Skip to main content

High-performance Python binding for bogdanfinn/tls-client via CFFI – zero-copy, panic-proof, full TLS fingerprint control

Project description

tls-client-python

PyPI version Python License: MIT

High-performance Python binding for bogdanfinn/tls-client via CFFI.

Zero-copy FFI boundary, panic-proof, full TLS fingerprint control — with a familiar requests-style API.


What is TLS Fingerprinting?

Some people think it is enough to change the user-agent header of a request to let the server think that the client requesting a resource is a specific browser. Nowadays this is not enough, because the server might use a technique to detect the client browser which is called TLS Fingerprinting.

For a deep dive, see this excellent article on TLS fingerprinting.

✨ Features

Category Details
🔐 TLS Fingerprinting Impersonate Chrome, Firefox, Safari, Brave, Opera, OkHttp & more
🌐 Protocol Support HTTP/1.1, HTTP/2 (h2), HTTP/3 (QUIC) with automatic negotiation
Protocol Racing Chrome-style Happy Eyeballs for HTTP/2 vs HTTP/3
📋 Header Ordering Control the exact order of HTTP headers per request
🔒 Certificate Pinning Pin server certificates for enhanced security
🍪 Cookie Jar Built-in cookie handling with customisable jar
🚇 Proxy Support HTTP and SOCKS5 proxies with CONNECT auth
🔀 Redirect Control Choose whether to follow redirects per request
📊 Bandwidth Tracking Monitor upload/download bytes in real time
🔄 sync/Async Session + AsyncSession
🛡️ Panic-proof All Go panics caught and surfaced as Python exceptions
⚙️ Custom TLS Full 26-field custom TLS client configuration

📦 Installation

pip install tls-client-python

Pre-compiled binaries are included for 9 platforms — no Go toolchain required.

Requirements: Python 3.6+


🚀 Quick Start

from tls_client import Session

# Create a session with Chrome 146 fingerprint
session = Session(client_identifier="chrome_146", verify=False)

# GET request
resp = session.get("https://tls.browserleaks.com/json")
print(resp.status_code)
print(resp.text)

# POST request
resp = session.post("https://tools.scrapfly.io/api/fp/ja3")
data = resp.json()
print(resp.status_code)
print(data)


# Context Manager
with Session(client_identifier="firefox_148") as session:
    resp = session.get("https://tls.browserleaks.com/json")
    print(resp.status_code)
    print(resp.text)


# Async Usage
import asyncio
from tls_client import AsyncSession

async def main():
    async with AsyncSession(client_identifier="firefox_148") as s:
        resp = await s.get("https://tls.browserleaks.com/json")
        print(resp.status_code)
        print(resp.json())

asyncio.run(main())

🖥️ Supported Platforms

Pre-compiled native libraries are bundled for these platforms:

OS Architecture Binary
Windows x86-64 tls-client-windows-amd64.dll
Windows x86 (32-bit) tls-client-windows-386.dll
macOS x86-64 tls-client-darwin-amd64.dylib
macOS ARM64 (Apple Silicon) tls-client-darwin-arm64.dylib
Linux x86-64 (glibc) tls-client-linux-amd64.so
Linux x86 (32-bit, glibc) tls-client-linux-386.so
Linux ARM64 tls-client-linux-arm64.so
Linux ARMv7 tls-client-linux-arm.so
Alpine Linux x86-64 (musl) tls-client-alpine-amd64.so

The correct binary is automatically selected at runtime. Override via TLS_CLIENT_LIB environment variable.


🎭 Supported Browser Profiles — 79 Identifiers

🌐 Chrome — 24 Profiles

Identifier Notes
chrome_103chrome_112 Chrome Stable 103–112
chrome_116_PSK Chrome 116 with PSK key exchange
chrome_116_PSK_PQ Chrome 116 with PSK + Post-Quantum
chrome_117 Chrome 117
chrome_120 Chrome 120
chrome_124 Chrome 124
chrome_130_PSK Chrome 130 with PSK
chrome_131 · chrome_131_PSK Chrome 131 (standard & PSK)
chrome_133 · chrome_133_PSK Chrome 133 (standard & PSK)
chrome_144 · chrome_144_PSK Chrome 144 (standard & PSK)
chrome_146 · chrome_146_PSK Chrome 146 — default (standard & PSK)

🦊 Firefox — 16 Profiles

Identifier Notes
firefox_102 · firefox_104 · firefox_105 · firefox_106 Firefox 102–106
firefox_108 · firefox_110 Firefox 108 · 110
firefox_117 · firefox_120 · firefox_123 Firefox 117–123
firefox_132 · firefox_133 · firefox_135 Firefox 132–135
firefox_146_PSK Firefox 146 with PSK
firefox_147 · firefox_147_PSK Firefox 147 (standard & PSK)
firefox_148 Firefox 148

