# TRACIO — Device Intelligence & Fraud Prevention Platform > TRACIO (tracio.ai) identifies every website visitor with 99.5% accuracy (internal benchmarks) across 300+ device, browser, and network signals, detects bots and AI agents, and returns a real-time verdict — real, suspicious, or fake — enriched with 35+ server-computed smart signals. Business plans add per-scenario guidance (allow, challenge, review, or deny) for payment, registration, login, and affiliate flows. Client SDK is open source (MIT, github.com/Tracio-App/sdk); server integration is webhook-based, with a read-only Server API for lookups. ## Products - [Device Identification](https://tracio.ai/platform/identification): Produce persistent visitor IDs from 300+ browser signals at 99.5% accuracy. - [Bot Detection](https://tracio.ai/platform/bot-detection): Catch headless browsers, automation frameworks, AI agents, and advanced bots in real time. - [Smart Signals](https://tracio.ai/platform/smart-signals): 35+ server-computed enrichment signals for end-to-end threat assessment. - [IP Intelligence](https://tracio.ai/platform/ip-intelligence): VPN, proxy, and Tor detection paired with geolocation and velocity tracking. ## Use cases - [Payment Fraud Prevention](https://tracio.ai/use-cases/payment-fraud): Catch fraudulent transactions before they clear by recognizing returning fraudsters across sessions. - [Account Takeover Protection](https://tracio.ai/use-cases/account-takeover): Flag login attempts from unrecognized devices before attackers gain access. - [Account Sharing Detection](https://tracio.ai/use-cases/account-sharing): Pinpoint when multiple people share a single account across different hardware. - [Credential Stuffing Prevention](https://tracio.ai/use-cases/credential-stuffing): Shut down automated login attacks that test stolen credential databases against your endpoints. - [Coupon & Promo Abuse Prevention](https://tracio.ai/use-cases/promo-abuse): Prevent users from exploiting sign-up bonuses and referral programs through multi-accounting. - [Anti-Scraping Protection](https://tracio.ai/use-cases/web-scraping): Block web scrapers even when they use real browsers and mimic human navigation. - [Content & Paywall Protection](https://tracio.ai/use-cases/content-protection): Enforce metered paywalls and content limits even when visitors use incognito or clear cookies. - [Anonymous Personalization](https://tracio.ai/use-cases/personalization): Deliver personalized experiences to anonymous visitors — no login required. - [E-Commerce](https://tracio.ai/use-cases/ecommerce): Eliminate chargebacks, shut down promo abuse, and lock down accounts with persistent device tracking across your entire purchase funnel. - [FinTech & Banking](https://tracio.ai/use-cases/fintech): Block account takeover with device binding, catch synthetic identities at onboarding with Smart Signals, and satisfy compliance requirements with risk assessment. - [Gaming & iGaming](https://tracio.ai/use-cases/gaming): Destroy multi-accounting with persistent device IDs, dismantle bot farms with automation detection, and enforce geo-compliance. - [SaaS Platforms](https://tracio.ai/use-cases/saas): End free trial abuse with device tracking, detect license sharing with seat counting, and block credential stuffing — without user friction. - [Media & Streaming](https://tracio.ai/use-cases/media): Enforce subscription limits with device counting, block paywall bypass, eliminate ad fraud with bot filtering, and protect content. - [Travel & Hospitality](https://tracio.ai/use-cases/travel): Intercept fraudulent bookings with checkout verification, protect loyalty programs with device clustering, and defend pricing APIs. ## Learn (educational guides) - [What is device intelligence?](https://tracio.ai/learn/what-is-device-intelligence): Device intelligence identifies and risk-scores the devices behind every request using browser, network, and behavioral signals. Learn how it works, its signals, and how to deploy it. - [What is device fingerprinting?](https://tracio.ai/learn/what-is-device-fingerprinting): Device fingerprinting identifies a browser or device from its attributes — canvas, fonts, WebGL, and more — without cookies. Learn how it works, which signals matter, and where it's used. - [What is bot detection?](https://tracio.ai/learn/what-is-bot-detection): Bot detection identifies automated, non-human traffic — headless