← 资料库索引 ← 官方文档 原始链接 ↗ 🔍
官方文档

Cloudflare 文档:JA3/JA4 指纹 原文标题:JA3/JA4 fingerprint

发表时间:2026-05-06采集时间:2026-10-09 10:58:19来源:developers.cloudflare.com原文语言:en状态:完整

内容概要总结

本文是 Cloudflare 官方文档中关于 JA3/JA4 指纹的说明页。它定义 JA3 与 JA4 指纹是根据 TLS 客户端发起连接的方式来识别客户端的标识符,每种客户端类型(浏览器、机器人、应用)有不同连接特征,故指纹可跨目标 IP、端口和证书作为稳定标识符;JA4 通过对 ClientHello 扩展排序改进 JA3,减少现代浏览器的唯一指纹数量。文档详细列出 JA4 指纹在日志中可能为 null/空的五种情形(非加密 HTTP 流量、请求发往 Cloudflare 内部或第三方源站、Bot Management 被跳过、TLS 会话恢复后不再计算、O2O 场景说明),并给出 ja4Signals 的 JSON 示例(含 h2h3_ratio_1h、browser_ratio_1h、uas_rank_1h 等字段)与缺失时的空输出示例。还给出分析与操作入口(Security Events/Analytics、Analytics GraphQL API、自定义规则),以及两个用例:用 JA3 阻止或允许某类流量、用移动应用统一的 JA3 指纹允许移动端流量。

翻译内容

原文内容(English)

文档索引
在以下位置获取完整文档索引:https://developers.cloudflare.com/bots/llms.txt
使用该文件在进一步探索之前发现所有可用页面。

JA3/JA4 指纹

最后更新于 2026 年 5 月 6 日 || 以 Markdown 查看 | Agent 设置

JA3 ↗︎ 和 JA4 ↗︎ 指纹根据 TLS 客户端发起连接的方式来识别它们。每种客户端类型(浏览器、机器人或应用程序)都有不同的连接特征,因此所得到的指纹可作为一个稳定的标识符,跨不同的目标 IP、端口和证书保持有效。

JA4 对 JA3 做了改进:它对 ClientHello 扩展进行排序,从而减少了现代浏览器产生的唯一指纹数量,并使分组更容易。

如果你想使用 JA4 指纹和 Signals Intelligence,你的 Workers 脚本应当能够在 Bot Management 无法计算或填充 JA4 Signals 时(例如非 TLS 流量,或 Bot Management 被跳过时)处理缺失字段。对于 Bot Management 生效的 Orange-to-Orange(O2O)场景,JA4 Signals 对应的是 eyeball(最终用户)连接,并在 O2O 链路中被保留,包括 O2O 区域请求及任何相应的子请求。

  • JA4 指纹可能缺失的可能性。
  • ja4Signals 数组可能缺失的可能性(例如,当该请求无法获得 JA4 时)。
  • 结果为 NaN 或 Infinity 的值将被排除在该数组之外。
{
 "ja4Signals": {
 "h2h3_ratio_1h": 0.98826485872269,
 "heuristic_ratio_1h": 7.288895722013e-05,
 "reqs_quantile_1h": 0.99905741214752,
 "uas_rank_1h": 901,
 "browser_ratio_1h": 0.93640440702438,
 "paths_rank_1h": 655,
 "reqs_rank_1h": 850,
 "cache_ratio_1h": 0.18918327987194,
 "ips_rank_1h": 662,
 "ips_quantile_1h": 0.99926590919495
 },
 "jaSignalsParsed": {
 "ratios": {
 "h2h3_ratio_1h": 0.98826485872269,
 "heuristic_ratio_1h": 7.288895722013e-05,
 "browser_ratio_1h": 0.93640440702438,
 "cache_ratio_1h": 0.18918327987194
 },
 "ranks": {
 "uas_rank_1h": 901,
 "paths_rank_1h": 655,
 "reqs_rank_1h": 850,
 "ips_rank_1h": 662
 },
 "quantiles": {
 "reqs_quantile_1h": 0.99905741214752,
 "ips_quantile_1h": 0.99926590919495
 }
 }
}

当 JA4 Signals 缺失时,输出如下所示:

缺失 JA4 signals 的输出 json

{
 "ja4Signals": {},
 "jaSignalsParsed": {
 "ratios": {},
 "ranks": {},
 "quantiles": {}
 }
}

JA3 或 JA4 指纹是一种基于 SSL/TLS 的标识符,在特定情况下在日志中可能为 null 或为空:

  • 由于 JA3 和 JA4 是在 TLS(SSL)握手期间计算的,因此对于未加密的 HTTP 流量,它们不会出现。
  • 当 Worker 向一个 Cloudflare 网络内部(例如非代理/内部 O2O)的区域或向第三方源站发送请求时,或在 Worker 将流量路由到目标区域时,该字段可能为空。
  • 当某个请求的 Bot Management 本身被跳过时,指纹可能缺失,因为该功能负责计算和填充这些值。
  • 使用 TLS 会话恢复(TLS Session Resumption)↗︎ 时,一旦初始 TLS 握手成功完成,后续连接将被简化。这导致不再进行进一步的指纹计算。
  • 在 Bot Management 生效的 Orange-to-Orange(O2O)场景中,JA3/JA4 指纹在 O2O 链路中被保留,并代表 eyeball(最终用户)连接。这包括 O2O 区域上的请求及任何相应的子请求。

分析

要获取关于潜在机器人请求的更多信息,可在以下位置使用这些 JA3 和 JA4 指纹:

  • Security Events 与 Security Analytics
  • Analytics GraphQL API,特别是 HTTP Requests 数据集

操作

要调整你的应用程序对特定指纹的响应方式,可将它们与以下功能一起使用:

用例

阻止或允许某些流量

一组相似的请求可能共享相同的 JA3 指纹。因此,JA3 可能有助于阻止传入的威胁。例如,如果你注意到某个机器人攻击未被现有防御捕获,可以创建一条自定义规则,阻止或质询该攻击所使用的 JA3。

反之,如果现有防御正在阻止实际上是合法的流量,可以创建一条使用 Skip 操作的自定义规则,允许在正常请求中看到的那个 JA3。

如果你想立即补救 Bot Management 的误报或漏报,JA3 也可能有用。

允许移动端流量

通常,移动应用程序流量会在不同设备和用户之间产生相同的 JA3 指纹。这意味着你可以通过其 JA3 指纹来识别你的移动应用程序流量。

使用该 JA3 指纹允许来自你移动应用程序的流量,但阻止或质询其余流量。

文档

Documentation Index

Fetch the complete documentation index at: https://developers.cloudflare.com/bots/llms.txt
Use this file to discover all available pages before exploring further.

JA3/JA4 fingerprint

Last updated May 6, 2026||View as Markdown|Agent setup

JA3 ↗︎ and JA4 ↗︎ fingerprints identify TLS clients based on how they initiate connections. Each client type (browser, bot, or application) has distinct connection characteristics, so the resulting fingerprint acts as a stable identifier across different destination IPs, ports, and certificates.

JA4 improves on JA3 by sorting ClientHello extensions, which reduces the number of unique fingerprints for modern browsers and makes grouping easier.

If you want to use JA4 fingerprints and Signals Intelligence, your Workers script should be able to handle missing fields when Bot Management isn't able to calculate or populate JA4 Signals (for example, non-TLS traffic or when Bot Management is skipped). For Orange-to-Orange (O2O) scenarios where Bot Management is in effect, JA4 Signals correspond to the eyeball (end-user) connection and are preserved through the O2O chain, including O2O zone requests and any corresponding subrequests.

  • The possibility that the JA4 fingerprint could be missing.
  • The possibility that the ja4Signals array could be missing (for example, if JA4 isn't available for the request).
  • Results with NaN or Infinity values will be excluded from the array.
{
 "ja4Signals": {
 "h2h3_ratio_1h": 0.98826485872269,
 "heuristic_ratio_1h": 7.288895722013e-05,
 "reqs_quantile_1h": 0.99905741214752,
 "uas_rank_1h": 901,
 "browser_ratio_1h": 0.93640440702438,
 "paths_rank_1h": 655,
 "reqs_rank_1h": 850,
 "cache_ratio_1h": 0.18918327987194,
 "ips_rank_1h": 662,
 "ips_quantile_1h": 0.99926590919495
 },
 "jaSignalsParsed": {
 "ratios": {
 "h2h3_ratio_1h": 0.98826485872269,
 "heuristic_ratio_1h": 7.288895722013e-05,
 "browser_ratio_1h": 0.93640440702438,
 "cache_ratio_1h": 0.18918327987194
 },
 "ranks": {
 "uas_rank_1h": 901,
 "paths_rank_1h": 655,
 "reqs_rank_1h": 850,
 "ips_rank_1h": 662
 },
 "quantiles": {
 "reqs_quantile_1h": 0.99905741214752,
 "ips_quantile_1h": 0.99926590919495
 }
 }
}

When JA4 Signals are missing, the output appears as follows:

Missing JA4 signals outputjson

{
 "ja4Signals": {},
 "jaSignalsParsed": {
 "ratios": {},
 "ranks": {},
 "quantiles": {}
 }
}

The JA3 or JA4 fingerprint is an SSL/TLS-based identifier and can be null or empty in logs under specific circumstances:

  • Since JA3 and JA4 are calculated during the TLS (SSL) handshake, they will not be present for non-encrypted HTTP traffic.
  • The field may be empty when a Worker sends a request to a zone that is either internal to Cloudflare's network (for example, non-proxied/internal O2O) or to a third-party origin, or when a Worker is routing traffic to the target zone.
  • The fingerprints may be absent when Bot Management itself is skipped for a request, as the feature is responsible for calculating and populating these values.
  • With TLS Session Resumption ↗︎, once the initial TLS handshake is successfully completed, subsequent connections will be streamlined. This results in no further fingerprint calculation.

In Orange-to-Orange (O2O) scenarios where Bot Management is in effect, JA3/JA4 fingerprints are preserved through the O2O chain and represent the eyeball (end-user) connection. This includes requests on the O2O zone and any corresponding subrequests.

Analytics

To get more information about potential bot requests, use these JA3 and JA4 fingerprints in:

Actions

To adjust how your application responds to specific fingerprints, use them with:

Use cases

Block or allow certain traffic

A group of similar requests may share the same JA3 fingerprint. For this reason, JA3 may be useful in blocking an incoming threat. For example, if you notice that a bot attack is not caught by existing defenses, create a custom rule that blocks or challenges the JA3 used for the attack.

Alternatively, if existing defenses are blocking traffic that is actually legitimate, create a custom rule with the Skip action allowing the JA3 seen across good requests.

JA3 may also be useful if you want to immediately remedy false positives or false negatives with Bot Management.

Allow mobile traffic

Often, mobile application traffic will produce the same JA3 fingerprint across devices and users. This means you can identify your mobile application traffic by its JA3 fingerprint.

Use the JA3 fingerprint to allow traffic from your mobile application, but block or challenge remaining traffic.

Docs