tikTok Web Signature Generator
Fully reverse-engineered TikTok Web API signature generator. Produces valid X-Gnarly, X-Bogus, and X-Dynosaur signatures that TikTok accepts with success responses.
Confirmed working — TikTok returns status_code: 0 (success) when requests are signed with these generators.
Need more than signatures? Profiles, followers, videos, comments, live chat and search through one REST API:
Unofficial TikTok API - dev.omar-thing.site
Reverse-Engineered Algorithm
This project contains a complete reverse engineering of TikTok's web signature algorithm (SDK version 5.3.2, build 1.0.0.417).
The algorithm was recovered through:
Deobfuscation of the production webmssdk.js bundle
Static analysis of the ChaCha-based cipher implementation
Dynamic tracing of signature generation at runtime
Byte-level reconstruction of the payload serialization format
Verification against live TikTok API responses
Result: Signatures generated by this library are accepted by TikTok's servers and return success responses (status_code: 0). Features
Generate X-Dynosaur signatures with ChaCha20 encryption and FNV-1a hashing
Generate X-Gnarly signatures with ChaCha20 encryption, MD5 digests and PRNG shuffle
Generate X-Bogus placeholder (legacy compatibility)
Support for SDK version 5.3.2 (build 1.0.0.417)
Custom Base64 alphabet encoding
Pure Python implementation
Lightweight and production-ready
No external API calls — everything computed offline
Deterministic with fixed inputs
Produces valid signatures that TikTok accepts
Installation bash
git clone https://github.com/n1tr00-10/tiktok-web-signature.git cd tiktok-web-signature
No dependencies beyond the Python standard library. Versions Component Version SDK 5.3.2 SCM Version 1.0.0.417 SCM Sub Version 1.0.0.2858 Release Build 1.0.0.417 Slardar SDK 1.16.6 Files text
tiktok-web-signature/ ├── x_dynosaur.py # X-Dynosaur generator ├── x_gnarly.py # X-Gnarly generator ├── x_bogus.py # X-Bogus placeholder (legacy) └── README.md
Usage X-Dynosaur python
from x_dynosaur import get_x_dynosaur
query = "aid=1988&app_name=tiktok_web&device_platform=web_pc" user_agent = "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" body = ""
token = get_x_dynosaur(query, user_agent, body) print(token)
X-Gnarly python
from x_gnarly import get_x_gnarly
query = "aid=1988&app_name=tiktok_web&device_platform=web_pc" user_agent = "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" body = ""
token = get_x_gnarly(query, user_agent=user_agent, body=body) print(token)
Full request with signatures python
import requests from x_dynosaur import get_x_dynosaur from x_gnarly import get_x_gnarly
query = "aid=1988&app_name=tiktok_web&device_platform=web_pc" ua = "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" body = ""
dynosaur = get_x_dynosaur(query, ua, body) gnarly = get_x_gnarly(query, dynosaur, "", ua, body)
headers = { "User-Agent": ua, "X-Dynosaur": dynosaur, "X-Gnarly": gnarly, }
resp = requests.get(f"https://www.tiktok.com/api/...?{query}", headers=headers) print(resp.json()) # TikTok returns success with valid signatures
Optional parameters Parameter Default Description timestamp int(time.time()) Unix timestamp f8 session value 32-bit session field canvas 2316120563 Canvas fingerprint value envcode 65 Environment code version "5.3.2" SDK version scm_version "1.0.0.417" SCM version security_flag 0 Security flag flag_32 0 32-bit flag flag_125 0 125-bit flag url / referer "www.tiktok.com/" Page URL proof_result "0" Proof-of-work result key_words random Custom ChaCha key (12 words) How it works
Both signatures use the same ChaCha-based cipher with:
4 constants: [1196819126, 600974999, 3863347763, 1451689750]
12 key words: derived from a PRNG
Round count: (sum(key) & 0x0f) + 5
Insert position: (sum(key_bytes) + sum(cipher)) % (len(cipher) + 1)
X-Dynosaur payload
56 fields (tags 0x20 – 0x38) containing:
timestamp, session value, canvas, envcode
FNV-1a hashes of query, body, user-agent
version strings
checksum field (0x20)
X-Gnarly payload
16 fields (indexes 0 – 16) containing:
MD5 digests of query, body, user-agent
timestamp, session value, canvas
version strings
XOR checksum fields
Fields are shuffled using a PRNG seeded from f8 before serialization. Custom Base64 alphabet text
u09tbS3UvgDEe6r-ZVMXzLpsAohTn7mdINQlW412GqBjfYiyk8JORCF5/xKHwacP=
Verification
Signatures have been verified against live TikTok API endpoints. With valid X-Dynosaur and X-Gnarly headers, TikTok returns: json
{"maigc":538051346,"version":1,"dataType":8} Updated token from response: ZKayKXtxB3G8lNt8L8ANOXxIgMRvPSnXFDYM2ocnU8cT5Ojn0UtXjJrO-kIqPSwfnsJx1VcdZkCEg9BZCXiLFL4Mz9BNMCcmIt0-evhDA4QwRnyfSNhKzT4mkdViClma2eBZblxz Token Validation HTTP 200 API Response: {'status_code': 0} Validation Result: {'valid': True, 'status': 0} fresh activated msToken ZKayKXtxB3G8lNt8L8ANOXxIgMRvPSnXFDYM2ocnU8cT5Ojn0UtXjJrO-kIqPSwfnsJx1VcdZkCEg9BZCXiLFL4Mz9BNMCcmIt0-evhDA4QwRnyfSNhKzT4mkdViClma2eBZblxz
This confirms the reverse-engineered algorithm is correct and the signatures are accepted by TikTok's servers. Token length
Token length is not fixed. It varies between 230–420 characters depending on:
Payload content
Field values (timestamp, canvas, envcode, etc.)
PRNG randomness
Base64 padding
This is normal and expected. FAQ
Do I need a session ID? No. Signatures are generated locally and do not require authentication.
Do these signatures expire? Yes. TikTok validates the timestamp embedded in the signature. Generate fresh signatures for each request.
Why is my token a different length than someone else's? The payload contains variable-length fields (hashes, timestamps, version strings). Different inputs produce different output lengths.
Which version does this support? SDK 5.3.2, build 1.0.0.417.
Are the signatures actually valid? Yes. The algorithm has been fully reverse-engineered and verified against live TikTok API responses. TikTok accepts these signatures and returns success.
Can I use this for automation? Yes, but always respect TikTok's Terms of Service and rate limits. Changelog v1.0.0 — SDK 5.3.2
Complete reverse engineering of TikTok's web signature algorithm
X-Dynosaur generator (ChaCha20 + FNV-1a)
X-Gnarly generator (ChaCha20 + MD5 + PRNG shuffle)
X-Bogus placeholder
Custom Base64 alphabet encoding
Support for SDK version 5.3.2 (build 1.0.0.417)
Verified against live TikTok API — returns success responses
Disclaimer
This project is provided for educational and research purposes only. It is not affiliated with, endorsed by, or sponsored by TikTok or ByteDance.
Use responsibly and in accordance with TikTok's Terms of Service. The authors are not responsible for any misuse of this software. License
MIT License — see LICENSE for details. Credits
Made by n1tr00