Server-side fingerprinting identifies a client using signals observable by the server during a request: HTTP headers and their order, TLS handshake parameters, IP address and routing attributes, and request timing. Because these signals are captured before any JavaScript runs, the technique works even when the client blocks or disables scripts, but yields lower entropy than rich client-side device fingerprints.
Every HTTP request carries observable metadata the client cannot easily suppress. The set of headers a browser sends, the order in which it sends them, the values it chooses for Accept-Language or Accept-Encoding, and the TLS cipher suites it advertises in its ClientHello all reflect the browser's implementation. A server or proxy can collect these fields and hash them into a fingerprint without any cooperation from, or even awareness by, the client-side page.
Common server-side signals include: HTTP header presence and order (browsers have distinctive default header sets), TLS/JA3 parameters from the ClientHello, IP geolocation and ASN attributes, and connection timing characteristics such as TCP window sizes. Each signal carries modest entropy on its own; a practical server-side fingerprint combines several of them.
The key tradeoff against client-side fingerprinting is coverage versus resistance. Server-side signals cannot be blocked by a browser extension, a content blocker, or a JavaScript sandbox, because they are emitted by the networking stack before the page loads. However, they are coarser and carry less identifying information than the hundreds of rendering, hardware, and API signals a client-side library can collect. They are also more susceptible to normalisation: CDNs rewrite headers, VPNs change IP addresses, and some TLS signals vary between network paths. A production detection system typically treats server-side signals as a lightweight, always-available first filter, then supplements them with richer client-side device fingerprints when JavaScript is available.
In doorman-benny
doorman-benny collects signals from JavaScript APIs inside the browser: rendering outputs, hardware descriptors, browser capabilities, and behavioural timing. It does not observe the HTTP request headers, TLS handshake parameters, or IP attributes that server-side fingerprinting uses, because those are network-layer signals outside the JavaScript environment. The two approaches are complementary: server-side signals provide a JS-independent baseline, while Benny's client-side device fingerprint contributes the higher-entropy hardware and rendering signals that distinguish devices within the same broad network profile.
Frequently asked questions
What is server-side fingerprinting?
Server-side fingerprinting identifies a client using signals the server observes during a request, such as HTTP headers and their order, TLS handshake parameters, IP address, and connection timing, without executing any code on the client. It works even when JavaScript is disabled or blocked.
Is server-side fingerprinting better than client-side fingerprinting?
Neither is strictly better; they capture different signal surfaces. Server-side fingerprinting is harder for users to block because it uses network-level signals that precede page execution, but it has lower entropy than client-side device fingerprinting, which can access hundreds of browser and hardware signals. Most robust detection pipelines use both.
What HTTP signals does server-side fingerprinting use?
Common signals include the set of HTTP request headers a client sends by default, the order in which those headers appear, specific header values such as Accept-Language and User-Agent, and TLS ClientHello parameters. Each browser and HTTP library has a characteristic header fingerprint that reflects its implementation.
Can server-side fingerprinting be defeated by a VPN or proxy?
A VPN or proxy changes the client's IP address and may rewrite some headers, which degrades IP-based and header-based signals. However, TLS parameters and the underlying header structure often survive routing changes, so a VPN is not a complete countermeasure against server-side fingerprinting.
How does server-side fingerprinting relate to JA3 fingerprinting?
JA3 fingerprinting is one specific server-side technique: it hashes TLS ClientHello fields to identify the client's TLS stack. Server-side fingerprinting is the broader concept that encompasses JA3, HTTP header analysis, IP intelligence, and other signals observable at the network layer before any JavaScript runs.

