Who Fingerprint is
Fingerprint is a device intelligence platform from the team behind FingerprintJS, the open-source browser fingerprinting library. It gives each browser and device a stable visitor ID, and adds Smart Signals such as bots, VPNs, tampered browsers and jailbroken iPhones, weighed into a single Suspect Score.
Fraud teams use it against fake accounts, account takeover, payment fraud and bots, and it ships SDKs for the web, iOS, Android, React Native and Flutter. That is why it is the device intelligence connector of our Fraud & risk module.
What it does in your platform
Fraud & risk
Recognises the device behind every sign-up, login and payment, and flags bots, VPNs and tampered or jailbroken devices. Its visitor ID and Suspect Score join the other signals in the module's decision, next to your own velocity limits.
How the connection works
Fingerprint's SDK runs in your apps, including our Flutter apps through Fingerprint's Flutter SDK. The app only gets a visitor ID; the full result, with Smart Signals, reaches the platform on the server side.
The device is identified
At sign-in, Fingerprint's SDK collects device signals and returns a visitor ID and an event ID to the app.
The platform gets the result
The module fetches the full event from Fingerprint's Server API in your region, or decrypts the sealed result the app passed on, so nothing can be altered on the device.
Signals are read
The module checks the visitor ID against the accounts it has seen on that device, and reads the Smart Signals and the Suspect Score.
The module decides
A device already tied to blocked accounts, or a high Suspect Score, raises the risk. The module merges it with your rules: allow, ask for a second factor, hold or block.
Every event is kept
A signed webhook also delivers each identification to the platform, so the device history stays in your records beyond Fingerprint's own retention.
Next to other providers
Fingerprint answers one question: which device is this. The module combines that with the scores of fraud engines such as Sardine, SEON, Sift or Feedzai, called in parallel, and with your own velocity limits and spending rules.
If Fingerprint is slow, the decision goes ahead on your own rules within a set timeout. Replacing it later does not change your apps, and past device history stays in your records.
When Fingerprint fits best
A strong fit when
- Fraudsters open many accounts from the same devices, to test stolen cards or abuse sign-up offers.
- Account takeover attempts come from devices your customers have never used.
- You want device signals you can read and act on yourself, next to a fraud engine's score.
Also worth a look
- Sardine or SEON, whose own SDKs collect device and behaviour data as part of their scoring.
- Your platform's own device binding, which already ties sessions to trusted devices.
How we get you live
The contract
We help you get your Fingerprint account and contract in place, with your workspace in the region your data should stay in: the US, the EU in Frankfurt or Asia in Mumbai.
The signals
We choose with you the Smart Signals and Suspect Score weights that matter for your risk, and how the module acts on them.
The keys
The secret API key, the encryption key for sealed results and the webhook signing key go into your platform's secrets and nowhere else. The apps only carry the public key.
A full test run
The whole flow runs in a separate Fingerprint environment for testing, from a new device to a held login, before your first real customer.
