Skip to main content

Device signals (v1)

Stable / GA

This is the current stable version of this step type. Device signals (v2) (DEVICE_SIGNALS:v2) is available in preview.

Evaluates the trustworthiness of the customer’s device​

Helps determine whether the device appears safe, familiar, and genuine or if there are signs of unusual activity, automation, or manipulation.


Key features​

  • Integrates device signals services (e.g., Fingerprint) to assess device risk and detect fraud attempts.
  • Analyses automation, environment manipulation, VMs/emulators, and behavioral anomalies.
  • Configurable risk thresholds via suspiciousUserThreshold, notTrustedUserThreshold, and confidenceScoreThreshold.
  • Output mapping based on suspectScore and confidence.score thresholds.

Configuration​

OptionTypeRequiredDescription
providerstringNoThe device signals provider to use. Only FINGERPRINT is supported for this step. Accepted values: FINGERPRINT.
suspiciousUserThresholdintegerYesDefines the threshold at which a user is considered suspicious based on suspectScore.
notTrustedUserThresholdintegerYesDefines the threshold at which a user is considered not_trusted based on suspectScore.
confidenceScoreThresholdintegerYesSets the minimum fingerprint confidence score (0–100) below which the result is deemed inconclusive.

Example configuration​

{
"provider": "fingerprint",
"suspiciousUserThreshold": 75,
"notTrustedUserThreshold": 50,
"confidenceScoreThreshold": 60
}

Input data blocks​

This step does not consume any input data blocks.


Routes​

RouteDescription
trustedThe device is considered trustworthy as the suspect score is below the defined suspicious threshold.
suspiciousThe device is flagged as suspicious because the suspect score has exceeded the suspicious threshold.
not_trustedThe device is deemed not trusted as the suspect score has surpassed the high-risk (not trusted) threshold.
inconclusiveA route could not be determined because the confidence score was below the required threshold.

Output data blocks​

RouteData blocks produced
trustedDeviceSignals
suspiciousDeviceSignals
not_trustedDeviceSignals
inconclusiveDeviceSignals

Output mapping​

ResultMapped Output
confidence.score < confidenceScoreThresholdinconclusive
suspectScore < suspiciousUserThresholdtrusted
suspectScore >= suspiciousUserThreshold and suspectScore < notTrustedUserThresholdsuspicious
suspectScore >= notTrustedUserThresholdnot_trusted
info

The confidence score from the provider is normalized to a 0-100 scale before comparison with confidenceScoreThreshold.

Example payloads​

DeviceSignals — trusted
{
"userReference": "usr-8f3a1c2d",
"requestId": "req-4b7e9f01-dc23-4a11-b8f6-3e5d2c1a0b99",
"provider": "fingerprint",
"timestamp": "2026-02-10T14:00:01.000Z",
"result": "trusted",
"browser": {
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36",
"incognito": false,
"name": "Chrome",
"version": "124.0.0.0",
"os": "Mac OS X",
"deviceType": "desktop"
},
"network": {
"ip": "82.64.123.45",
"location": {
"country": "FR",
"city": "Paris",
"latitude": 48.8566,
"longitude": 2.3522
},
"timezone": "Europe/Paris"
},
"signals": {
"visitorId": "Rp7k3mN2xQwL9dVc",
"confidence": {
"score": 0.98
},
"suspectScore": 5,
"incognito": false,
"bot": {
"result": "notDetected"
},
"vpn": {
"result": "notDetected"
},
"tampering": {
"result": false
}
}
}