browsers, scripts, and AI agents — using device, network, and behavioral signals. Learn how it works and how to deploy it. - [What is account takeover (ATO)?](https://tracio.ai/learn/what-is-account-takeover): Account takeover (ATO) is when an attacker gains unauthorized access to a legitimate user's account. Learn how ATO attacks work, warning signs, and how device intelligence stops them. - [What is credential stuffing?](https://tracio.ai/learn/what-is-credential-stuffing): Credential stuffing is an automated attack that tests stolen username-password pairs against login pages at scale. Learn how it works, why it succeeds, and how to defend against it. - [What is fraud scoring?](https://tracio.ai/learn/what-is-fraud-scoring): Fraud scoring assigns a risk value to a user, action, or transaction so systems can allow, challenge, or block it. Learn how fraud scores are built, what signals feed them, and how to use them. - [What is IP intelligence?](https://tracio.ai/learn/what-is-ip-intelligence): IP intelligence enriches an IP address with reputation, geolocation, and network context — detecting VPNs, proxies, and datacenters. Learn how it works and where it fits in fraud prevention. ## Glossary - [Glossary index](https://tracio.ai/glossary): 73 fraud-prevention and device-intelligence terms, each with definition, mechanics, and FAQ ## Comparisons & alternatives - [tracio.ai vs FingerprintJS Pro](https://tracio.ai/compare/vs-fingerprintjs): The open-source, auditable device intelligence engine — a closer, more transparent alternative to FingerprintJS Pro, with an MIT-licensed client and EU data residency. - [tracio.ai vs Castle](https://tracio.ai/compare/vs-castle): Deep device intelligence and a persistent visitor ID you can build on — a complement or alternative to Castle's account-security focus. - [tracio.ai vs SEON](https://tracio.ai/compare/vs-seon): Deeper, privacy-first device fingerprinting than SEON's device layer — while SEON leads on email and phone enrichment. - [tracio.ai vs reCAPTCHA](https://tracio.ai/compare/vs-recaptcha): Silent device identification with a persistent visitor ID and granular signals — a privacy-first complement to reCAPTCHA's challenge-and-score model, with no data sent to Google. - [tracio.ai vs DataDome](https://tracio.ai/compare/vs-datadome): A persistent visitor identity and granular device signals you can build on — where DataDome focuses on managed, edge-layer bot mitigation. - [tracio.ai vs Kasada](https://tracio.ai/compare/vs-kasada): Persistent visitor identity and raw device signals via API — a decision layer you control, versus Kasada's inline bot mitigation that blocks automation at the edge. - [tracio.ai vs IPQualityScore](https://tracio.ai/compare/vs-ipqualityscore): Deeper browser-signal fingerprinting versus IPQualityScore's broad, IP-centric bundle of fraud checks. - [tracio.ai vs Arkose Labs](https://tracio.ai/compare/vs-arkose-labs): A silent, persistent device identity you can build on — where Arkose Labs raises attacker cost with risk-based interactive challenges. - [Top FingerprintJS Alternatives in 2026](https://tracio.ai/alternatives/fingerprintjs-alternatives): The best FingerprintJS alternatives in 2026, compared honestly. Tracio, SEON, Castle, DataDome and more — strengths, trade-offs, pricing, and open-source options. - [Top Castle Alternatives in 2026](https://tracio.ai/alternatives/castle-alternatives): The best Castle alternatives in 2026, compared honestly. Tracio, FingerprintJS, SEON, Arkose and more — strengths, trade-offs, and which fits account takeover, bots, or device intelligence. - [Top SEON Alternatives in 2026](https://tracio.ai/alternatives/seon-alternatives): The best SEON alternatives in 2026, compared honestly. Tracio, FingerprintJS, IPQualityScore and more — device intelligence, email and phone enrichment, strengths, and trade-offs. - [Top DataDome Alternatives in 2026](https://tracio.ai/alternatives/datadome-alternatives): The best DataDome alternatives in 2026, compared honestly. Tracio, Cloudflare Bot Management, Arkose, hCaptcha and more — bot mitigation, device intelligence, strengths, and trade-offs. ## Documentation - [Documentation](https://tracio.ai/docs): Learn how to integrate TRACIO device intelligence into your application for accurate visitor identification, bot detection, and fraud prevention. - [Quick Start](https://tracio.ai/docs/quick-start): Get