Skip to main content

High-performance Python binding for bogdanfinn/tls-client via CFFI – zero-copy, panic-proof, full TLS fingerprint control

Project description

tls-client-python

PyPI version Python License: MIT

High-performance Python binding for bogdanfinn/tls-client via CFFI.


What is TLS Fingerprinting?

Some people think it is enough to change the user-agent header of a request to let the server think that the client requesting a resource is a specific browser. Nowadays this is not enough, because the server might use a technique to detect the client browser which is called TLS Fingerprinting.

For a deep dive, see this excellent article on TLS fingerprinting.

✨ Features

Category Details
🔐 TLS Fingerprinting Impersonate Chrome, Firefox, Safari, Brave, Opera, OkHttp & more
🌐 Protocol Support HTTP/1.1, HTTP/2 (h2), HTTP/3 (QUIC) with automatic negotiation
Protocol Racing Chrome-style Happy Eyeballs for HTTP/2 vs HTTP/3
📋 Header Ordering Control the exact order of HTTP headers per request
🔒 Certificate Pinning Pin server certificates for enhanced security
🍪 Cookie Jar Built-in cookie handling with customisable jar
🚇 Proxy Support HTTP and SOCKS5 proxies with CONNECT auth
🔀 Redirect Control Choose whether to follow redirects per request
📊 Bandwidth Tracking Monitor upload/download bytes in real time
🔄 sync/Async Session + AsyncSession
🛡️ Panic-proof All Go panics caught and surfaced as Python exceptions
⚙️ Custom TLS Full 26-field custom TLS client configuration

📦 Installation

pip install tls-client-python

Pre-compiled binaries are included for 9 platforms — no Go toolchain required.

Requirements: Python 3.6+


🚀 Quick Start

from tls_client import Session

# Create a session with Chrome 146 fingerprint
session = Session(client_identifier="chrome_146", verify=False)

# GET request
resp = session.get("https://tls.browserleaks.com/json")
print(resp.status_code)
print(resp.text)

# POST request
resp = session.post("https://tools.scrapfly.io/api/fp/ja3")
data = resp.json()
print(resp.status_code)
print(data)


# Context Manager
with Session(client_identifier="firefox_148") as session:
    resp = session.get("https://tls.browserleaks.com/json")
    print(resp.status_code)
    print(resp.text)


# Async Usage
import asyncio
from tls_client import AsyncSession

async def main():
    async with AsyncSession(client_identifier="firefox_148") as s:
        resp = await s.get("https://tls.browserleaks.com/json")
        print(resp.status_code)
        print(resp.json())

asyncio.run(main())

🖥️ Supported Platforms

Pre-compiled native libraries are bundled for these platforms:

OS Architecture Binary
Windows x86-64 tls-client-windows-amd64.dll
Windows x86 (32-bit) tls-client-windows-386.dll
macOS x86-64 tls-client-darwin-amd64.dylib
macOS ARM64 (Apple Silicon) tls-client-darwin-arm64.dylib
Linux x86-64 (glibc) tls-client-linux-amd64.so
Linux x86 (32-bit, glibc) tls-client-linux-386.so
Linux ARM64 tls-client-linux-arm64.so
Linux ARMv7 tls-client-linux-arm.so
Alpine Linux x86-64 (musl) tls-client-alpine-amd64.so

The correct binary is automatically selected at runtime. Override via TLS_CLIENT_LIB environment variable.


🎭 Supported Browser Profiles — 79 Identifiers

🌐 Chrome — 24 Profiles

Identifier Notes
chrome_103chrome_112 Chrome Stable 103–112
chrome_116_PSK Chrome 116 with PSK key exchange
chrome_116_PSK_PQ Chrome 116 with PSK + Post-Quantum
chrome_117 Chrome 117
chrome_120 Chrome 120
chrome_124 Chrome 124
chrome_130_PSK Chrome 130 with PSK
chrome_131 · chrome_131_PSK Chrome 131 (standard & PSK)
chrome_133 · chrome_133_PSK Chrome 133 (standard & PSK)
chrome_144 · chrome_144_PSK Chrome 144 (standard & PSK)
chrome_146 · chrome_146_PSK Chrome 146 — default (standard & PSK)

🦊 Firefox — 16 Profiles

Identifier Notes
firefox_102 · firefox_104 · firefox_105 · firefox_106 Firefox 102–106
firefox_108 · firefox_110 Firefox 108 · 110
firefox_117 · firefox_120 · firefox_123 Firefox 117–123
firefox_132 · firefox_133 · firefox_135 Firefox 132–135
firefox_146_PSK Firefox 146 with PSK
firefox_147 · firefox_147_PSK Firefox 147 (standard & PSK)
firefox_148 Firefox 148

