| CURLOPT_ECH(3) | Introduction to Library Functions | CURLOPT_ECH(3) |
CURLOPT_ECH - configuration for Encrypted Client Hello
#include <curl/curl.h> CURLcode curl_easy_setopt(CURL *handle, CURLOPT_ECH, char *config);
This feature is experimental and may change before it is considered stable. We advise against using it in production.
ECH is only compatible with TLSv1.3.
Pass a string that specifies configuration details for ECH. In all cases, if ECH is attempted, it may fail for various reasons. The keywords supported are:
The application does not have to keep the string around after setting this option.
Using this option multiple times makes the last set string override the previous ones. Set it to NULL or "false" to disable its use again.
NULL, meaning ECH is disabled.
This functionality affects all TLS based protocols: HTTPS, FTPS, IMAPS, POP3S, SMTPS etc. only
This option works only with the following TLS backends: OpenSSL, Rustls and wolfSSL
int main(void)
{
CURL *curl = curl_easy_init();
static const char *config =
"ecl:AED+DQA87wAgACB/RuzUCsW3uBbSFI7mzD63TUXpI8sGDTnFTbFCDpa+"
"CAAEAAEAAQANY292ZXIuZGVmby5pZQAA";
if(curl) {
CURLcode result;
curl_easy_setopt(curl, CURLOPT_ECH, config);
result = curl_easy_perform(curl);
curl_easy_cleanup(curl);
}
}
Added in curl 8.8.0
curl_easy_setopt(3) returns a CURLcode indicating success or error.
CURLE_OK (0) means everything was OK, non-zero means an error occurred, see libcurl-errors(3).
| 2026-09-07 | libcurl |