How to Configure TLS Fingerprint Spoofing in OmniRoute: A Complete Implementation Guide

Enable the TLS fingerprint proxy by setting TLS_FINGERPRINT_ENABLED=true in your environment variables and define fingerprint profiles in the session pool to disguise outbound HTTP(S) requests as coming from different browsers.

OmniRoute is an open-source request routing proxy that supports advanced traffic anonymization techniques. When you configure TLS fingerprint spoofing in OmniRoute, the system routes outbound HTTP(S) requests through a specialized TLS-client proxy that injects crafted TLS fingerprints—including User-Agent strings, Accept-Language headers, and TLS-level identifiers—to mimic legitimate browser traffic or any custom profile you define.

Understanding the TLS Fingerprint Architecture

The implementation consists of three integrated components that work together to mask your traffic's identity.

Define Fingerprint Profiles in the Session Pool

Fingerprint profiles are stored in the session-pool service and managed by the FingerprintRotator class. Each profile contains a userAgent, acceptLanguage, and optional tlsSignature. The rotator cycles through available profiles in open-sse/services/sessionPool/fingerprintRotator.ts, ensuring every request appears to come from a different client with a unique fingerprint.id.

Enable the TLS-Client Proxy

Set the environment variable TLS_FINGERPRINT_ENABLED=true in your .env file. When enabled, the proxy instantiated in open-sse/services/tlsClientProxy.ts intercepts every outbound fetch and rewrites the TLS handshake using the selected fingerprint profile.

Wire the Proxy into Request Handling

The core request pipeline flows through handleChatCoretranslateRequestgetExecutor. In open-sse/utils/tlsClient.ts, the executor checks if fingerprinting is active. If so, it passes the current fingerprint to tlsClientProxy.runWithTlsTracking, which creates a temporary TLS socket that mimics the chosen profile.

How TLS Fingerprint Spoofing Works Internally

Fingerprint Rotation Strategy

When a new session initializes, FingerprintRotator.next() returns a fresh fingerprint object. This method guarantees round-robin distribution across your profile pool, ensuring each request presents a distinct TLS identity to remote servers.

TLS Capture for Custom Signatures

The MITM layer in src/mitm/tproxy/tlsCapture.ts can record raw TLS handshakes from real browsers. You can store these captured signatures as templates and replay them through the proxy, enabling precise spoofing of specific server-expected signatures.

Proxy Execution Flow

The runWithTlsTracking function in open-sse/services/tlsClientProxy.ts builds a temporary HTTPS server that wraps upstream requests. It injects fingerprint headers and optionally replaces the TLS ClientHello with a captured signature. The proxy then streams the response back to the original handler without the upstream server detecting the spoofing.

Fallback Mechanism

If the proxy cannot start due to missing certificate files or other errors, the system falls back to standard HTTPS requests. The unit test suite in tests/unit/tls-options.test.ts validates both proxy-enabled and proxy-disabled code paths to ensure no fatal errors occur for the caller.

Configuration Examples

Adding Fingerprint Profiles

Store JSON profiles in your database that the session-pool loads at startup:

[
  {
    "id": "fp-chrome-101",
    "userAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) Chrome/101.0.4951.54 Safari/537.36",
    "acceptLanguage": "en-US,en;q=0.9",
    "tlsSignature": "chrome-101"
  },
  {
    "id": "fp-firefox-96",
    "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:96.0) Gecko/20100101 Firefox/96.0",
    "acceptLanguage": "en-US,en;q=0.8",
    "tlsSignature": "firefox-96"
  }
]

Enabling via Environment Variables

Add to your .env file:

TLS_FINGERPRINT_ENABLED=true

Manual Implementation in Custom Code

For advanced use cases, manually invoke the proxy in your TypeScript code:

import { runWithTlsTracking } from '@/open-sse/services/tlsClientProxy';
import { FingerprintRotator } from '@/open-sse/services/sessionPool/fingerprintRotator';

// Obtain a fingerprint for the current request
const fp = FingerprintRotator.next();

// Wrap a fetch call with the TLS proxy
const response = await runWithTlsTracking(fp, async () => {
  return fetch('https://api.example.com/v1/data', {
    method: 'GET',
    headers: { 'Accept': 'application/json' },
  });
});
const data = await response.json();

The runWithTlsTracking function automatically creates a temporary TLS socket presenting the chosen fingerprint to the remote server.

Automatic Integration

When you enable the environment flag, the core request pipeline automatically calls the proxy whenever a fingerprint attaches to the session. No additional code changes are required for standard implementations.

Key Source Files Reference

Summary

Frequently Asked Questions

What is TLS fingerprint spoofing and why use it in OmniRoute?

TLS fingerprint spoofing disguises the cryptographic signature of your HTTP client to mimic legitimate browser traffic. In OmniRoute, this prevents detection by services that block or throttle non-browser TLS implementations, allowing your requests to blend in with regular user traffic.

Where are fingerprint profiles stored in OmniRoute?

Fingerprint profiles reside in the session-pool service and are managed by the FingerprintRotator class. You define profiles as JSON objects containing userAgent, acceptLanguage, and optional tlsSignature fields, which the system loads at startup from your configured database.

Can I use custom TLS signatures captured from real browsers?

Yes. The tlsCapture.ts module in src/mitm/tproxy/tlsCapture.ts records raw TLS handshakes from actual browser sessions. You can store these captures as templates and reference them in your fingerprint profiles' tlsSignature field to replay authentic browser signatures.

What happens if the TLS proxy fails to start?

If the TLS proxy encounters errors such as missing certificate files, OmniRoute automatically falls back to standard HTTPS requests. The tls-options.test.ts unit test suite verifies this fallback behavior to ensure your application continues functioning even when fingerprinting is unavailable.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →