Free network diagnostic
JA4 Fingerprint Checker for Your TLS Connection
Read the JA4 fingerprint observed when your connection reaches our hosting edge. Use it to compare client configurations, with no invented bot or fraud score.
Measure this connectionโs TLS fingerprint
The check sends a request to Coronium and reads the JA4 observation supplied by Vercel, our hosting edge. It does not submit your browser data to an external fingerprint-checking service.
What the checker observes
JA4 summarizes characteristics of a TLS clientโs connection setup. This tool reads the JA4 digest that Vercel supplies to the request handler. It also shows the JA3 hash when the hosting edge provides one. The Vercel documentation identifies the request headers used for these measurements.
The server does not calculate a fingerprint from your user-agent string or call another checker on your behalf. That would risk measuring our server rather than the incoming connection. If the hosting edge supplies no valid JA4 value, the page reports that the measurement is unavailable.
A fingerprint is not a unique user or a score
The JA4 project defines TLS client fingerprinting as one part of a larger family of network methods. Different clients can share connection characteristics. The displayed string is not a reliable account identifier and should not be treated as proof of a personโs identity.
A fingerprint also does not tell you whether another website will accept a request. A security product can combine it with other signals and site-specific rules. Read the IP reputation guide for the distinction between a fingerprint, network classification and risk score.
How proxies change the observation point
The result belongs to the TLS connection that reaches Vercel. A tunnel that carries the clientโs TLS connection and a service that terminates TLS and starts a new connection have different observation boundaries. If another gateway terminates TLS upstream, the observed fingerprint may describe that gatewayโs connection.
Record the client version, proxy configuration and timestamp when comparing results. Change one setting at a time. An unchanged JA4 does not prove that the public IP stayed the same, and a changed JA4 does not establish that the request is more trustworthy. Use ASN lookup for network routing and WebRTC testing for browser connection candidates.
Check a script or AI browser in its actual runtime
The button measures the request made by the browser displaying this page. It does not measure a Python worker or model API request running elsewhere. Open the tool inside a remote browser to inspect that browserโs connection.
For a command-line client, request the same measurement endpoint directly:
curl --silent --show-error --max-time 15 \
https://www.coronium.io/api/tls-fingerprint
That response describes the curl connection reaching our edge. Running the command on your laptop does not validate a cloud worker. Keep measurement failures visible in automation; do not substitute an example digest when a request returns no observation.
Use the result during diagnosis
Save the fingerprint with the response code and request time for the workflow you are investigating. If you own the destination, compare that evidence with your own request logs and access rules. A match to a public fingerprint example is not proof of the reason for a denial.
For a Cloudflare error, use the Cloudflare diagnosis guide. A JA4 result measured here is not access to another serviceโs private bot score. Avoid interpreting repeated measurements as a ranking of browsers or proxy providers.
Method and sources
Documentation reviewed October 11, 2026. The result panel identifies the source and time of each check. A failed or incomplete check is not a clean result.
Frequently asked questions
Continue the diagnosis
Check the network announcing an IP address.
Inspect browser connection candidates separately from TLS.
Work from the actual error and site rule.
Verify configuration in the browser or runtime you use.