🍏 Safari — 10 Profiles

Identifier Device
safari_15_6_1 Safari 15.6.1 (macOS)
safari_16_0 Safari 16.0 (macOS)
safari_ipad_15_6 Safari 15.6 (iPadOS)
safari_ios_15_5 · safari_ios_15_6 Safari iOS 15.5–15.6
safari_ios_16_0 · safari_ios_17_0 Safari iOS 16 · 17
safari_ios_18_0 · safari_ios_18_5 Safari iOS 18 · 18.5
safari_ios_26_0 Safari iOS 26

🦁 Brave — 2 Profiles

Identifier Notes
brave_146 Brave Browser 146
brave_146_PSK Brave 146 with PSK

🎭 Opera — 3 Profiles

Identifier
opera_89 · opera_90 · opera_91

🤖 OkHttp (Android) — 7 Profiles

Identifier
okhttp4_android_7okhttp4_android_13

📱 Mobile / App SDKs — 16 Profiles

Category Identifiers
Zalando zalando_android_mobile · zalando_ios_mobile
Nike nike_ios_mobile · nike_android_mobile
MMS mms_ios · mms_ios_1 · mms_ios_2 · mms_ios_3
Mesh mesh_ios · mesh_ios_1 · mesh_ios_2 · mesh_android · mesh_android_1 · mesh_android_2
Confirmed confirmed_ios · confirmed_android

☁️ Cloudflare-specific — 1 Profile

Identifier Notes
cloudscraper Custom profile tuned for Cloudflare-protected sites

🔧 Advanced Usage

Custom TLS Client (Full Control)

Set custom_tls_client with up to 26 fields to bypass client_identifier entirely:

session = Session(custom_tls_client={
    "ja3_string": "771,4865-4866-4867-49195-49199-49196-49200-52393-52392-49171-49172-156-157-47-53,0-23-65281-10-11-35-16-5-13-18-51-45-43-27-17513,29-23-24,0",
    "h2_settings": {"HEADER_TABLE_SIZE": 65536, "MAX_CONCURRENT_STREAMS": 1000},
    "h2_settings_order": ["HEADER_TABLE_SIZE", "MAX_CONCURRENT_STREAMS"],
    "pseudo_header_order": [":method", ":authority", ":scheme", ":path"],
    "connection_flow": 1048576,
    "key_share_curves": ["X25519", "P256"],
    "alpn_protocols": ["h2", "http/1.1"],
    "supported_versions": ["1.3", "1.2"],
    "stream_id": 3,
})

Certificate Pinning

session = Session(
    certificate_pinning_hosts={
        "example.com": ["sha256/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA="]
    }
)

Client Certificates (mTLS)

session = Session(
    client_certificates=[{
        "cert_pem": open("client.crt", "rb").read(),
        "key_pem": open("client.key", "rb").read(),
    }]
)

Stream Response to Disk

resp = session.stream_to_file(
    "GET", "https://tls.browserleaks.com/",
    output_path="/tmp/image.png"
)
print(resp.status_code)  # response metadata still available

Per-Request Overrides

All Session constructor parameters can be overridden per request:

s = Session(client_identifier="chrome_146")
# Override fingerprint for a single request
resp = s.get("https://tls.browserleaks.com/json", client_identifier="firefox_148")

🔬 Architecture

Layer Technology
Go Engine bogdanfinn/tls-client compiled as C shared library (-buildmode=c-shared)
FFI Boundary Raw C structs via CFFI — no JSON serialization overhead
Memory Safety ffi.gc(resp, FreeResponse) — Go panics surfaced as RuntimeError
Python API requests-style Session, Response, AsyncSession

📚 API Reference

Session

Method Description
get(url, **kwargs) HTTP GET
post(url, **kwargs) HTTP POST
put(url, **kwargs) HTTP PUT
delete(url, **kwargs) HTTP DELETE
head(url, **kwargs) HTTP HEAD
patch(url, **kwargs) HTTP PATCH
execute_request(method, url, **kwargs) Generic request with full options
typed_request(Request) Strongly-typed request
stream_to_file(method, url, path) Stream response body to disk
clear_client_pool() Close idle connections (static)

Response

Property / Method Description
status_code HTTP status code (int)
headers Response headers (dict of list)
content Raw bytes body
text Decoded text body
encoding Detected charset
url Final URL after redirects
cookies Response cookies dict
used_protocol Protocol used (e.g. HTTP/2.0)
ok True if status_code < 400
reason HTTP reason phrase
json() Parse body as JSON
raise_for_status() Raise RuntimeError on 4xx/5xx

🔗 Credits

This project is a Python binding for bogdanfinn/tls-client, which itself is built upon:


📄 License

MIT — see LICENSE.