🍏 Safari — 10 Profiles

Identifier Device
safari_15_6_1 Safari 15.6.1 (macOS)
safari_16_0 Safari 16.0 (macOS)
safari_ipad_15_6 Safari 15.6 (iPadOS)
safari_ios_15_5 · safari_ios_15_6 Safari iOS 15.5–15.6
safari_ios_16_0 · safari_ios_17_0 Safari iOS 16 · 17
safari_ios_18_0 · safari_ios_18_5 Safari iOS 18 · 18.5
safari_ios_26_0 Safari iOS 26

🦁 Brave — 2 Profiles

Identifier Notes
brave_146 Brave Browser 146
brave_146_PSK Brave 146 with PSK

🎭 Opera — 3 Profiles

Identifier
opera_89 · opera_90 · opera_91

🤖 OkHttp (Android) — 7 Profiles

Identifier
okhttp4_android_7okhttp4_android_13

📱 Mobile / App SDKs — 16 Profiles

Category Identifiers
Zalando zalando_android_mobile · zalando_ios_mobile
Nike nike_ios_mobile · nike_android_mobile
MMS mms_ios · mms_ios_1 · mms_ios_2 · mms_ios_3
Mesh mesh_ios · mesh_ios_1 · mesh_ios_2 · mesh_android · mesh_android_1 · mesh_android_2
Confirmed confirmed_ios · confirmed_android

☁️ Cloudflare-specific — 1 Profile

Identifier Notes
cloudscraper Custom profile tuned for Cloudflare-protected sites

🔧 Advanced Usage

Custom TLS Client (Full Control)

Set custom_tls_client with up to 26 fields to bypass client_identifier entirely:

session = Session(custom_tls_client={
    "ja3_string": "771,4865-4866-4867-49195-49199-49196-49200-52393-52392-49171-49172-156-157-47-53,0-23-65281-10-11-35-16-5-13-18-51-45-43-27-17513,29-23-24,0",
    "h2_settings": {"HEADER_TABLE_SIZE": 65536, "MAX_CONCURRENT_STREAMS": 1000},
    "h2_settings_order": ["HEADER_TABLE_SIZE", "MAX_CONCURRENT_STREAMS"],
    "pseudo_header_order": [":method", ":authority", ":scheme", ":path"],
    "connection_flow": 1048576,
    "key_share_curves": ["X25519", "P256"],
    "alpn_protocols": ["h2", "http/1.1"],
    "supported_versions": ["1.3", "1.2"],
    "stream_id": 3,
})

Certificate Pinning

session = Session(
    certificate_pinning_hosts={
        "example.com": ["sha256/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA="]
    }
)

Client Certificates (mTLS)

session = Session(
    client_certificates=[{
        "cert_pem": open("client.crt", "rb").read(),
        "key_pem": open("client.key", "rb").read(),
    }]
)

Stream Response to Disk

resp = session.stream_to_file(
    "GET", "https://tls.browserleaks.com/",
    output_path="/tmp/image.png"
)
print(resp.status_code)  # response metadata still available

Per-Request Overrides

All Session constructor parameters can be overridden per request:

s = Session(client_identifier="chrome_146")
# Override fingerprint for a single request
resp = s.get("https://tls.browserleaks.com/json", client_identifier="firefox_148")

🔬 Architecture

Layer Technology
Go Engine bogdanfinn/tls-client compiled as C shared library (-buildmode=c-shared)
FFI Boundary Raw C structs via CFFI — no JSON serialization overhead
Memory Safety ffi.gc(resp, FreeResponse) — Go panics surfaced as RuntimeError
Python API requests-style Session, Response, AsyncSession

📚 API Reference

Session

Method Description
get(url, **kwargs) HTTP GET
post(url, **kwargs) HTTP POST
put(url, **kwargs) HTTP PUT
delete(url, **kwargs) HTTP DELETE
head(url, **kwargs) HTTP HEAD
patch(url, **kwargs) HTTP PATCH
execute_request(method, url, **kwargs) Generic request with full options
typed_request(Request) Strongly-typed request
stream_to_file(method, url, path) Stream response body to disk
clear_client_pool() Close idle connections (static)

Response

Property / Method Description
status_code HTTP status code (int)
headers Response headers (dict of list)
content Raw bytes body
text Decoded text body
encoding Detected charset
url Final URL after redirects
cookies Response cookies dict
used_protocol Protocol used (e.g. HTTP/2.0)
ok True if status_code < 400
reason HTTP reason phrase
json() Parse body as JSON
raise_for_status() Raise RuntimeError on 4xx/5xx

🔗 Credits

This project is a Python binding for bogdanfinn/tls-client, which itself is built upon:


📄 License

MIT — see LICENSE.


