-manylinux_2_28_x86_64.whl Python 3 none Linux glibc 2.28+ x86-64 Details
curlpro-0.4.3-py3-none-manylinux_2_28_aarch64.whl Python 3 none Linux glibc 2.28+ ARM64 Details
curlpro-0.4.3-py3-none-macosx_13_0_x86_64.whl Python 3 none macOS 13.0+ x86-64 Details
curlpro-0.4.3-py3-none-macosx_13_0_arm64.whl Python 3 none macOS 13.0+ ARM64 Details

Total release size: 39.2 MB

Release files / curlpro-0.4.3.tar.gz

Download URL curlpro-0.4.3.tar.gz
Size 324.5 kB
Tags Source
SHA-256 checksum
How to use checksums
bb603ca8303d1f115838ff9dc146fc853de1df131f341d54f26396053dfeaac5
BLAKE2b-256 checksum
How to use checksums
c8a031a7bab716b7c11f2b908832320e2cf5ad6cc28d861bf304c006ed3ae995
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 9, 2026.

Transparency log

Release files / curlpro-0.4.3-py3-none-win_amd64.whl

Download URL curlpro-0.4.3-py3-none-win_amd64.whl
Size 9.6 MB
Tags Python 3 Windows x86-64
SHA-256 checksum
How to use checksums
0ee43671720c40745073873ca20ed1bb4d166e82a50ed6917a2af080f4a39f5d
BLAKE2b-256 checksum
How to use checksums
41800924f1f22b6494019948172f94e37db8965e1b981c6c87af11e248271510
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 9, 2026.

Transparency log

Release files / curlpro-0.4.3-py3-none-manylinux_2_28_x86_64.whl

Download URL curlpro-0.4.3-py3-none-manylinux_2_28_x86_64.whl
Size 9.8 MB
Tags Linux glibc 2.28+ x86-64 Python 3
SHA-256 checksum
How to use checksums
00765b789159778d7724b52ba2780df29e0d16a264c1ea3b18bc8168669b6c88
BLAKE2b-256 checksum
How to use checksums
6af29a358c10d11a0cbfdc977aa3b800f3fb71a64c75fce801a3420746f44914
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 9, 2026.

Transparency log

Release files / curlpro-0.4.3-py3-none-manylinux_2_28_aarch64.whl

Download URL curlpro-0.4.3-py3-none-manylinux_2_28_aarch64.whl
Size 9.0 MB
Tags Linux glibc 2.28+ ARM64 Python 3
SHA-256 checksum
How to use checksums
652d97d7687da56644abcb12e4665ce9cf699d56436007462241ebabee208e95
BLAKE2b-256 checksum
How to use checksums
88079d384bffc1d4a007e6485df65886199cfb693713a2b3b67e8949bea7bbb2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 9, 2026.

Transparency log

Release files / curlpro-0.4.3-py3-none-macosx_13_0_x86_64.whl

Download URL curlpro-0.4.3-py3-none-macosx_13_0_x86_64.whl
Size 5.4 MB
Tags Python 3 macOS 13.0+ x86-64
SHA-256 checksum
How to use checksums
4979b7f59f1a967b07a62aede5fbecb12ecb170e594fb2ce899c886f34083476
BLAKE2b-256 checksum
How to use checksums
8985d063a2f9b95d533d8624fdf2266f429c1aa0f950061372349c4eab805bf6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 9, 2026.

Transparency log

Release files / curlpro-0.4.3-py3-none-macosx_13_0_arm64.whl

Download URL curlpro-0.4.3-py3-none-macosx_13_0_arm64.whl
Size 5.0 MB
Tags Python 3 macOS 13.0+ ARM64
SHA-256 checksum
How to use checksums
a4120c5bc379db71057a17bf52a445680e25b1f116d205107502e9d728c85fd7
BLAKE2b-256 checksum
How to use checksums
8d20be56158a36ce6aecd4b5d68ddf215abcb2b51ac929dc3c978872b292ce48
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 9, 2026.

Transparency log

Release history Release notifications | RSS feed

0.12.0

6 release files

0.11.0

6 release files

0.10.1

6 release files

0.10.0

6 release files

0.9.0

6 release files

0.8.0

6 release files

0.7.2

6 release files

0.7.1

6 release files

0.7.0

6 release files

0.6.0

6 release files

0.5.2

6 release files

0.5.1

6 release files

0.5.0

6 release files

This release

0.4.3 This release

6 release files

0.4.2

6 release files

0.4.1

6 release files

0.4.0

6 release files

0.3.0

6 release files

0.2.1

6 release files

0.2.0

6 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page