Smart Signals
Next-level insights for
advanced fraud defense.
Built by our world-class research team, Smart Signals are 20+ bleeding-edge risk indicators to empower smarter, faster fraud decisions.
Recognize malicious activity.
Sharpen risk assessment. Stay ahead of sophisticated threats.
Block high-risk visitors instantly.
Act faster on clear red flags like tampering or spoofing.
Strengthen your fraud engine.
Easily integrate via API. Add more breadth and depth to risk models.
Get AI-driven recommendations.
See a single, actionable Suspect Score based on your unique data.
A more complete layer of device intelligence for your fraud stack
Velocity Signals
Correlate and identify important visitor data points at three distinct time-based intervals.
{
"distinct_ip": {
"5_minutes": 1,
"1_hour": 1,
"24_hours": 1
},
"distinct_country": {
"5_minutes": 1,
"1_hour": 2,
"24_hours": 2
},
"events": {
"5_minutes": 1,
"1_hour": 5,
"24_hours": 5
}
} High-Activity Device
Flag devices with unusually high activity levels in the past 24 hours.
{
"high_activity_device": true
} IP Geolocation
Accurately determine the location of the actual IP address.
{
"address": "94.142.239.124",
"geolocation": {
"accuracy_radius": 20,
"latitude": 50.05,
"longitude": 14.4,
"postal_code": "150 00",
"timezone": "Europe/Prague",
"city_name": "Prague",
"country_code": "CZ",
"country_name": "Czechia",
"continent_code": "EU",
"continent_name": "Europe"
},
"asn": "7922",
"asn_name": "COMCAST-7922",
"datacenter_result": true
} VPN
Determine if a user is using a VPN
{
"vpn": true,
"vpn_confidence": "high",
"vpn_ml_score": 0.895,
"vpn_origin_timezone": "Europe/Berlin",
"vpn_origin_country": "DE",
"vpn_methods": {
"timezone_mismatch": true,
"public_vpn": true,
"auxiliary_mobile": false,
"os_mismatch": false,
"relay": false,
"ml_prediction": true
}
} Proxy
Detect if an IP address is being used by a residential or data center proxy provider.
{
"proxy": true,
"proxy_confidence": "high",
"proxy_ml_score": 0.821,
"proxy_details": {
"proxy_type": "residential",
"last_seen_at": 1708102555327,
"provider": "BrightData"
}
} IP Blocklist
Detect when an IP matches a known database of malicious actors or spammers.
{
"email_spam": true,
"attack_source": true,
"tor_node": false
} Anti-Detect Browser
Detect requests originating from anti-detect browsers designed to spoof browser identity and evade fingerprinting.
{
"tampering": true,
"tampering_confidence": "high",
"tampering_ml_score": 0.8712,
"tampering_details": {
"anomaly_score": 0.8955,
"anti_detect_browser": true
}
} Incognito
Detect if a visitor is browsing in incognito or private mode.
{
"incognito": true
} Tampering
Identify browser spoofing incidents and suspicious browser signature anomalies.
{
"tampering": true,
"tampering_confidence": "high",
"tampering_ml_score": 0.8712,
"tampering_details": {
"anomaly_score": 0.8955,
"anti_detect_browser": true
}
} Privacy-Focused
Indicates if a request is initiated from a privacy-focused browser (e.g. Tor) or from a browser with anti-fingerprinting settings enabled.
{
"privacy_settings": true
} Virtual Machine
Identify if a request is coming from a virtual machine.
{
"virtual_machine": true,
"virtual_machine_ml_score": 0.812
} Dev Tools
Flags developer tools, debug modes, or debugging sessions on browsers and devices.
{
"developer_tools": true
} Rare Device
Flag devices with unusually rare hardware and browser configurations based on global traffic patterns.
{
"rare_device": true,
"rare_device_percentile_bucket": "p99.9+"
} Raw Device
Receive additional device data including 35 raw browser and device id attributes.
{
"platform": "MacIntel",
"screen_resolution": [
1920,
1080
],
"color_depth": 24,
"timezone": "America/Sao_Paulo",
"hardware_concurrency": 10,
"device_memory": 8,
"languages": [
"en-US"
],
"cookies_enabled": true,
"local_storage": true,
"session_storage": true,
"indexed_db": true
} Proximity Detection
Assign devices to a coarse geographic zone to detect co-location patterns and devices within the same physical area.
{
"proximity": {
"id": "w1aTfd4MCvl",
"precision_radius": 10,
"confidence": 0.95
}
} VPN Mobile
Determine if a user is leveraging a VPN on a mobile device.
{
"vpn": true,
"vpn_confidence": "high",
"vpn_ml_score": 0.895,
"vpn_origin_timezone": "Europe/Berlin",
"vpn_origin_country": "DE",
"vpn_methods": {
"timezone_mismatch": true,
"public_vpn": true,
"auxiliary_mobile": false,
"os_mismatch": false,
"relay": false,
"ml_prediction": true
}
} Browser Bot
Identify automated tools, friendly search bots, and other sophisticated threats in real time.
{
"bot": "bad",
"bot_type": "selenium"
} AI Agent
Detect requests originating from AI agents and assistants within your application.
{
"bot": "good",
"bot_type": "ai_agent",
"bot_info": {
"category": "ai_agent",
"provider": "OpenAI",
"name": "ChatGPT Agent",
"identity": "signed",
"confidence": "high"
}
} Android Emulator
Prevent spam and protect against nefarious Android emulator farms by ensuring the request is coming from a physical device. (Android only)
{
"emulator": true
} Active Call
Detects an in-progress cellular or internet call at the moment of identification.
{
"active_call": true
} Tampered Request
Detect when device properties have been modified to spoof a new visitor ID or bypass Smart Signals.
{
"tampering": true,
"tampering_details": {
"anomaly_score": 0.8955
}
} iOS Simulator
Detects when a visitor is using an iOS simulator rather than a real iPhone or iPad. (iOS only)
{
"simulator": true
} MitM Attack
Spots if requests made to Fingerprint were intercepted or altered.
{
"mitm_attack": true
} Rooted Device
Ensure a safe Android mobile application environment by detecting rooted devices. (Android only)
{
"root_apps": true
} Jailbroken Device
Detect if a visitor is using a jailbroken iPhone or iPad. (iOS only)
{
"jailbroken": true
} Cloned App
Identify requests originating from cloned applications on the same device. (Android only)
{
"cloned_app": true
} Frida
Indicates if the open source tool Frida has been used to tamper with the app.
{
"frida": true
} Factory Reset
Indicates the exact time a device was last reset to factory settings.
{
"factory_reset_timestamp": 1689756000
} Geo Spoofing
Indicates if the user has spoofed the location of their mobile device.
{
"location_spoofing": true
} Automation
Know when a session is driven by software (agents, scripts, bots) instead of a person. Catch credential stuffing, scraping, scalping, card testing, and automated signups before they reach your users.
Device & app trust
Know if a user's device is genuine, or an environment built to look like one. Spot the simulated, modified, and actively probed environments behind fake account farms, promo abuse, and multi-accounting.
Tampering & spoofing
Catch visitors who alter or spoof the data that identifies their device. Tampering is not accidental and indicates deliberate evasion, such as circumventing account limits, bans, and promo rules.
Anonymity & privacy
Detect when a user is obscuring their network origin or limiting what their browser reveals. Privacy tooling is widely used, so this works best as context for repeat signups, promo abuse, and account takeover.
Geolocation
Check whether a visitor is where they claim to be, and when devices are clustered in the same physical area. Detect delivery and gig-work fraud and device farms operating from a single location.
Reputation
Detect visitors whose history and device configuration stand out from your normal traffic. Points to multi-accounting, account takeover, and traffic from IPs tied to spam and network attacks.
Waiting for live Fingerprint event…
A more complete layer of device intelligence for your fraud stack
Adaptive. Trainable. Fully customizable. Suspect Score is a dynamic risk scoring system that helps you catch and contain fraud faster.
