The account is new.The machine is on file.
A fake account changes the email, the card, the window and the exit country. One verify call returns a device id that none of it moves, and the sightings behind it.
Five accounts arrived on one machine
Each attempt cleared something the browser holds, and none of it reaches the machine the id is computed from.
3c9d41e0b7a8f512
What this project has already seen of the browser reading this
identity.returningidentity.degradedidentity.linked_devicesDecide on the machine the account arrives on
The first two rungs read the response, the last two read the accounts you have already bound to that id.
- 01Allow
identity.returning === falseA first visit, with nothing on file against the machine.
- 02Bind
identity.returning === trueSeen before, which on its own is a customer coming back.
- 03Review
accountsForDevice(id) >= 3Three accounts behind one machine, which a shared household can explain.
- 04Block
bannedDevices.has(id)A machine you have already ruled on.
Add the script, read the id on your server
import { useTrustSig } from "@trustsig/react";
const { getResponse } = useTrustSig();
const { token } = await getResponse();import { TrustSig, hasReasonGroup } from '@trustsig/server';
const ts = new TrustSig({ secretKey: process.env.TRUSTSIG_SECRET_KEY });
app.post('/signup', async (req, res) => {
const token = req.headers['x-trustsig-response'];
const result = await ts.verifyRemote(token);
// is_bot is true once the session crossed the block threshold.
if (result.is_bot) {
return res.status(403).json({ error: 'Access denied.' });
}
if (await bannedDevices.has(result.identity.device_id)) {
return res.status(403).json({ error: 'Access denied.' });
}
// Your table, keyed on the device id. TrustSig supplies the key and the
// sighting counts; how many accounts sit behind one machine is yours.
const prior = await accountsForDevice(result.identity.device_id);
if (prior.length >= 3 || hasReasonGroup(result, 'velocity')) {
return queueForReview(req, res, {
device_id: result.identity.device_id,
accounts: prior.length,
});
}
return completeSignup(req, res, {
device_id: result.identity.device_id,
trial: prior.length === 0 ? 'full' : 'none',
});
});What the id does not claim
- A device id is not a person
identity.device_id - A household laptop, a shared desk, a library machine. One id, several people behind it.
- Some ids name a crowd
identity.degraded - A locked-down browser withholds enough of the surface that its fingerprint belongs to a cohort, and the response says so.
- A fresh machine is a fresh id
identity.linked_devices - A second laptop defeats it, and the next account costs the hardware rather than another inbox.
- Sightings count requests, not signups
velocity.device - An ordinary customer reading your pricing page produces a dozen in one session, so the number measures traffic.
Repeat signups, answered
The scan runs on the signup form before the account exists, and the verify call returns identity.device_id with first_seen, last_seen and sightings. A repeat signup on a new email address arrives on an id you have already counted.
Yes. identity.device_id is computed from what the machine renders and reports, so there is nothing on the device to clear. A private window is reported separately as device.incognito: it changes what the page can store, not what the hardware draws.
Yes, and identity.degraded tells you how far the ban reaches: it marks an id whose fingerprint a large cohort shares. A library desktop, a household laptop and a hot desk all read as one id.
No. The reading happens in the page, so the id is the same whichever exit the request arrives from. The network block carries connection_type, vpn, tor and datacenter separately, so one machine signing up from four countries still reads as one machine.
Nothing. A different machine produces a different identity.device_id. identity.linked_devices reports when the graph has already resolved more than one id to one machine, and naming the person behind both is TrustSig Pro.
No. The id comes from the token alone, and nothing you collect in the form is sent to TrustSig. The id is scoped to your project, so it cannot be joined against another site, and the privacy note has the rest.
No. velocity.device counts how often your project has seen the machine, which tracks requests rather than accounts.
Put the id behind your own gate.
Your signup handler gets the identity block on the request it already answers.