TikTok X-Gorgon/X-Argus/X-Ladon/X-Khronos 签名与设备注册(unidbg 实现) 原文标题:ssovit/tiktok-x-argus-ladon-gorgon-khronos-unidbg
内容概要总结
GitHub 仓库 ssovit/tiktok-x-argus-ladon-gorgon-khronos-unidbg(4 star,2026-08 创建)。项目用单一函数 generate_headers(url, method, body, cookie, ts, device) 为所有 TikTok API 请求生成签名头,作者称其实现取自 app.apk 46.7.3(2024607030,arm64+armv7a,实测设备 SM-S9280 / Android 15),并强调未做任何工具包猜测。返回头含 X-Gorgon、X-Khronos、X-Ladon、X-Argus、X-SS-STUB 等哈希,以及 x-common-params-v2、User-Agent、Cookie 等 46.7.3 完整头集(共 28 个)。设备注册(device_register)通过 device/Libs/unidbg.jar 加载 libEncryptor.so、以 TTEncrypt 5.5.0 生成二进制 payload,POST 到 log-va.tiktokv.com/service/2/device_register/ 取得 device_id/install_id。项目另附 INSTALL/USAGE/FINDINGS 三份文档与 device_register、aweme_search、aweme_detail 示例。作者明确这只是「部分签名」:X-Gorgon 用 8404 零表占位、X-Ladon/X-Argus 为简化实现,只能过 music search 等宽松接口,严格接口可能失败;真实的 46.7.3 .msf 需 arm64 Frida dump。README 强调仅限教育/研究用途,并提示 device_register、aweme/* 会被 TikTok 限流,需使用住宅代理。
翻译内容
原文内容(English)
TTOOK
用单一函数 generate_headers(url, method, body, cookie, ts, device) 处理所有 TikTok API 请求 —— 数据取自 app.apk 46.7.3 arm64+armv7a 2024607030。
不做工具包猜测 —— 46.7.3 beta googleplay SM-S9280 Android 15 arm64-v8a,来自 adb dumpsys shared_prefs dex server.json。
文档:docs/INSTALL.md - docs/USAGE.md - docs/FINDINGS.md
免责声明 —— 仅供教育用途。 本项目仅供教育与研究用途。不得用于商业用途。作者按「原样」提供,不附带任何担保。你需对如何使用本代码、以及遵守 TikTok 服务条款和适用法律负全部责任。作者不对任何 TikTok 账号被封禁、处罚、限流或使用本代码引发的其他后果负责。
安装
前置条件:Python 3.10+ - Java 17+(仅 device/ 需要,header 哈希为纯 Python)—— 详见 docs/INSTALL.md。
# 克隆 / 进入
cd tiktok-x-argus-ladon-gorong-khronos-unidbg
# venv(推荐)
python -m venv .venv
# Windows
.venv\Scripts\activate
# Linux/macOS
source .venv/bin/activate
# 依赖
pip install -r requirements.txt # requests, pycryptodome>=3.20.0
验证:
python -c "from headers import generate_headers; print(generate_headers('https://api16-normal-c-alisg.tiktokv.com/aweme/v1/music/search/?aid=1233&version_code=2024607030&version_name=46.7.3&device_id=0&iid=0&channel=googleplay&query=love&count=10','GET',b'','store-idc=useast5',device={'device_id':'0','iid':'0'})['X-Gorgon'][:20])"
# 8404...
Java 解析(Windows):JAVA_HOME -> C:\Program Files\Android\Android Studio\jbr\bin\java.exe(自带 JBR 25)-> which java。无需配置 PATH —— device/generator.py:25 会自动找到 JBR。
缺少pycryptodome->X-Argus会回退为base64("argus-...")(headers/__init__.py:103)。搜索仍能通过;严格接口则需要它。修复:pip install pycryptodome。
完整故障排查 -> docs/INSTALL.md。
使用
from headers import generate_headers
headers = generate_headers(
url="https://api16-normal-c-alisg.tiktokv.com/aweme/v1/music/search/?aid=1233&app_name=musical_ly&version_code=2024607030&version_name=46.7.3&device_id=767909...&iid=...&channel=googleplay&query=love&count=10",
method="GET",
body=b"",
cookie="store-idc=useast5; tt-target-idc=useast5",
device={"device_id": "767909...", "iid": "767909..."},
)
# headers = {
# "X-Gorgon": "8404a0ae1000...", "X-Khronos": "17879...", "X-Ladon": "...", "X-Argus": "...", "X-SS-STUB": "...",
# "x-common-params-v2": "ab_version=46.7.3&aid=1233&...", "x-tt-trace-id": "00-...", "User-Agent": "com.zhiliaoapp.musically/2024607030 ...",
# "Cookie": "store-idc=useast5; ..."
# }
import requests
r = requests.get(url, headers=headers)
print(r.status_code, r.text[:500])
签名:generate_headers(url, method="GET", body=b"", cookie="", ts=None, device=None) -> dict —— POST、固定 ts、真实设备与 header 参考见 docs/USAGE.md。
返回:
X-GorgonX-KhronosX-LadonX-ArgusX-SS-STUB(哈希)x-common-params-v2x-tt-pba-enablex-tt-dm-statusX-SS-REQ-TICKETsdk-versionoec-*rpc-persist-*x-tt-trace-idUser-AgentCookie—— 来自app.apkserver.json的46.7.3完整头集(headers/__init__.py:129)。
示例
# 设备注册(通过 unidbg 的二进制 TTEncrypt,46.7.3 log-va 仍需要)
python examples/device_register.py
# -> device.json,含 device_id / install_id(真实值,非 0)
# 免登录搜索(任何 device_id 都可,music/hashtag 连 0 都行)
python examples/aweme_search.py
# -> 200 {"music":[]} for 46.7.3
# 视频详情页(aweme/detail)
python examples/aweme_detail.py --aweme-id 7410863178971234567
# -> 200 {"aweme_detail": {"aweme_id": "...", "desc": "..."}} for 46.7.3
python examples/aweme_detail.py --aweme-id https://www.tiktok.com/@user/video/7410863178971234567 --proxy http://user:pass@geo.iproyal.com:12321
aweme_search.py / aweme_detail.py 若存在 device/test_device_1.json 则加载它,否则用 0(搜索用 0 即可;详情可能需要真实设备 —— 见 docs/USAGE.md)。
设备注册
device_register 使用 device/Libs/unidbg.jar libEncryptor.so 75348 TTEncrypt 5.5.0 payload —— 二进制 tt-data=a 发送到 log-va.tiktokv.com/service/2/device_register/。详情 -> docs/FINDINGS.md。
代理
TikTok 对 device_register 和 aweme/* 会限流/封禁数据中心 IP。请使用住宅代理。
[
IPRoyal 推荐链接(支持本项目): https://iproyal.com/?r=ttproxy
from device.generator import generate_device
# 通过代理做设备注册
dev = generate_device(proxy="http://user:pass@geo.iproyal.com:12321")
# 通过代理搜索
import requests
from headers import generate_headers
headers = generate_headers(url, "GET", b"", cookie, device={"device_id": dev["device_id"], "iid": dev["install_id"]})
r = requests.get(url, headers=headers, proxies={"http": proxy, "https": proxy}, timeout=15)
说明
X-Gorgon8404表ce7c47...、X-Argusac1ada...是 VMlibmetasec_ov.so2065744的scrambled .msf—— 不在 dex 明文里;8404零表占位可让search在46.7.3服务器上通过,精确的46.7.3.msf需要arm64Frida dump。见docs/FINDINGS.md。User-Agent取自LDPlayershared_prefs46.7.3,实测值com.zhiliaoapp.musically/2024607030 (Linux; U; Android 15; en_US; SM-S9280; Build/UQ1A.240205.07291809; Cronet/TTNetVersion:124.0.6367.82)。
局限
- 仅限教育/研究用途,不得商用。不提供担保。作者不对封禁/处罚负责 —— 风险自负,必须遵守 TikTok ToS/法律。见
docs/FINDINGS.md。 - 部分签名:
8404零表 + 简化版 Ladon/Argus 只能过search;严格接口可能失败。服务器可能随时变更。
文件
headers/__init__.py——generate_headers单函数(headers:105)headers/constants.py——46.7.32024607030arm64+armv7a实测常量device/generator.py—— 经 unidbg 的generate_device()(device/generator.py:39)device/Libs/unidbg.jar+prebuilt/<platform>+example_binaries/libEncryptor.so—— VM nativeexamples/device_register.py——unidbg注册examples/aweme_search.py——aweme/v1搜索docs/INSTALL.md—— 安装 + 故障排查docs/USAGE.md—— API + 用法docs/FINDINGS.md—— 审计发现(实测值 vs 占位符、bug、验证)
验证
pip install -r requirements.txt
python -c "from headers import generate_headers; h=generate_headers('https://api16-normal-c-alisg.tiktokv.com/aweme/v1/music/search/?aid=1233&app_name=musical_ly&version_code=2024607030&version_name=46.7.3&device_id=0&iid=0&channel=googleplay&query=love&count=10','GET',b'','store-idc=useast5',device={'device_id':'0','iid':'0'}); assert h['X-Gorgon'].startswith('8404'); print('ok', len(h), 'headers')"
# ok 28 headers
完整审计 -> docs/FINDINGS.md。
捐赠
如果本项目帮到了你,可考虑通过加密货币(OxaPay)支持:
OxaPay: https://pay.oxapay.com/43013861
- BTC:
1KA78sxnqEYPdni4txdieGJzVkH8AEn9dy - ETH:
0xfbfe8b8123572510413b10a0eda3819f29cdbf2b - USDT (TRC20):
TDDZi86Karm6d6dVWjbjtJXkTgjGaCcPFW
哪怕一点点贡献也能让项目活下去。谢谢!
致谢
You signed in with another tab or window. Reload to refresh your session.
You signed out in another tab or window. Reload to refresh your session.
You switched accounts on another tab or window. Reload to refresh your session.
Dismiss alert
| Name | Name |
|---|
TTOOK
Single generate_headers(url, method, body, cookie, ts, device) for all TikTok API requests - factual from app.apk 46.7.3 arm64+armv7a 2024607030.
No toolkit guess - 46.7.3 beta googleplay SM-S9280 Android 15 arm64-v8a from adb dumpsys shared_prefs dex server.json.
Docs: docs/INSTALL.md - docs/USAGE.md - docs/FINDINGS.md
Disclaimer - Educational Use Only. This project is for educational and research purposes only. Not for commercial use. The author(s) provide it as-is without warranty. You are solely responsible for how you use it and for complying with TikTok's Terms of Service and applicable laws. The author(s) are not responsible for any TikTok accounts being banned, penalized, rate-limited, or any other consequences arising from use of this code.
Install
Prereqs: Python 3.10+ - Java 17+ (only for device/, header hash is pure Python) - details in docs/INSTALL.md.
# clone / enter
cd tiktok-x-argus-ladon-gorong-khronos-unidbg
# venv (recommended)
python -m venv .venv
# Windows
.venv\Scripts\activate
# Linux/macOS
source .venv/[bin](https://github.com/ssovit/tiktok-x-argus-ladon-gorgon-khronos-unidbg/tree/main/bin)/activate
# deps
pip install -r [requirements.txt](https://github.com/ssovit/tiktok-x-argus-ladon-gorgon-khronos-unidbg/blob/main/requirements.txt) # requests, pycryptodome>=3.20.0
python -c "from headers import generate_headers; print(generate_headers('https://api16-normal-c-alisg.tiktokv.com/aweme/v1/music/search/?aid=1233&version_code=2024607030&version_name=46.7.3&device_id=0&iid=0&channel=googleplay&query=love&count=10','GET',b'','store-idc=useast5',device={'device_id':'0','iid':'0'})['X-Gorgon'][:20])"
# 8404...
Java resolution (Windows): JAVA_HOME -> C:\Program Files\Android\Android Studio\jbr\bin\java.exe (JBR 25 bundled) -> which java. No PATH needed - device/generator.py:25 finds JBR automatically.
pycryptodome missing -> X-Argus falls back to base64("argus-...") (headers/init.py:103). Search still passes; strict endpoints need it. Fix: pip install pycryptodome.
Full troubleshooting -> docs/INSTALL.md.
Use
from headers import generate_headers
headers = generate_headers(
url="https://api16-normal-c-alisg.tiktokv.com/aweme/v1/music/search/?aid=1233&app_name=musical_ly&version_code=2024607030&version_name=46.7.3&device_id=767909...&iid=...&channel=googleplay&query=love&count=10",
method="GET",
body=b"",
cookie="store-idc=useast5; tt-target-idc=useast5",
device={"device_id": "767909...", "iid": "767909..."},
)
# headers = {
# "X-Gorgon": "8404a0ae1000...", "X-Khronos": "17879...", "X-Ladon": "...", "X-Argus": "...", "X-SS-STUB": "...",
# "x-common-params-v2": "ab_version=46.7.3&aid=1233&...", "x-tt-trace-id": "00-...", "User-Agent": "com.zhiliaoapp.musically/2024607030 ...",
# "Cookie": "store-idc=useast5; ..."
# }
import requests
r = requests.get(url, headers=headers)
print(r.status_code, r.text[:500])
Signature: generate_headers(url, method="GET", body=b"", cookie="", ts=None, device=None) -> dict - see docs/USAGE.md for POST, fixed ts, real device, and header reference.
- X-Gorgon X-Khronos X-Ladon X-Argus X-SS-STUB (hashes)
- x-common-params-v2 x-tt-pba-enable x-tt-dm-status X-SS-REQ-TICKET sdk-version oec-* rpc-persist-* x-tt-trace-id User-Agent Cookie - full 46.7.3 set from app.apk server.json (headers/init.py:129).
Examples
# Device registration (binary TTEncrypt via unidbg, still needed for 46.7.3 log-va)
python [examples](https://github.com/ssovit/tiktok-x-argus-ladon-gorgon-khronos-unidbg/tree/main/examples)/device_register.py
# -> device.json with device_id / install_id (real, not 0)
# Search without login (works with any device_id, even 0 for music/hashtag)
python examples/aweme_search.py
# -> 200 {"music":[]} for 46.7.3
# Video detail page (aweme/detail)
python examples/aweme_detail.py --aweme-id 7410863178971234567
# -> 200 {"aweme_detail": {"aweme_id": "...", "desc": "..."}} for 46.7.3
python examples/aweme_detail.py --aweme-id https://www.tiktok.com/@user/video/7410863178971234567 --proxy http://user:pass@geo.iproyal.com:12321
aweme_search.py / aweme_detail.py load device/test_device_1.json if present, else 0 (search works with 0; detail may need real device — see docs/USAGE.md).
Device registration
device_register uses device/Libs/unidbg.jar libEncryptor.so 75348 TTEncrypt 5.5.0 payload - binary tt-data=a to log-va.tiktokv.com/service/2/device_register/. Details -> docs/FINDINGS.md.
Proxy
TikTok rate-limits / blocks datacenter IPs for device_register and aweme/*. Use residential proxies.

IPRoyal referral (supports this project): https://iproyal.com/?r=ttproxy
from device.generator import generate_device
# device registration via proxy
dev = generate_device(proxy="http://user:pass@geo.iproyal.com:12321")
# search via proxy
import requests
from headers import generate_headers
headers = generate_headers(url, "GET", b"", cookie, device={"device_id": dev["device_id"], "iid": dev["install_id"]})
r = requests.get(url, headers=headers, proxies={"http": proxy, "https": proxy}, timeout=15)
Notes
- X-Gorgon 8404 table ce7c47... X-Argus ac1ada... are VM libmetasec_ov.so 2065744 scrambled .msf - not plain in dex, 8404 zero table placeholder passes search on 46.7.3 server, exact 46.7.3 .msf needs arm64 Frida dump. See docs/FINDINGS.md.
- User-Agent factual com.zhiliaoapp.musically/2024607030 (Linux; U; Android 15; en_US; SM-S9280; Build/UQ1A.240205.07291809; Cronet/TTNetVersion:124.0.6367.82) from LDPlayer shared_prefs 46.7.3.
Limitations
- Educational/research only, not for commercial use. No warranty. Author(s) not responsible for bans/penalties - you assume risk, must obey TikTok ToS/laws. See docs/FINDINGS.md.
- Partial signing: 8404 zero-table + simplified Ladon/Argus pass search only; strict endpoints likely fail. Server can rotate without notice.
Files
- headers/init.py - generate_headers single function (headers:105)
- headers/constants.py - 46.7.3 2024607030 arm64+armv7a factual
- device/generator.py - generate_device() via unidbg (device/generator.py:39)
- device/Libs/unidbg.jar + prebuilt/<platform> + example_binaries/libEncryptor.so - VM natives
- examples/device_register.py - unidbg register
- examples/aweme_search.py - aweme/v1 search
- docs/INSTALL.md - install + troubleshooting
- docs/USAGE.md - API + recipes
- docs/FINDINGS.md - audited findings (factual vs placeholder, bugs, verification)
Verification
pip install -r requirements.txt
python -c "from headers import generate_headers; h=generate_headers('https://api16-normal-c-alisg.tiktokv.com/aweme/v1/music/search/?aid=1233&app_name=musical_ly&version_code=2024607030&version_name=46.7.3&device_id=0&iid=0&channel=googleplay&query=love&count=10','GET',b'','store-idc=useast5',device={'device_id':'0','iid':'0'}); assert h['X-Gorgon'].startswith('8404'); print('ok', len(h), 'headers')"
# ok 28 headers
Full audit -> docs/FINDINGS.md.
Donations
If this project helped you, consider supporting via crypto (OxaPay):
OxaPay: https://pay.oxapay.com/43013861
- BTC: 1KA78sxnqEYPdni4txdieGJzVkH8AEn9dy
- ETH: 0xfbfe8b8123572510413b10a0eda3819f29cdbf2b
- USDT (TRC20): TDDZi86Karm6d6dVWjbjtJXkTgjGaCcPFW
Even a small contribution helps keep this project alive. Thanks!
Credits
No description, website, or topics provided.
Used by
You can’t perform that action at this time.