Star 历史趋势
数据来源: GitHub API · 生成自 Stargazers.cn
README.md

tikTok Web Signature Generator

Stars Forks Issues

Fully reverse-engineered TikTok Web API signature generator. Produces valid X-Gnarly, X-Bogus, and X-Dynosaur signatures that TikTok accepts with success responses.

Confirmed working — TikTok returns status_code: 0 (success) when requests are signed with these generators.

Need more than signatures? Profiles, followers, videos, comments, live chat and search through one REST API:
Unofficial TikTok API - dev.omar-thing.site

Reverse-Engineered Algorithm

This project contains a complete reverse engineering of TikTok's web signature algorithm (SDK version 5.3.2, build 1.0.0.417).

The algorithm was recovered through:

Deobfuscation of the production webmssdk.js bundle

Static analysis of the ChaCha-based cipher implementation

Dynamic tracing of signature generation at runtime

Byte-level reconstruction of the payload serialization format

Verification against live TikTok API responses

Result: Signatures generated by this library are accepted by TikTok's servers and return success responses (status_code: 0). Features

Generate X-Dynosaur signatures with ChaCha20 encryption and FNV-1a hashing

Generate X-Gnarly signatures with ChaCha20 encryption, MD5 digests and PRNG shuffle

Generate X-Bogus placeholder (legacy compatibility)

Support for SDK version 5.3.2 (build 1.0.0.417)

Custom Base64 alphabet encoding

Pure Python implementation

Lightweight and production-ready

No external API calls — everything computed offline

Deterministic with fixed inputs

Produces valid signatures that TikTok accepts

Installation bash

git clone https://github.com/n1tr00-10/tiktok-web-signature.git cd tiktok-web-signature

No dependencies beyond the Python standard library. Versions Component Version SDK 5.3.2 SCM Version 1.0.0.417 SCM Sub Version 1.0.0.2858 Release Build 1.0.0.417 Slardar SDK 1.16.6 Files text

tiktok-web-signature/ ├── x_dynosaur.py # X-Dynosaur generator ├── x_gnarly.py # X-Gnarly generator ├── x_bogus.py # X-Bogus placeholder (legacy) └── README.md

Usage X-Dynosaur python

from x_dynosaur import get_x_dynosaur

query = "aid=1988&app_name=tiktok_web&device_platform=web_pc" user_agent = "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" body = ""

token = get_x_dynosaur(query, user_agent, body) print(token)

X-Gnarly python

from x_gnarly import get_x_gnarly

query = "aid=1988&app_name=tiktok_web&device_platform=web_pc" user_agent = "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" body = ""

token = get_x_gnarly(query, user_agent=user_agent, body=body) print(token)

Full request with signatures python

import requests from x_dynosaur import get_x_dynosaur from x_gnarly import get_x_gnarly

query = "aid=1988&app_name=tiktok_web&device_platform=web_pc" ua = "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" body = ""

dynosaur = get_x_dynosaur(query, ua, body) gnarly = get_x_gnarly(query, dynosaur, "", ua, body)

headers = { "User-Agent": ua, "X-Dynosaur": dynosaur, "X-Gnarly": gnarly, }

resp = requests.get(f"https://www.tiktok.com/api/...?{query}", headers=headers) print(resp.json()) # TikTok returns success with valid signatures

Optional parameters Parameter Default Description timestamp int(time.time()) Unix timestamp f8 session value 32-bit session field canvas 2316120563 Canvas fingerprint value envcode 65 Environment code version "5.3.2" SDK version scm_version "1.0.0.417" SCM version security_flag 0 Security flag flag_32 0 32-bit flag flag_125 0 125-bit flag url / referer "www.tiktok.com/" Page URL proof_result "0" Proof-of-work result key_words random Custom ChaCha key (12 words) How it works

Both signatures use the same ChaCha-based cipher with:

4 constants: [1196819126, 600974999, 3863347763, 1451689750]

