> ## Documentation Index
> Fetch the complete documentation index at: https://docs.safesquid.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Application Signatures

<Note>
  CLI man page: `safesquid-applicationSignatures(5)`
</Note>

The **Application Signatures** section (`safesquid-applicationSignatures(5)`) tags each HTTP request with application signature strings (for example Webmail, BitTorrent, Chrome). Other sections match those tags with exact string compare — especially [Access Profiles](/admin_guide/policies_and_profiles/access_profiles) (Request Types field) and [Request Types](/admin_guide/policies_and_profiles/request_types).

<Note>
  Vendor signature databases download on the appliance update schedule. See [startup.ini](/admin_guide/start_here/startup_ini) UPDATE settings, [Cloud / categorisation feeds](/admin_guide/start_here/cloud_feeds), and [Subscription](/admin_guide/infrastructure_and_access/subscription) (expired subscription skips all signature processing).
</Note>

## Core mechanics

### Processing order

1. If `SUBSCRIPTION_EXPIRED` is set, processing is skipped entirely for that connection.
2. Prior application-signature and request-type tags are cleared.
3. Built-in tags may be added: `IPV4 Host`, `IPV6 Host`, `Cross Site Request`.
4. **Application Signatures List** is walked top to bottom. **Every** enabled rule whose tests pass may add or remove tags — there is no first-match stop.
5. Tags from earlier rules in the same pass are visible to later rules via the **Application signatures** prerequisite field.
6. Final tags are copied to `request_types` and logged as application signatures.

### Global Enabled quirk

The section global **Enabled** switch is stored in configuration but request-time matching checks only each rule's own **Enabled** flag. Per-rule Enabled off skips that row; global off does not stop the signature loop by itself.

### Inner filter order (per row)

For each enabled row, filters run in fixed order; any failure skips to the next row:

1. **Application signatures** — prerequisite tags (exact / `!` match, same engine as Access Profiles).
2. **Method**, **Protocol** — exact; missing header when field set → skip row.
3. **Mime type** — regex on request `Content-Type`.
4. **Port range list**, post data size gates, **File**, host/referer regex fields, **User Agent**, **X-Forwarded-For**, **Request header pattern**.
5. On match: add **Added application signatures** and **category** tags; remove listed **Removed application signatures**.

<Warning>
  **Post data size:** when `Content-Length` is present, the rule is *skipped* when `content_length > minimum` or `content_length < maximum` (optional fields must be active). No Content-Length → min/max checks are not applied.
</Warning>

<Warning>
  **URL commands** are loaded from configuration but not evaluated — leave blank.
</Warning>

### Application Categories List

Category definition rows are saved to the local dev XML for UI autocomplete. Runtime category tags come from the **category** field on Application Signatures List rules, not from the Categories list alone.

## Examples

<Tip>
  ### Tag webmail from vendor rule

  Vendor database row matches host and User-Agent; adds `Webmail`.

  **Result:** Access Profiles matching Request Types or application signature `Webmail` apply webmail policy.
</Tip>

<Tip>
  ### Custom rule on top of vendor tags

  * Prerequisite `Webmail`, Host Name `mail\.partner\.com`
  * Added application signatures `Partner-Webmail`

  **Result:** only partner webmail gets the extra tag; generic webmail keeps `Webmail` only.
</Tip>

<Tip>
  ### Category tag for reporting

  On match, **category** `SocialMedia` is added to application signatures (same tag list).

  **Result:** policies and logs can match category name `SocialMedia` without a separate Categories list row.
</Tip>

## How to verify

1. Check **Reports → Modules Status** for application signature load/download state.
2. Reproduce a request; read Detailed logs column `application_signatures`.
3. Enable **Trace Entry** on a rule where available; confirm tags in Native PROFILE logs.
4. Debug header `X-SafeSquid-Application-Signatures` when Send Debugging Headers To includes CLIENT — see [Debug response headers](/admin_guide/start_here/debug_response_headers).

## See also

* [Request Types](/admin_guide/policies_and_profiles/request_types)
* [Access Profiles](/admin_guide/policies_and_profiles/access_profiles)
* [Subscription](/admin_guide/infrastructure_and_access/subscription)
* [Cloud / categorisation feeds](/admin_guide/start_here/cloud_feeds)
* [Logging and troubleshooting](/admin_guide/start_here/logging)

CLI: `man safesquid-applicationSignatures`


## Related topics

- [Application Signatures](/use_cases/profiling_engine/application_signatures.md)
- [Content Signatures](/admin_guide/policies_and_profiles/content_signatures.md)
- [Runtime Data and Signatures](/safesquid_swg/files_and_folders/runtime_data_and_signatures.md)
- [Allow Remote Applications to Particular Users](/use_cases/access_restriction/allow_remote_applications_to_particular_users.md)
- [Cloud / categorisation feeds](/admin_guide/start_here/cloud_feeds.md)
