curl_cffi is a free, open source data extraction & web scraping project written in Python and released under MIT. It has 6,507 GitHub stars, 552 forks and 72 open issues, and was last pushed 15 hours ago. On this registry it ranks #29 of 45 tracked projects in Data Extraction & Web Scraping, with 5 head-to-head comparisons available. It gained 10 stars over the last 3 tracked days.

What is curl_cffi?

curl_cffi is a Python HTTP client that binds the curl-impersonate fork through cffi so Python programs can impersonate browser TLS/JA3 and HTTP/2 fingerprints, and it is aimed at developers whose scripts are blocked by bot protection despite apparently correct requests.

What it is

curl_cffi is a Python binding for the curl-impersonate fork, built with cffi, and it sits beside requests, httpx, aiohttp, and pycurl in the Python HTTP client ecosystem. It belongs to the impersonate suite with curl-impersonate, the brimp browser, the impers Node.js binding, and the impersonate.pro commercial offering. The project is MIT licensed, requires Python 3.10 or newer since v0.14, and is published on PyPI as curl_cffi. Its API mimics requests, so adoption does not require learning a new client interface.

The concrete problem is fingerprint-based blocking. Modern bot protection inspects the TLS/JA3 and HTTP/2 fingerprint of a connection, not only headers or cookies, and pure Python clients such as requests and httpx present fingerprints that differ from real browsers. A site can therefore reject traffic for no obvious reason even when the request is otherwise correct. curl_cffi replaces that transport with curl-impersonate so the connection presents a browser-like fingerprint, including recent browsers and custom fingerprints, and it adds HTTP/2 and HTTP/3 support that requests lacks. Project topics include akamai-fingerprint, ja3, ja3-fingerprint, ja4, http2-fingerprint, and http3-fingerprints.

Key capabilities

  • Impersonates JA3/TLS and HTTP/2 fingerprints, including recent browsers and custom fingerprints, with added support for new algorithms and extensions in Chrome 150/152.
  • Supports HTTP/3 with fingerprints and UDP proxy and HTTP/2, while the README table shows requests and aiohttp without HTTP/2 and requests, aiohttp, and httpx without HTTP/3.
  • Mimics the requests API, so existing requests-style code stays familiar.
  • Supports asyncio with proxy rotation on each request.
  • Supports WebSocket connections.
  • Ships pre-compiled under the MIT licence, so no local compile is required.

Who uses it and how

  • Data extraction and web scraping teams, the registry category for this project, use it when a target site blocks otherwise valid Python requests.
  • Python services written against the requests API adopt it for HTTP/2 or HTTP/3 and browser-like fingerprints without rewriting call sites.
  • Async scraping pipelines use asyncio with proxy rotation on each request, which suits jobs spread across many proxies.
  • Developers facing JavaScript challenges can pair it with brimp, a lightweight browser that works like curl_cffi with JavaScript enabled, while Node.js users can use impers.
  • Teams needing commercial support, additional fingerprints, or a cloud offering can turn to impersonate.pro.

Getting started

Install the PyPI package curl_cffi and follow the documentation at https://curl-cffi.readthedocs.io/; Python 3.10 is the minimum supported version since v0.14. The binding is pre-compiled, so no local build step is required.

How it compares

Among the Python clients named in the README, requests and aiohttp lack HTTP/2, httpx lacks HTTP/3, and pycurl is marked only partially for HTTP/3, while curl_cffi lists HTTP/2 and HTTP/3 with fingerprints. It also differs from curl-impersonate, the underlying curl distribution, from impers, the Node.js binding, and from brimp, the browser-like tool with JavaScript enabled.

When to use it — and when not to

Choose curl_cffi when a Python client must present browser-like TLS/JA3 and HTTP/2 or HTTP/3 fingerprints, particularly in scraping or data extraction where requests and httpx are blocked. A self-hoster operates a Python 3.10+ environment, manages any proxy rotation and UDP proxy infrastructure for HTTP/3, and should expect to track fingerprint updates as browsers change, because impersonation is an ongoing cat-and-mouse process; the commercial impersonate.pro option exists for more fingerprints and support. It is a poor fit for projects that are not blocked, that require a pure-Python dependency with no compiled component, or that are pinned below Python 3.10.

project readme (upstream, from github) — read inline

curl_cffi

PyPI Downloads PyPI - Python Version PyPI version Generic badge Generic badge

Documentation

Python binding for curl-impersonate fork via cffi. For commercial support, visit impersonate.pro.

curl_cffi is the most popular Python binding for curl. Unlike other pure python http clients like httpx or requests, curl_cffi can impersonate browsers' TLS/JA3 and HTTP/2 fingerprints. If you are blocked by some website for no obvious reason, you can give curl_cffi a try.

For JavaScript bindings, see impers, for solving JavaScript challenges, see brimp.

Python 3.10 is the minimum supported version since v0.14.

Recent highlights

  • 🧭 Our new toy, brimp, a lightweight browser, works like curl_cffi with JavaScript enabled. Try it out today!
  • 🆕 Added support for the new algorithm and extensions in Chrome 150/152.

Recall.ai - API for meeting recordings

Recall.ai

If you’re looking for a meeting recording API, consider checking out Recall.ai, an API that records Zoom, Google Meet, Microsoft Teams, in-person meetings, and more.

Sponsors

Maintenance of this project is made possible by all the contributors and sponsors. If you'd like to sponsor this project and have your avatar or company logo appear below click here. 💖


Bypass Cloudflare with API

Yes Captcha!

