Advanced TLS Forwarder Plugin for OB2

I’m releasing an advanced TLS Forwarder plugin for OB2 designed for controlled testing, debugging, and development environments.

This plugin allows you to forward HTTP requests through a local forwarding service while giving fine-grained control over transport behavior, protocol handling, and request customization.

It is intended for:

  • API integration testing
  • QA environments
  • Debugging complex HTTP/TLS interactions
  • Testing proxy configurations
  • Controlled lab environments

:white_check_mark: TLS Client Profile Selection

Choose specific TLS client identifiers or use randomized profiles for testing compatibility scenarios.

:white_check_mark: HTTP/2 Configuration

Optional HTTP/2 settings configuration for advanced transport testing.

:white_check_mark: Full Proxy Support

  • Static proxy
  • Rotating proxy
  • Auth proxy formats supported

:white_check_mark: Transport Controls

  • Force HTTP/1
  • Disable HTTP/3
  • Toggle keep-alives
  • Custom timeout control
  • Optional TLS extension randomization (for compatibility testing)

:white_check_mark: Advanced Header Handling

  • Custom headers
  • Default headers
  • CONNECT headers
  • Optional header normalization control

:white_check_mark: Cookie Handling

  • Automatic Set-Cookie parsing
  • Cookies stored in OB2’s cookie jar
  • Visible cookie logging section

How It Works

The plugin builds a structured JSON payload containing the request details (URL, method, headers, body, proxy, and transport options) and sends it to a local forwarder service.

The forwarder executes the request and returns the response data (status, body, headers, protocol). The plugin then updates OB2’s response fields, handles cookies automatically, and logs the full request/response for visibility.

Plugin :
TlsForwarder.rar (13.7 KB)

Tls Used : https://github.com/bogdanfinn/tls-client-api

Example : Screenshot 2026 02 22 211118 hosted at ImgBB — ImgBB

6 Likes

hi bro! can you send your tg for contacting?

@Mrx001_3 here you go

Just FYI, the new version of OB2 on staging has curl-impersonate as a selectable HTTP lib, which spoofs the ja3 fingerprint of browsers / mobile clients :wink: feel free to try it out

1 Like

Nice, I’ll definitely test it.

Of course, That’s the moment :wink: