Fingerprint check

What your connection gives away before a page runs a single script: your IP address, the TLS handshake, HTTP/2 settings and the order of your headers. Sites use these to tell browsers apart even when the user agent lies.

What the server sees

Connection

IP address•••.•••.•••.•••
ProtocolHTTP/2.0
TLS versionTLS 1.3
CipherTLS_AES_128_GCM_SHA256
ALPNh2

Who does it look like?

User agent saysUnknown
TLS handshake saysOther
HTTP/2 saysOther

Chrome and Safari add random "GREASE" values to the handshake, Firefox never does. Each engine also sends HTTP/2 pseudo-headers in its own order.

TLS fingerprint

JA4t13d1011h2_61a7ad8aa9b6_3fcd1a44f3e3
JA3 hashaf903d72a0686c78e250958b6d5fe33a
GREASEno
Full handshake
JA3771,4866-4865-4867-49196-49195-52393-49200-49199-52392-255,16-5-0-13-11-35-43-10-23-51-45,29-23-24,0
Cipher suitesTLS_AES_256_GCM_SHA384TLS_AES_128_GCM_SHA256TLS_CHACHA20_POLY1305_SHA256TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA2560x00FF
Extensions (in order)alpnstatus_requestserver_namesignature_algorithmsec_point_formatssession_ticketsupported_versionssupported_groupsextended_master_secretkey_sharepsk_key_exchange_modes
GroupsX25519CurveP256CurveP384
Signature algorithmsECDSAWithP384AndSHA384ECDSAWithP256AndSHA256Ed25519PSSWithSHA512PSSWithSHA384PSSWithSHA256PKCS1WithSHA512PKCS1WithSHA384PKCS1WithSHA256
VersionsTLS 1.3TLS 1.2
Offered ALPNh2http/1.1

HTTP/2 fingerprint

Akamai fingerprint2:0;4:2097152;5:16384;6:16384|5177345|0|m,s,a,p
Settings2:04:20971525:163846:16384
Window update5177345
Pseudo-header orderm,s,a,p

Request headers, in the order they were sent

:methodGET
:schemehttps
:authoritycheck.spitfirebrowser.xyz
:path/
accept*/*
user-agentMozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
accept-encodinggzip, br, zstd, deflate

What your browser shows

These tests run only in your browser. Their results are never sent to the server.

WebRTC

Public IP seen by WebRTCTesting…
Local addressesTesting…
ResultTesting…

A VPN or proxy that WebRTC bypasses shows up here as a public IP different from the one above. Browsers hide local addresses behind random .local names.

API

The same data as JSON, for scripts and for Spitfire's about:fingerprint page. CORS is open, and each IP gets 30 requests per minute.

/api/v1/allEverything on this page
/api/v1/ipIP address and Tor exit flag
/api/v1/headersRequest headers in order
/api/v1/tlsTLS handshake, JA3 and JA4
/api/v1/http2HTTP/2 settings and Akamai fingerprint

Nothing is stored or logged. Each request is answered from the connection it arrived on and forgotten.