httpcloak
Go HTTP client with browser-identical TLS/HTTP2 fingerprinting. Bypass bot detection by perfectly mimicking Chrome, Firefox, and Safari at the cryptographic level (JA3/JA4, Akamai fingerprint, header order). Supports HTTP/1.1, HTTP/2, HTTP/3, sessions, cookies, and proxies.
Not yet testedsource: GitHubhomepageGoMITcommit 30379124605d
Go, MIT licensed. The project labels itself: anti bot, bot detection, browser fingerprint, browser fingerprinting, cloudflare, go, golang and http client.
httpcloak has not been verified yet.
Measured by Argusic on a fresh machine every time. Every number links to its evidence.
At a glance
Subject data from GitHub, linked at the top of this page, refreshed . Test data by Argusic (CC BY 4.0); every number links to a run page with the full log, the recording, and their sha256 hashes.
Also tested, in the same area
Every one of these was installed and run by Argusic on a clean machine. Nothing appears here that was not tested.
Run history
No recorded runs.
Topics (from GitHub)
anti-botbot-detectionbrowser-fingerprintbrowser-fingerprintingcloudflaregogolanghttp-clienthttp2http3ja3-fingerprintja4-fingerprintjsnodejspythonpython3quictls-fingerprinttls-fingerprintingweb-scraping
Embed the badge
Markdown for the project README. It links back here; terms on the terms page.
[](https://argusic.com/subject/httpcloak)Questions
- Does httpcloak run?
- httpcloak has not been fully verified yet. No recorded run has produced a verdict yet.
- How did Argusic test httpcloak?
- On a fresh, disposable machine, with every command recorded. 0 attempts are recorded, and the full method is on the methodology page.
- Where is the evidence for httpcloak?
- All 0 recorded runs are on this page, each linking to its full log and terminal recording, stored with a sha256 fingerprint so it cannot be quietly altered.