Yescaptcha is a proxy service that bypasses Cloudflare and uses the API interface to obtain verified cookies (e.g. cf_clearance). Click here to register:


TLS fingerprinting alone isn't enough for modern bot protection. Hyper Solutions provides the missing piece - API endpoints that generate valid antibot tokens for:

Akamai • DataDome • Kasada • Incapsula

No browser automation. Just simple API calls that return the exact cookies and headers these systems require.

🚀 Get Your API Key | 📖 Docs | 💬 Discord


cloro: SERP and AI search API for Google, ChatGPT, Perplexity, Gemini, Copilot and Grok


Impersonate Suite

curl-cffi is part of the impersonate suite.

  • curl-impersonate. A curl distribution that impersonates browsers.
  • curl_cffi. Python binding to curl-impersonate.
  • brimp. Browser-impersonate, a lightweight browser
  • impers. Node.js binding to curl-impersonate.
  • impersonate.pro. Commercial support, more fingerprints and cloud offering.

Features

  • Supports JA3/TLS and http2 fingerprints impersonation, including recent browsers and custom fingerprints.
  • Much faster than requests/httpx, on par with aiohttp/pycurl, see benchmarks.
  • Mimics the requests API, no need to learn another one.
  • Pre-compiled, so you don't have to compile on your machine.
  • Supports asyncio with proxy rotation on each request.
  • Supports http 2.0, which requests does not.
  • Supports http 3.0, with fingerprints and udp proxy.
  • Supports websocket.
  • MIT licensed.
requests aiohttp httpx pycurl curl_cffi
http/2
http/3 ☑️1 2
sync
async
websocket
native retry
fingerprints
speed 🐇 🐇🐇 🐇 🐇🐇 🐇🐇

Notes:

  1. For pycurl, http/3 is usually disabled at compile time by default.
  2. http/3 support since v0.11.4, http/3 proxy and fingerprints since v0.15.0.

Install

pip install curl_cffi --upgrade

This should work on Linux, macOS and Windows out of the box.

On macOS, you can also install via Homebrew:

brew install lexiforest/tap/curl-cffi

To install beta releases:

pip install curl_cffi --upgrade --pre

To install unstable version from GitHub:

git clone https://github.com/lexiforest/curl_cffi/
cd curl_cffi
make preprocess
pip install .

Usage

curl_cffi comes with a low-level curl API and a high-level requests-like API. curl_cffi also bundles with a CLI called curl-cffi.

CLI

Since v0.15, curl_cffi comes with a CLI called curl-cffi, you can use it for debugging a certain url with the --impersonate option. It can also serve as a web_fetch replacement for "agents".

curl-cffi get tls.browserleaks.com/json

# curl-cffi can be hard to type, use an alias if you want
alias imp=curl-cffi
imp get tls.browserleaks.com/json --impersonate chrome

For a complete CLI guide, see docs.

requests-like

import curl_cffi

# Notice the impersonate parameter
r = curl_cffi.get("https://tls.browserleaks.com/json", impersonate="chrome")

print(r.json())
# output: {..., "ja3n_hash": "aa56c057ad164ec4fdcb7a5a283be9fc", ...}
# the js3n fingerprint should be the same as target browser

# To keep using the latest browser version as `curl_cffi` updates,
# simply set impersonate="chrome" without specifying a version.
# Other similar values are: "safari" and "safari_ios"
r = curl_cffi.get("https://tls.browserleaks.com/json", impersonate="chrome")

# Use http/3 with impersonation
r = curl_cffi.get(
    "https://fp.impersonate.pro/api/http3",
    http_version="v3",
    impersonate="chrome"
)

# To pin a specific version, use version numbers together.
r = curl_cffi.get("https://tls.browserleaks.com/json", impersonate="chrome124")

# To impersonate other than browsers, bring your own ja3/akamai strings
# See examples directory for details.
r = curl_cffi.get("https://tls.browserleaks.com/json", ja3=..., akamai=...)

# http/socks proxies are supported
proxies = {"https": "http://localhost:3128"}
r = curl_cffi.get("https://tls.browserleaks.com/json", impersonate="chrome", proxies=proxies)

proxies = {"https": "socks://localhost:3128"}
r = curl_cffi.get("https://tls.browserleaks.com/json", impersonate="chrome", proxies=proxies)

Sessions

s = curl_cffi.Session()

# httpbin is a http test website, this endpoint makes the server set cookies
s.get("https://httpbin.org/cookies/set/foo/bar")
print(s.cookies)
# <Cookies[<Cookie foo=bar for httpbin.org />]>

# retrieve cookies again to verify
r = s.get("https://httpbin.org/cookies")
print(r.json())
# {'cookies': {'foo': 'bar'}}

Supported impersonate browsers

curl_cffi supports the same browser versions preset as supported by our fork of curl-impersonate:

The open source version of curl_cffi includes versions when we are adding new capabilities for impersonating. If you see a version, e.g. chrome135, was skipped, it's simply because there's nothing new or we were busy at that time. Y

readme truncated — read the full docs on github

Frequently asked questions

Is curl_cffi free to use?

curl_cffi is open source under the MIT licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does curl_cffi do?

Python binding for curl-impersonate fork via cffi. A http client that can impersonate browser tls/ja3/http2 fingerprints.

What is curl_cffi written in?

curl_cffi is primarily written in Python. Its source is publicly available at https://github.com/lexiforest/curl_cffi, and it has 6,507 GitHub stars.