🙏 Community

Join the Discord server for support and discussion.


Powered by
JetBrains logo.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

tls_client_python-1.15.0.2.tar.gz (39.5 MB view details)

Uploaded Source

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

tls_client_python-1.15.0.2-py3-none-win_amd64.whl (3.3 MB view details)

Uploaded Python 3Windows x86-64

tls_client_python-1.15.0.2-py3-none-win32.whl (42.6 MB view details)

Uploaded Python 3Windows x86

tls_client_python-1.15.0.2-py3-none-musllinux_1_1_x86_64.whl (44.3 MB view details)

Uploaded Python 3musllinux: musl 1.1+ x86-64

tls_client_python-1.15.0.2-py3-none-macosx_11_0_arm64.whl (4.1 MB view details)

Uploaded Python 3macOS 11.0+ ARM64

tls_client_python-1.15.0.2-py3-none-macosx_10_9_x86_64.whl (4.4 MB view details)

Uploaded Python 3macOS 10.9+ x86-64

tls_client_python-1.15.0.2-py3-none-any.whl (43.0 MB view details)

Uploaded Python 3

File details

Details for the file tls_client_python-1.15.0.2.tar.gz.

File metadata

  • Download URL: tls_client_python-1.15.0.2.tar.gz
  • Upload date:
  • Size: 39.5 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for tls_client_python-1.15.0.2.tar.gz
Algorithm Hash digest
SHA256 d2674e22789c30ec21fc634b75edc67f4fc05e2ede43a7a78d3c5b2a386279e0
MD5 3075da5f824cdb25efb3420b2b88ef89
BLAKE2b-256 c0475580c47539cd5588173d2f3240407c0a62e9543e7c241c94c255ed82c076

See more details on using hashes here.

Provenance

The following attestation bundles were made for tls_client_python-1.15.0.2.tar.gz:

Publisher: build_workflow.yml on komAAmok/tls-client-python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file tls_client_python-1.15.0.2-py3-none-win_amd64.whl.

File metadata

File hashes

Hashes for tls_client_python-1.15.0.2-py3-none-win_amd64.whl
Algorithm Hash digest
SHA256 77387e39a93b5143539d6dd2c4225558ce83468a826e7086090cc45921a35918
MD5 1dc39ca4af7ff6f9de1049340dfde43b
BLAKE2b-256 f936ee48b24aec7d8d00e5a55660313db98eaa44f69d81bb7a380f3f5b1c7403

See more details on using hashes here.

Provenance

The following attestation bundles were made for tls_client_python-1.15.0.2-py3-none-win_amd64.whl:

Publisher: build_workflow.yml on komAAmok/tls-client-python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file tls_client_python-1.15.0.2-py3-none-win32.whl.

File metadata

File hashes

Hashes for tls_client_python-1.15.0.2-py3-none-win32.whl
Algorithm Hash digest
SHA256 c236a96c1dfe541ad7a5d52308df39e7fa4a3a9230f88a29117ac15b308b1293
MD5 795c1be7177485046a59ae046472c575
BLAKE2b-256 13d6c070fdfddebc02eab1210d5f7e510939809e52412588c6c3304fed9c41de

See more details on using hashes here.

Provenance

The following attestation bundles were made for tls_client_python-1.15.0.2-py3-none-win32.whl:

Publisher: build_workflow.yml on komAAmok/tls-client-python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file tls_client_python-1.15.0.2-py3-none-musllinux_1_1_x86_64.whl.

File metadata

File hashes

Hashes for tls_client_python-1.15.0.2-py3-none-musllinux_1_1_x86_64.whl
Algorithm Hash digest
SHA256 37893b1872aa8fbd97cd72d61521b084836d9c26c14a081d282ab726bf9f4b42
MD5 015a095be2385fc3a2f09ad714e0e4e7
BLAKE2b-256 def112809a99d4a0be4519faeb73e6897582009f64a7b8abddd330f49cfd0e06

See more details on using hashes here.

Provenance

The following attestation bundles were made for tls_client_python-1.15.0.2-py3-none-musllinux_1_1_x86_64.whl:

Publisher: build_workflow.yml on komAAmok/tls-client-python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file tls_client_python-1.15.0.2-py3-none-manylinux2014_x86_64.whl.

File metadata

File hashes

Hashes for tls_client_python-1.15.0.2-py3-none-manylinux2014_x86_64.whl
Algorithm Hash digest
SHA256 efbde18429983205fec941b507a9758d112326b7105b6dfee660d608fcf62a8f
MD5 8b669bfd823cc851c336773f80b3741d
BLAKE2b-256 5a2e54248c0166e614699d5462d8f86f7773262572f62f60375d7c55de7e6bee

See more details on using hashes here.

