utls

A fork of Go's standard TLS library that gives low-level control over the TLS ClientHello. It is used to make connections look like other clients, mainly for censorship circumvention.

Share on XLicense: BSD-3-Clause

Overview

uTLS is a fork of Go's crypto/tls library that gives low-level access to the TLS ClientHello. The handshake itself is still done by crypto/tls, and uTLS only changes the ClientHello and exposes its details. Go's default ClientHello has a distinctive fingerprint, so tools can be easily recognised and blocked. With uTLS a program can imitate other clients, which is mainly used for anti-censorship. It requires Go 1.21 or newer.

Key features

  • Read and write access to all bits of the ClientHello
  • Fingerprint resistance, including randomized fingerprints
  • Read access to ClientHandshakeState such as ServerHello
  • Support for fake session tickets

Best for

Aimed at Go developers building anti-censorship or similar tools that must not stand out. The README warns parts of its documentation may be outdated, so check godoc.

Upstream
refraction-networking/utls
Fork on GitHub
Guo-astro/utls
Upstream stars
2.6k
Category
Security and networking
Language
Go
License
BSD-3-Clause
Forked
2025-10-15
Sync status
In syncLast synced 2026-09-29