unmask

docs

JA4 acquisition, LB / CDN setup, supported distros, FAQ.

Getting started

unmask is a bot challenge built on JA4 TLS fingerprints and other signals. Start with install (pick OS × HTTP server to get the exact commands).

Whether JA4 is available depends on where TLS terminates and native / forward-auth. Find your setup and the topics here:

  • JA4 acquisition — table of JA4 availability per setup pattern (the old “deployment topologies” live here)
  • LB / CDN setup — getting JA4 from a front LB / CDN (GCP / Cloudflare / AWS etc.)
  • Verified crawlers — stopping UA-spoofed crawlers: why the address decides, not the name
  • Advisor — mechanically extracted ban candidates with their evidence, an optional model layer, and a scheduled digest
  • Supported distros — the OS × HTTP server matrix
  • Backup & restore — back up config / DB / bans, restore on a new host
  • Monitoring — Prometheus /metrics endpoint + healthz liveness probe
  • Offline range updates — keeping crawler IP ranges fresh on hosts without outbound HTTPS / with legacy trust stores
  • Containers — the GHCR images, docker compose quick start, and the gateway mode that puts unmask in front of any HTTP server
  • FAQ — common operational questions