Provenance

The following attestation bundles were made for tls_client_python-1.15.0.2-py3-none-manylinux2014_x86_64.whl:

Publisher: build_workflow.yml on komAAmok/tls-client-python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file tls_client_python-1.15.0.2-py3-none-manylinux2014_i686.whl.

File metadata

File hashes

Hashes for tls_client_python-1.15.0.2-py3-none-manylinux2014_i686.whl
Algorithm Hash digest
SHA256 e8676bde85a8f9505a929fcc8f8f55a14f5413ba63a8a910cc82ab36bf39117d
MD5 79f0f971d6417a2341bc49b2f70caef1
BLAKE2b-256 7052df7484372b620c52f84b888958960e8578bbc82cc9fe0e2e1539fb071f78

See more details on using hashes here.

Provenance

The following attestation bundles were made for tls_client_python-1.15.0.2-py3-none-manylinux2014_i686.whl:

Publisher: build_workflow.yml on komAAmok/tls-client-python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file tls_client_python-1.15.0.2-py3-none-manylinux2014_armv7l.whl.

File metadata

File hashes

Hashes for tls_client_python-1.15.0.2-py3-none-manylinux2014_armv7l.whl
Algorithm Hash digest
SHA256 bc6fb94ca39c5e6bc978fbada6edcf7d13d6418b9d05b73d6bb8fce6102f6b90
MD5 5c103b835a7688643266a2dce61c12ff
BLAKE2b-256 8f89c6896bfcef2df730015f4676bd54c795ef1e4047964fb6484088bb4fda06

See more details on using hashes here.

Provenance

The following attestation bundles were made for tls_client_python-1.15.0.2-py3-none-manylinux2014_armv7l.whl:

Publisher: build_workflow.yml on komAAmok/tls-client-python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file tls_client_python-1.15.0.2-py3-none-manylinux2014_aarch64.whl.

File metadata

File hashes

Hashes for tls_client_python-1.15.0.2-py3-none-manylinux2014_aarch64.whl
Algorithm Hash digest
SHA256 58160b0fe3e362fa910b9ecbfa4baf10435e015b0b6a37df79ec317d31573154
MD5 bb03e5f805ef7934e4faf1f7fec2f1e4
BLAKE2b-256 f7271ebd3b6dc0a3729debd7a0ae1fcb1607587871b4dd025c3e07683fa6ab2a

See more details on using hashes here.

Provenance

The following attestation bundles were made for tls_client_python-1.15.0.2-py3-none-manylinux2014_aarch64.whl:

Publisher: build_workflow.yml on komAAmok/tls-client-python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file tls_client_python-1.15.0.2-py3-none-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for tls_client_python-1.15.0.2-py3-none-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 487786e72c7a177484cab2e6a0b32756433b58deddcd10890d88e06c8933bb21
MD5 a9d23e0ecdbae875a58855bc747e3731
BLAKE2b-256 1eaff1aea775a788f8d159c91beaae023bb083009cf2070efe469ad7b58c4c57

See more details on using hashes here.

Provenance

The following attestation bundles were made for tls_client_python-1.15.0.2-py3-none-macosx_11_0_arm64.whl:

Publisher: build_workflow.yml on komAAmok/tls-client-python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file tls_client_python-1.15.0.2-py3-none-macosx_10_9_x86_64.whl.

File metadata

File hashes

Hashes for tls_client_python-1.15.0.2-py3-none-macosx_10_9_x86_64.whl
Algorithm Hash digest
SHA256 e05a3cdefeb13c09b57d8473c9ea80bc3aa179d7dee90c72064359769c1f9e7f
MD5 417a75524bdb99754cdad035ecbbc105
BLAKE2b-256 1c6280ecf5232fc84aa658e35fd46cfc1af8301428e13117c71f6a5f3b574cb7

See more details on using hashes here.

Provenance

The following attestation bundles were made for tls_client_python-1.15.0.2-py3-none-macosx_10_9_x86_64.whl:

Publisher: build_workflow.yml on komAAmok/tls-client-python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file tls_client_python-1.15.0.2-py3-none-any.whl.

File metadata

File hashes

Hashes for tls_client_python-1.15.0.2-py3-none-any.whl
Algorithm Hash digest
SHA256 cd56bd90289559e065c4b98c01c72020f0971b919ae064a818fec6235d0854d6
MD5 f1ec4860d1cf21a2e86fa0e5d46c5cc5
BLAKE2b-256 4f321017b180466c84373484d83f7b650b6fa444f01d5f829e93c5371137325f

See more details on using hashes here.

Provenance

The following attestation bundles were made for tls_client_python-1.15.0.2-py3-none-any.whl:

Publisher: build_workflow.yml on komAAmok/tls-client-python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page