started with TRACIO device intelligence in 5 minutes. Install the SDK, get a visitor ID, and run bot detection in the browser. - [Custom Domains](https://tracio.ai/docs/custom-domains): Serve the TRACIO script from your own subdomain so it keeps loading where third-party analytics domains are blocked. DNS, certificate and snippet setup. - [How It Works](https://tracio.ai/docs/how-it-works): Understand the architecture of TRACIO's device intelligence platform, from client-side signal collection to server-side visitor identification. - [JavaScript SDK](https://tracio.ai/docs/js-agent): Complete reference for the @tracio/sdk JavaScript SDK, including initialization, configuration, identification, lifecycle callbacks, and error handling. - [React SDK](https://tracio.ai/docs/sdk-react): Integrate TRACIO into a React app with the @tracio/react package — TracioProvider, useVisitorId, useTracioResult, and useTracio hooks. - [Vue SDK](https://tracio.ai/docs/sdk-vue): Integrate TRACIO into a Vue 3 app with the @tracio/vue package — the TracioPlugin and useVisitorId, useTracioResult, and useTracio composables. - [Angular SDK](https://tracio.ai/docs/sdk-angular): Integrate TRACIO into an Angular app with the @tracio/angular package — the provideTracio provider and the signal-based TracioService. - [Svelte SDK](https://tracio.ai/docs/sdk-svelte): Integrate TRACIO into a Svelte 5 app with the @tracio/svelte package — Tracio.init plus the useVisitorId, useTracioResult, and useTracio stores. - [Webhooks](https://tracio.ai/docs/webhooks): Configure webhooks to receive real-time identification events on your server as they happen. - [Identification](https://tracio.ai/docs/identification): How TRACIO identifies visitors using 300+ browser signals, tiered hashing, and AI-powered fuzzy matching for returning visitors. - [Bot Detection](https://tracio.ai/docs/bot-detection): Detect automated browsers, headless tools, AI agents, and antidetect browsers with near-zero false positives and verified-crawler allowlisting. - [Smart Signals](https://tracio.ai/docs/smart-signals): Reference of TRACIO's server-side enrichment signals including VPN/proxy detection, bot detection, and browser tampering. - [IP Intelligence](https://tracio.ai/docs/ip-intelligence): Server-side IP analysis covering VPN, proxy, Tor, and datacenter detection plus city-level geolocation and ASN. - [Cloud Deployment](https://tracio.ai/docs/cloud-deployment): TRACIO managed cloud — US/EU region selection, public and secret API keys, and the two ways to consume results server-side. - [Privacy & GDPR](https://tracio.ai/docs/privacy-gdpr): How TRACIO supports privacy compliance — no PII collection, first-party cookies, US/EU data regions, cookie consent, and GDPR data-subject rights. - [Changelog](https://tracio.ai/docs/changelog): Pointer to the full history of product changes — it lives on /changelog. - [Troubleshooting](https://tracio.ai/docs/troubleshooting): Solutions for common issues with TRACIO integration including blocked requests, low confidence scores, bot false positives, and cookie persistence problems. - [Error Handling](https://tracio.ai/docs/error-handling): Handle TRACIO SDK errors with the TracioError type, error codes, retry detection, and the onError callback. - [Testing](https://tracio.ai/docs/testing): Test your TRACIO integration with your dashboard public key, browser verification, and mocking the SDK instance in unit tests. - [Account Linking](https://tracio.ai/docs/account-linking): Pass your internal account ID as linkedId to unlock the Connections dashboard, cross-device identity, and account-takeover drift detection. - [Roles & Permissions](https://tracio.ai/docs/roles-permissions): What each dashboard role — Owner, Admin, Member, Read Only — can see and change in a TRACIO workspace. - [Data API](https://tracio.ai/docs/server-api): Read your identification data server-side — visitors, sessions and velocity over HTTPS, authenticated with a secret API key. ## Blog - [The real cost of false positives in fraud detection (with the math)](https://tracio.ai/blog/cost-of-false-positives-fraud-detection): Fraud dashboards count the fraud you blocked and ignore the customers you blocked with it. This is an illustrative model for the true cost of a false positive — the number that decides whether tightening your rules actually made you money. - [Detecting emulators and virtual machines in web