
A next-generation HTTP stealth proxy which perfectly cloaks requests as the Chrome browser across all layers of the stack.
"I don't believe it, thermoptic camouflage!"
This is an HTTP proxy designed to bypass services that use fingerprinting such as JA4+ to block certain HTTP clients. Using this proxy, you can use your preferred HTTP clients like curl and still have magically indistinguishable fingerprints from a real (Chrome/Chromium) web browser. thermoptic also comes with some fun features to mitigate JavaScript-based fingerprinting. It also makes it easy to do hybrid scraping using both a web browser and low-level HTTP clients together.
Even if you’re unfamiliar with JA4+ fingerprinting, if you’ve done any scraping you’ve probably been blocked by it before. Popular services such as Cloudflare use such techniques (and other tricks) to detect use of "non-human" HTTP clients to block requests. These services can also use this fingerprinting to detect if you start a session with a real browser and then switch to a low-level client like curl later. thermoptic solves all of these problems by presenting a unified "real" browser fingerprint for all scraping requests.
Here's an example JA4H (HTTP) fingerprint of curl without the proxy:
$ curl https://ja4db.com/id/ja4h/
ge11nn090000_b6a016211e8a_000000000000_e3b0c44298fc
This is quite different from the fingerprint that Chrome produces when you visit the URL directly:
ge11cn19enus_f2808f0d04cf_9a10d4221160_7068f58def6e
However, when we use the proxy to make the request, our JA4H fingerprint is magically identical:
$ curl --proxy http://thermoptic:1234 https://ja4db.com/id/ja4h/
ge11cn19enus_f2808f0d04cf_9a10d4221160_7068f58def6e
(The same goes for our JA4 TLS fingerprint as well, etc).
To start a thermoptic proxy which cloaks your traffic through a containerized Chrome instance on Ubuntu 22.04:
Regular Docker setup (works on hosts without a GPU runtime):
docker compose up --build
That's all, now you can proxy traffic through it:
curl --proxy http://127.0.0.1:1234 --insecure https://ja4db.com/id/ja4h/
Important notes:
PROXY_USERNAME and PROXY_PASSWORD.---insecure you need to use the generated CA file located in ./ssl/rootCA.crt. This is generated the first time you run thermoptic.thermoptic to any Chrome/Chromium instance launched with the --remote-debugging-port flag. This is essential as you'll want to set up and proxy through more commonly used environments to keep your fingerprint as low profile as possible (e.g. Chrome on Windows)./dev/dri, and lets the bundled Chrome container switch to the NVIDIA/Vulkan rendering path. To use this, run docker compose -f docker-compose.yml -f docker-compose.gpu.yml up --build.curl, requests, etc) with thermoptic, just set the proxy and your fingerprints are taken care of../hooks/onstart.js.http://127.0.0.1:14111) to control the Dockerized Chrome browser window. Useful to manually log into sites manually and then seemlessly use the proxy to make requests as your logged-in session (and for debugging).UPSTREAM_PROXY environment variable in docker-compose.yml.
curl with thermoptic set as a proxy.thermoptic analyzes the request to best determine what type of browser request it's supposed to be (e.g. manual URL visit? Form submission? A fetch() request?).thermoptic uses the Chrome Debugging Protocol (CDP) to puppet the browser and set up a page that mocks the request exactly as it normally would occur in a real web browser.thermoptic triggers the request via the mocked context and captures the HTTP response.thermoptic sends the HTTP response back to the client.Due to the fact that the browser is actually making the request using its full stack, the resulting JA4 fingerprints are identitical.
NOTE: Due to many WAFs employing JavaScript-level fingerprinting of web browsers, thermoptic also exposes hooks to utilize the browser for key steps of the scraping process. See this section for more information on this.
To put it bluntly: other approaches have fundamental flaws which prevent them from being a practical long term solution to the browser fingerprinting problem.
Many other attempts to "beat" browser JA4+ fingerprinting do so by reimplementing the various layers of the browser stack. This approach has a number of serious drawbacks, such as:
In contrast, because thermoptic uses the browser itself to perform HTTP requests:
thermoptic controls just needs to be updated in order to match the latest set of fingerprints.Of course, no solution is without drawbacks. See the DOWNSIDES.md docs for a fleshed out list of downsides to the thermoptic approach.