Browser Bot Detection
Identify automated tools, friendly search bots, and other sophisticated threats in real time.
AI Agent Detection
Detect requests originating from AI agents and assistants within your application.
High-Activity Device
Flag devices with unusually high activity levels in the past 24 hours.
Android Emulator Detection
Prevent spam and protect against nefarious Android emulator farms by ensuring the request is coming from a physical device. (Android only)
Active Call
Detects an in-progress cellular or internet call at the moment of identification.
iOS Simulator Detection
Detects when a visitor is using an iOS simulator rather than a real iPhone or iPad. (iOS only)
Virtual Machine Detection
Identify if a request is coming from a virtual machine.
Jailbroken Device Detection
Detect if a visitor is using a jailbroken iPhone or iPad. (iOS only)
Rooted Device Detection
Ensure a safe Android mobile application environment by detecting rooted devices. (Android only)
Frida Detection
Indicates if the open source tool Frida has been used to tamper with the app.
Developer Tools Detection
Flags developer tools, debug modes, or debugging sessions on browsers and devices.
Cloned App Detection
Identify requests originating from cloned applications on the same device. (Android only)
Factory Reset Detection
Indicates the exact time a device was last reset to factory settings.
Raw Device Attributes
Receive additional device data including 35 raw browser and device id attributes.
Browser Tamper Detection
Identify browser spoofing incidents and suspicious browser signature anomalies.
Anti-Detect Browser Detection
Detect requests originating from anti-detect browsers designed to spoof browser identity and evade fingerprinting.
Tampered Request Detection
Detect when device properties have been modified to spoof a new visitor ID or bypass Smart Signals.
Man-in-the-Middle Attack Detection
Detect if requests made to Fingerprint were intercepted or altered.
VPN Detection
Determine if a user is using a VPN
VPN Detection (mobile)
Determine if a user is leveraging a VPN on a mobile device.
Proxy Detection
Detect if an IP address is being used by a residential or data center proxy provider.
Incognito Detection
Detect if a visitor is browsing in incognito or private mode.
Privacy-Focused Browser
Indicates if a request is initiated from a privacy-focused browser (e.g. Tor) or from a browser with anti-fingerprinting settings enabled.
IP Geolocation
Accurately determine the location of the actual IP address.
Geolocation Spoofing Detection
Indicates if the user has spoofed the location of their mobile device.
Proximity Detection
Assign devices to a coarse geographic zone to detect co-location patterns and devices within the same physical area.
Velocity Signals
Correlate and identify important visitor data points at three distinct time-based intervals.
Rare Device Detection
Flag devices with unusually rare hardware and browser configurations based on global traffic patterns.
IP Blocklist Matching
Detect when an IP matches a known database of malicious actors or spammers.
AI-powered fraud recommendations
Adaptive. Trainable. Fully customizable. Suspect Score is a dynamic risk scoring system that helps you catch and contain fraud faster.
Import your fraud data
CSV file
Why Fingerprint_
Built for today's most pressing fraud challenges
Payment fraud
Stop fraudulent orders and transactions.
New Account Fraud
Prevent fake signups and automated fraud.
Account takeover
Build secure and friction-free login experiences.
Why Fingerprint_
Built for today's most pressing fraud challenges
async function placeOrder(req, res) {
const { eventId, orderDetails } = req.body;
const event = await client.getEvent(eventId);
const isBadBot = event.bot === 'bad';
const suspectScore = event.suspect_score;
const ipVelocity = event.velocity?.distinct_ip?.['1_hour'];
if (isBadBot || suspectScore > 20 || ipVelocity > 3) {
return res.status(403).json({ error: 'Order flagged for review' });
}
await processOrder(orderDetails);
res.json({ status: 'confirmed' });
} Frequently
Asked Questions
Identify web, mobile,
and agentic traffic in minutes
Collect visitor IDs and signals instantly for free,
or reach out to our team for a custom demo.
250+
7 Billion +
80 Million +