🙏 Community

Join the Discord server for support and discussion.


Powered by
JetBrains logo.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

tls_client_python-1.15.1.tar.gz (23.7 MB view details)

Uploaded Source

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

tls_client_python-1.15.1-py3-none-win_amd64.whl (23.8 MB view details)

Uploaded Python 3Windows x86-64

tls_client_python-1.15.1-py3-none-win32.whl (23.8 MB view details)

Uploaded Python 3Windows x86

tls_client_python-1.15.1-py3-none-musllinux_1_1_x86_64.whl (23.8 MB view details)

Uploaded Python 3musllinux: musl 1.1+ x86-64

tls_client_python-1.15.1-py3-none-macosx_11_0_arm64.whl (23.8 MB view details)

Uploaded Python 3macOS 11.0+ ARM64

tls_client_python-1.15.1-py3-none-macosx_10_9_x86_64.whl (23.8 MB view details)

Uploaded Python 3macOS 10.9+ x86-64

File details

Details for the file tls_client_python-1.15.1.tar.gz.

File metadata

  • Download URL: tls_client_python-1.15.1.tar.gz
  • Upload date:
  • Size: 23.7 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for tls_client_python-1.15.1.tar.gz
Algorithm Hash digest
SHA256 fd069bd4184edc56af72647a4b5ab5ff6a58b49e17cb29ac7e93b2274353ad65
MD5 fe90e25410d0bf6b0577732eb985e867
BLAKE2b-256 5794bbfb4bb7ec4d5f0d25cadde332e485f3ccc31d5a922627ee3ec5432d68ac

See more details on using hashes here.

Provenance

The following attestation bundles were made for tls_client_python-1.15.1.tar.gz:

Publisher: build_workflow.yml on komAAmok/tls-client-python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file tls_client_python-1.15.1-py3-none-win_amd64.whl.

File metadata

File hashes

Hashes for tls_client_python-1.15.1-py3-none-win_amd64.whl
Algorithm Hash digest
SHA256 048c2df28fd4ac0105694ce9dad1238e6d11a27acf90d525210e1e10a57b5861
MD5 525c0062a4effba86db3a27f48362c0a
BLAKE2b-256 7bfc6c11e3a7be6e6ecc41e98e1a9b487b90afb3b5fd3ca3ea36f8db93a5afdb

See more details on using hashes here.

Provenance

The following attestation bundles were made for tls_client_python-1.15.1-py3-none-win_amd64.whl:

Publisher: build_workflow.yml on komAAmok/tls-client-python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file tls_client_python-1.15.1-py3-none-win32.whl.

File metadata

File hashes

Hashes for tls_client_python-1.15.1-py3-none-win32.whl
Algorithm Hash digest
SHA256 1db397d635a098c4b2de4f61500e6eef5b76e7b84954612fe1681ee2a3c12e60
MD5 e70462a239f74e52c35db11934d084d3
BLAKE2b-256 819330ea21c1007c1476078beb06c192def43b126fa7509d1982264728180c8e

See more details on using hashes here.

Provenance

The following attestation bundles were made for tls_client_python-1.15.1-py3-none-win32.whl:

Publisher: build_workflow.yml on komAAmok/tls-client-python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file tls_client_python-1.15.1-py3-none-musllinux_1_1_x86_64.whl.

File metadata

File hashes

Hashes for tls_client_python-1.15.1-py3-none-musllinux_1_1_x86_64.whl
Algorithm Hash digest
SHA256 53f88b3e57a5e52b1a5826fcd019f92d1d073ec4209f57856193cf08092b02df
MD5 8ef9247c29c6a8a0fbefbe04de9d3530
BLAKE2b-256 642998a61eb674ff3bf94961e87c3d56a7a0c619156adec4d2806740bcaa2ff8

See more details on using hashes here.

Provenance

The following attestation bundles were made for tls_client_python-1.15.1-py3-none-musllinux_1_1_x86_64.whl:

Publisher: build_workflow.yml on komAAmok/tls-client-python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file tls_client_python-1.15.1-py3-none-manylinux2014_x86_64.whl.

File metadata

File hashes

Hashes for tls_client_python-1.15.1-py3-none-manylinux2014_x86_64.whl
Algorithm Hash digest
SHA256 a5749913b37938f18d8689fedbb455fd55b11ab49661811436c61893866e4fde
MD5 a43b603c7fcdf83dafdc394a009fb45f
BLAKE2b-256 f18d4409934e1cbc9bc645dba59d335c4c41fa8e50b8e5713dbd8bbbf2e17d39

See more details on using hashes here.

Provenance

The following attestation bundles were made for tls_client_python-1.15.1-py3-none-manylinux2014_x86_64.whl:

Publisher: build_workflow.yml on komAAmok/tls-client-python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file tls_client_python-1.15.1-py3-none-manylinux2014_i686.whl.

File metadata

File hashes

Hashes for tls_client_python-1.15.1-py3-none-manylinux2014_i686.whl
Algorithm Hash digest
SHA256 0c86b80a3115bb6ddc1d447fb8ee5767b5626465ab2d76a380b9161b26ec21e9
MD5 016ca8d8becb80dc45d6a44449ec2aef
BLAKE2b-256 014a3165771daf824daaeabd81435fba770aa9932e2790ddef900315c768701f

See more details on using hashes here.

Provenance

The following attestation bundles were made for tls_client_python-1.15.1-py3-none-manylinux2014_i686.whl:

Publisher: build_workflow.yml on komAAmok/tls-client-python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file tls_client_python-1.15.1-py3-none-manylinux2014_armv7l.whl.

File metadata

File hashes

Hashes for tls_client_python-1.15.1-py3-none-manylinux2014_armv7l.whl
Algorithm Hash digest
SHA256 afd3edce388d415d2639a4d171f864f180745408fe76e1a931f1287f9c32f2de
MD5 244a49dee1d50e011e93a1238f0b0295
BLAKE2b-256 ce2ed9a9cf943c50c1f8867d6608c6d4d2b51509f83cf38bb1b117240c65a239

See more details on using hashes here.

Provenance

The following attestation bundles were made for tls_client_python-1.15.1-py3-none-manylinux2014_armv7l.whl:

Publisher: build_workflow.yml on komAAmok/tls-client-python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file tls_client_python-1.15.1-py3-none-manylinux2014_aarch64.whl.

File metadata

File hashes

Hashes for tls_client_python-1.15.1-py3-none-manylinux2014_aarch64.whl
Algorithm Hash digest
SHA256 5406b63592b7a723d5e7ac90990c587d091853eac59da1d6126029d7f00e8eb5
MD5 c273d3a396a8bc7efadf515527fd1544
BLAKE2b-256 97cdab3a3bdfaa9d59aee155ad616ebaee6c6c445b9bf2c2d96e58a24779dfe5

See more details on using hashes here.

Provenance

The following attestation bundles were made for tls_client_python-1.15.1-py3-none-manylinux2014_aarch64.whl:

Publisher: build_workflow.yml on komAAmok/tls-client-python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file tls_client_python-1.15.1-py3-none-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for tls_client_python-1.15.1-py3-none-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 da71ab3a03beed6afef9a0f44b8b7a802b84fa2c17cbe8f6743adf4b9ac54e3b
MD5 bc279e46baddbccbbf0109f77d420775
BLAKE2b-256 3d5d453377776889c1177fcd9a23409fea8726be47784b5c4605b3a303e2e330

See more details on using hashes here.

Provenance

The following attestation bundles were made for tls_client_python-1.15.1-py3-none-macosx_11_0_arm64.whl:

Publisher: build_workflow.yml on komAAmok/tls-client-python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file tls_client_python-1.15.1-py3-none-macosx_10_9_x86_64.whl.

File metadata

File hashes

Hashes for tls_client_python-1.15.1-py3-none-macosx_10_9_x86_64.whl
Algorithm Hash digest
SHA256 6181fbd7da18a11908301126b3531a5c2d6ef34d5979399c3bba69284186c8c3
MD5 42905d1267959c6d33f12bef24755598
BLAKE2b-256 35070f11d0361c57413a252694720d4cb9f40f80bf52ccf4f2a085e88834b80b

See more details on using hashes here.

Provenance

The following attestation bundles were made for tls_client_python-1.15.1-py3-none-macosx_10_9_x86_64.whl:

Publisher: build_workflow.yml on komAAmok/tls-client-python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page