Skip to main content

Device signals (v2)

Preview / Alpha

This version of this step type is in preview / alpha. The functionality and subsequently the documentation can still change.

Evaluates the trustworthiness of the customer’s device and produces structured device context and risk assessment data​

Collects device intelligence from the customer’s browser using FingerprintJS Pro and evaluates whether the device appears safe, familiar, and genuine or if there are signs of unusual activity, automation, or manipulation. The Step produces a DeviceContext data block with the collected device data and a DeviceRiskAssessment data block that drives route selection.


Key features​

  • Structured risk assessment: the verdict is exposed as a DeviceRiskAssessment data block containing the composite result, the confidence score (0–100), the visitor history, and vault references to the raw provider responses.
  • Device context output: a DeviceContext data block with browser, operating system, IP address, geolocation, and detection details is produced on every route, giving downstream Steps access to the collected device data.
  • Smart Signals: bot detection, browser tampering, virtual machines, developer tools, location spoofing, jailbroken devices, emulators, cloned apps, man-in-the-middle attacks, high-activity devices, proxies, VPNs, and Tor exit nodes are captured as per-IP or device-level detections.
  • Provider evidence: the full, raw FingerprintJS Server API response is stored in the vault and referenced from the assessment, so verdicts remain auditable.
  • Configurable risk thresholds: suspiciousUserThreshold, notTrustedUserThreshold, and confidenceScoreThreshold are all optional and fall back to sensible defaults.

Configuration​

OptionTypeRequiredDescription
providerstringNoDevice signals provider. Accepted values: FINGERPRINT.
suspiciousUserThresholdintegerNoSuspect score at or above which the device is routed to the suspicious route.
notTrustedUserThresholdintegerNoSuspect score at or above which the device is routed to the not_trusted route.
confidenceScoreThresholdintegerNoMinimum confidence score (0–100) below which the result is inconclusive.

Example configuration​

Thresholds omitted — defaults apply

{}

Custom thresholds

{
"provider": "FINGERPRINT",
"suspiciousUserThreshold": 75,
"notTrustedUserThreshold": 90,
"confidenceScoreThreshold": 60
}

Input data blocks​

This step does not consume any input data blocks.


Routes​

RouteDescription
trustedThe device is considered trustworthy as the suspect score is below the suspicious threshold.
suspiciousThe device is flagged as suspicious because the suspect score has reached the suspicious threshold.
not_trustedThe device is deemed not trusted as the suspect score has reached the high-risk (not trusted) threshold.
inconclusiveA verdict could not be determined because the confidence score was below the required threshold.

Output data blocks​

RouteData blocks produced
trustedDeviceContext, DeviceRiskAssessment
suspiciousDeviceContext, DeviceRiskAssessment
not_trustedDeviceContext, DeviceRiskAssessment
inconclusiveDeviceContext, DeviceRiskAssessment

Output mapping​

ResultRoute
confidenceScore < confidenceScoreThresholdinconclusive
suspectScore < suspiciousUserThresholdtrusted
suspectScore >= suspiciousUserThreshold and suspectScore < notTrustedUserThresholdsuspicious
suspectScore >= notTrustedUserThresholdnot_trusted
info

The confidence score returned by the provider (0–1) is converted to a 0–100 scale before comparison with confidenceScoreThreshold. The score stored in the DeviceRiskAssessment data block is on the same 0–100 scale.

info

Output data blocks are persisted to the vault automatically. The raw FingerprintJS Server API response is also stored in the vault as providerResult evidence and referenced from the DeviceRiskAssessment data block, so verdicts remain auditable.

Example payloads​

DeviceContext — desktop, no detections
{
"provider": "fingerprint",
"platform": "web",
"collectedAt": "2026-02-10T14:00:01.000Z",
"deviceId": "Rp7k3mN2xQwL9dVc",
"collectionId": "1770700801123.Qk7xPz",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36",
"browserName": "Chrome",
"browserVersion": "124.0.0.0",
"osName": "Mac OS X",
"osVersion": "10.15.7",
"deviceType": "desktop",
"deviceModel": null,
"deviceManufacturer": null,
"sdkVersion": null,
"appBundleId": null,
"timezone": "Europe/Berlin",
"language": null,
"ipAddresses": [
{
"version": "v4",
"address": "82.64.123.45",
"geolocation": {
"latitude": 48.8566,
"longitude": 2.3522,
"city": "Paris",
"country": "FR",
"timezone": "Europe/Paris"
},
"vpn": false,
"tor": false
}
],
"incognito": false,
"detections": {
"bot": false,
"tampering": false,
"virtualMachine": false,
"developerTools": null,
"locationSpoofing": null,
"jailbroken": null,
"emulator": false,
"clonedApp": null,
"mitmAttack": null,
"highActivityDevice": null,
"proxy": false
}
}
DeviceRiskAssessment — trusted
{
"provider": "fingerprint",
"timestamp": "2026-02-10T14:00:01.000Z",
"result": "trusted",
"confidenceScore": 98,
"visitorFound": true,
"firstSeenAt": 1704067200000,
"lastSeenAt": 1770732001000,
"evidence": [
{
"type": "providerResult",
"ref": {
"$ref": "vault",
"$id": "e8f1b2c3-4d5e-6f7a-8b9c-0d1e2f3a4b5c"
}
}
]
}
DeviceRiskAssessment — not_trusted
{
"provider": "fingerprint",
"timestamp": "2026-02-10T14:00:01.000Z",
"result": "not_trusted",
"confidenceScore": 91,
"visitorFound": true,
"firstSeenAt": 1704067200000,
"lastSeenAt": 1770732001000,
"evidence": [
{
"type": "providerResult",
"ref": {
"$ref": "vault",
"$id": "e8f1b2c3-4d5e-6f7a-8b9c-0d1e2f3a4b5c"
}
}
]
}