12 key words: derived from a PRNG

Round count: (sum(key) & 0x0f) + 5

Insert position: (sum(key_bytes) + sum(cipher)) % (len(cipher) + 1)

X-Dynosaur payload

56 fields (tags 0x20 – 0x38) containing:

timestamp, session value, canvas, envcode

FNV-1a hashes of query, body, user-agent

version strings

checksum field (0x20)

X-Gnarly payload

16 fields (indexes 0 – 16) containing:

MD5 digests of query, body, user-agent

timestamp, session value, canvas

version strings

XOR checksum fields

Fields are shuffled using a PRNG seeded from f8 before serialization. Custom Base64 alphabet text

u09tbS3UvgDEe6r-ZVMXzLpsAohTn7mdINQlW412GqBjfYiyk8JORCF5/xKHwacP=

Verification

Signatures have been verified against live TikTok API endpoints. With valid X-Dynosaur and X-Gnarly headers, TikTok returns: json

{"maigc":538051346,"version":1,"dataType":8} Updated token from response: ZKayKXtxB3G8lNt8L8ANOXxIgMRvPSnXFDYM2ocnU8cT5Ojn0UtXjJrO-kIqPSwfnsJx1VcdZkCEg9BZCXiLFL4Mz9BNMCcmIt0-evhDA4QwRnyfSNhKzT4mkdViClma2eBZblxz Token Validation HTTP 200 API Response: {'status_code': 0} Validation Result: {'valid': True, 'status': 0} fresh activated msToken ZKayKXtxB3G8lNt8L8ANOXxIgMRvPSnXFDYM2ocnU8cT5Ojn0UtXjJrO-kIqPSwfnsJx1VcdZkCEg9BZCXiLFL4Mz9BNMCcmIt0-evhDA4QwRnyfSNhKzT4mkdViClma2eBZblxz

This confirms the reverse-engineered algorithm is correct and the signatures are accepted by TikTok's servers. Token length

Token length is not fixed. It varies between 230–420 characters depending on:

Payload content

Field values (timestamp, canvas, envcode, etc.)

PRNG randomness

Base64 padding

This is normal and expected. FAQ

Do I need a session ID? No. Signatures are generated locally and do not require authentication.

Do these signatures expire? Yes. TikTok validates the timestamp embedded in the signature. Generate fresh signatures for each request.

Why is my token a different length than someone else's? The payload contains variable-length fields (hashes, timestamps, version strings). Different inputs produce different output lengths.

Which version does this support? SDK 5.3.2, build 1.0.0.417.

Are the signatures actually valid? Yes. The algorithm has been fully reverse-engineered and verified against live TikTok API responses. TikTok accepts these signatures and returns success.

Can I use this for automation? Yes, but always respect TikTok's Terms of Service and rate limits. Changelog v1.0.0 — SDK 5.3.2

Complete reverse engineering of TikTok's web signature algorithm

X-Dynosaur generator (ChaCha20 + FNV-1a)

X-Gnarly generator (ChaCha20 + MD5 + PRNG shuffle)

X-Bogus placeholder

Custom Base64 alphabet encoding

Support for SDK version 5.3.2 (build 1.0.0.417)

Verified against live TikTok API — returns success responses

Disclaimer

This project is provided for educational and research purposes only. It is not affiliated with, endorsed by, or sponsored by TikTok or ByteDance.

Use responsibly and in accordance with TikTok's Terms of Service. The authors are not responsible for any misuse of this software. License

MIT License — see LICENSE for details. Credits

Made by n1tr00

关于 About

tiktok web signature reverse engineer generates valid tiktok signatures for API requets
chachachacha20encryptionpythonreverse-engineeringsignaturtiktoktiktok-algotiktok-apitiktok-automation-scripttiktok-bot-2026tiktok-signingtiktok-web-appweb-scrapingx-bogusx-dynosaurx-gnarly

语言 Languages

Python100.0%

提交活跃度 Commit Activity

代码提交热力图
过去 52 周的开发活跃度
7
Total Commits
峰值: 7次/周
Less
More

核心贡献者 Contributors