Skip to main content

Device fingerprint

The browser collector gathers device components and submits them to POST /v1/fp/collect. The server resolves the device identity and returns fp_id; the client never decides it.

  1. Add the collector bundle to your page (Defraudo provides the versioned URL and its SRI integrity value):

    <script src="<collector-url>/fingerprint.global.js" integrity="sha384-..." crossorigin="anonymous"></script>
  2. Allow your page origin for the project (dashboard, project settings, allowed origins). The publishable key must belong to the same project as the secret key that sends events (a sandbox event needs a sandbox collect key); otherwise the device is not found at scoring.

  3. Call the collector with a publishable key. The bundle exposes a global AntiFrodFP:

    const config = {
    url: 'https://api-test.defraudo.com/v1/fp/collect',
    apiKey: 'pk_live_xxxxxxxxxxxxxxxxxxxxxx',
    // externalAccountId is ignored with a publishable key; accounts are linked by the event (step 4)
    };

    AntiFrodFP.prewarm(); // on page load: starts the heavy collection early
    const response = await AntiFrodFP.submitFast(config); // at the user's action
    const { data } = await response.json(); // data.fp_id
    AntiFrodFP.submitFull(config); // optional: fire-and-forget full stage
  4. Send fp_id to your backend and put it in the event with external_account_id, using your secret key; this is what links the account to the device:

    { "event_id": "...", "event_type": "login", "context": { "fp_id": "<data.fp_id>" } }

Staged submissions with the same session_id reuse one fp_id while the session is active (600 s after the last collect). A provisional id created from too little data is replaced by the next stage that has enough; both ids keep working for scoring. The collector can also request browser location on the full stage if you pass a location option; it is off by default. The bundle stays under 30 KB gzip.