JA3 and JA4 fingerprints. If the domain has enabled Advanced Bot Management but the EO-Bot-Fingerprint header in the origin-pull request is empty, check whether HTTPS access is enabled for the domain.EO-Bot-Tag header is retained with unchanged behavior and is independent of the headers described in this document.www.example.com.Top-level Type | Structure | Applicable Headers |
Dictionary | Members are in the "key=value" format and separated by commas. | EO-Bot-Fingerprint,EO-Bot-Known-Tool,EO-Bot-Search-Engine,EO-Bot-Source-IDC,EO-Bot-IP-Reputation,EO-Bot-Intelligence,EO-Bot-Botnet-ID |
List | Members are attestation instances separated by commas. Each instance consists of a bare value and parameters, with parameters introduced by a semicolon. | EO-Bot-Client-Attestation,EO-Bot-Client-Risk,EO-Bot-User-Risk |
EO-Bot-Fingerprintja3 and ja4 fingerprints are carried based on the actual detection capability; either one or both of them may be present.Field | Type | Description |
ja3 | String | TLS client JA3 fingerprint. |
ja4 | String | TLS client JA4 fingerprint. |
EO-Bot-Fingerprint: ja3="d41d8cd98f00b204e9800998ecf8427e", ja4="t13d1516h2_8daaf6152771_02713d6af862"
EO-Bot-Known-ToolField | Type | Description |
category_name | String | The category of the matched tool. The value is maintained by the EdgeOne tool signature database, for example, search_engine (search engine). |
tool_name | String | Name of the matched tool, for example, Bingbot, GoogleBot, PagePeeker. |
EO-Bot-Known-Tool: category_name="search_engine", tool_name="Bingbot"
EO-Bot-Search-EngineField | Type | Description |
provider_name | String | Name of the matched search engine provider, for example, 360Spider, DuckDuckBot, GoogleBot. |
EO-Bot-Search-Engine: provider_name="360Spider"
EO-Bot-Source-IDCField | Type | Description |
idc_name | String | Name of the IDC or carrier, for example, pccw.com. |
EO-Bot-Source-IDC: idc_name="pccw.com"
EO-Bot-IP-ReputationField | Type | Description |
<threat_type> | String | The field name is the threat type. Values include attacker (network attack), proxy (network proxy), scanner (scanner), account_take_over (account takeover attack), and malicious_bot (malicious Bot). |
Value of <threat_type> | String | Confidence level of the corresponding threat type. Values include high (high confidence), medium (medium confidence), and low (low confidence). |
EO-Bot-IP-Reputation: proxy="high", account_take_over="medium"
EO-Bot-IntelligenceField | Type | Description |
bot_rating | String | Bot rating. Values include evil_bot (malicious Bot request), suspect_bot (suspected Bot request), good_bot (normal Bot request), normal (normal request), and - when the bot rating is unclassified. |
EO-Bot-Intelligence: bot_rating="evil_bot"
EO-Bot-Client-AttestationField | Type | Description |
token_status | String | Token verification status. Values include valid (token valid), invalid (token invalid), and expired (token expired). |
token_exceptions | String | Reason for token verification exception. Multiple exception tags are separated by half-width commas (,). Values include EO-Attest-TokenMissing (the request does not carry the attestation result token), EO-Attest-TokenExpired (the token has expired), and EO-Attest-UsageLimitExceeded (the token has exceeded the usage limit), etc. |
EO-Bot-Client-Attestation: attest-0000056382;token_status="expired";token_exceptions="EO-Attest-TokenExpired"
EO-Bot-Client-RiskField | Type | Description |
attester_type | String | Attestation method identifier, generated by combining the attestation provider and attestation option, for example, TC-EO-CAPTCHA. Available attestation providers include EdgeOne human verification, Tencent Cloud Captcha, and Tencent Cloud RCE. The specific value is subject to the configuration in the console under Client Attestation > Attesters. |
device_type | String | Client device type that initiates attestation, for example, android. |
risk_score | Integer | Client risk score. The value range is 0-100, and a higher score indicates higher risk. |
risk_level | String | Client risk level. Values include high (high risk), medium (medium risk), and low (general risk). |
risk_details | String | Client risk details. Multiple risk tags are separated by half-width commas (,), for example, EO-App-DataAnomaly (abnormal client data) and EO-App-FPLowConfidence (low confidence in client fingerprint). |
EO-Bot-Client-Risk: attest-0000056382;attester_type="TC-EO-CAPTCHA";device_type="android";risk_score=100;risk_level="high";risk_details="EO-App-DataAnomaly,EO-App-FPLowConfidence"
EO-Bot-User-RiskField | Type | Description |
attester_type | String | Attestation method identifier, generated by combining the attestation provider and attestation option, for example, TC-EO-CAPTCHA. Available attestation providers include EdgeOne human verification, Tencent Cloud Captcha, and Tencent Cloud RCE. The specific value is subject to the configuration in the console under Client Attestation > Attesters. |
device_type | String | Client device type that initiates attestation, for example, android. |
user_id | String | User account identifier that initiates attestation. The value is the Base64 encoding of the original account representation. |
user_operation | String | User operation type, defined by the business in Client Attestation rules. The value is the Base64 encoding of the original operation type. |
risk_score | Integer | Account risk score. The value range is 0-100, and a higher score indicates higher risk. |
risk_level | String | Account risk level. Values include high (high risk), medium (medium risk), and low (general risk). |
risk_details | String | Account risk details. Multiple risk tags are separated by half-width commas (,), for example, EO-Acc-UReqRateE (excessively fast user requests). |
EO-Bot-User-Risk: attest-0000056382;attester_type="TC-EO-CAPTCHA";device_type="android";user_id="YWRtaW4=";user_operation="YWNjb3VudC5sb2dpbg==";risk_score=99;risk_level="high";risk_details="EO-Acc-UReqRateE"
EO-Bot-Botnet-IDField | Type | Description |
botnet_id | String | Bot network identifier, for example, 0dad2a4c7f1e93b5c2d84e6f0a1b3c57. |
EO-Bot-Botnet-ID: botnet_id="0dad2a4c7f1e93b5c2d84e6f0a1b3c57"
Was this page helpful?
You can also Contact sales or Submit a Ticket for help.
Help us improve! Rate your documentation experience in 5 mins.
Feedback