traffic](https://tracio.ai/blog/detecting-emulators-virtual-machines): Emulators and VMs power fraud at scale — device farms, mobile-app emulation, cloud browsers. Detecting them means reading hardware, timing, and coherence signals a virtualized environment can't fully reproduce. - [Promo and coupon abuse: how multi-account farms work and how to detect them](https://tracio.ai/blog/promo-abuse-multi-account-farms): Signup bonuses and first-order coupons assume one person, one account. Multi-account farms industrialize the gap — hundreds of fake identities harvesting the same offer. Here's the operation, and the device signals that expose it. - [Device fingerprinting in a post-cookie world: the 2026 regulatory and technical map](https://tracio.ai/blog/fingerprinting-post-cookie-2026): Third-party cookies are gone or going; fingerprinting is more scrutinized than ever. The 2026 map of what changed technically (ITP, Privacy Sandbox) and legally (GDPR, ePrivacy) — and why first-party fraud fingerprinting stands apart. - [The Real Cost of False Positives in Bot Detection: Why 99% Accuracy Isn't Enough](https://tracio.ai/blog/false-positives-bot-detection-cost): On most platforms legitimate traffic dwarfs bots, so a 1% false-positive rate blocks more real customers than the entire bot count. The base-rate math that decides whether bot detection helps or quietly costs you revenue. - [How AI agents break traditional bot detection — and what still catches them](https://tracio.ai/blog/ai-agents-vs-bot-detection): AI agents drive real browsers, read pages like humans, and solve the challenges built to stop bots. The assumptions behind CAPTCHA-era detection are gone — but agents still leave signals a human never would. - [Browser fingerprinting vs IP reputation: what catches more fraud](https://tracio.ai/blog/fingerprinting-vs-ip-reputation): Browser fingerprinting and IP reputation catch different fraud in different ways. Fingerprinting identifies the device across IP changes; IP reputation flags infrastructure regardless of device. The comparison, and why you run both. - [Residential proxy detection: signals that still work in 2026](https://tracio.ai/blog/residential-proxy-detection): Residential proxies route fraud through real consumer IPs, so IP reputation alone no longer catches them. The signals that still work look past the address itself — at network stack, coherence, and behavior. - [Passkeys + device intelligence: layered account takeover defense](https://tracio.ai/blog/passkeys-device-intelligence-ato): Passkeys close the credential-theft attack surface but leave account recovery, enrollment, and session hijacking exposed. Device intelligence covers the gaps passkeys structurally can't, forming a layered ATO defense. - [Detecting AI Agents: How Claude, ChatGPT, and Perplexity Browsers Differ from Humans](https://tracio.ai/blog/detecting-ai-agents): AI agents present as browsers but behave nothing like humans — short goal-directed sessions, pixel-perfect clicks, zero typos. The 11 signals that separate Computer Use, Operator, and Perplexity traffic from real visitors. - [How to evaluate device fingerprinting accuracy claims: a buyer's framework](https://tracio.ai/blog/device-fingerprinting-accuracy-benchmarks): Every device intelligence vendor claims high accuracy. This is the framework for turning a headline percentage into a number you can actually verify against your own traffic — and the questions that separate real engineering from marketing. - [Refund fraud and serial returners: a device-graph approach](https://tracio.ai/blog/refund-fraud-serial-returners): Refund fraud and serial returners exploit account-level blind spots. A device graph links the accounts, addresses, and payment methods one operator uses to industrialize returns, wardrobing, and empty-box claims. - [WebGPU Fingerprinting: The Next Generation After Canvas and WebGL](https://tracio.ai/blog/webgpu-fingerprinting-next-generation): WebGPU exposes deeper hardware capabilities than Canvas and WebGL combined — and it's already available in Chrome, Edge, and Firefox. What it can reveal, and why it will replace older fingerprinting techniques over the next 2–3 years. - [The Anatomy of a Multi-Accounting Attack: Case Study on an iGaming Platform](https://tracio.ai/blog/multi-accounting-attack-igaming): One operator, 217 accounts, $84,000 in bonus abuse. How professional multi-accounting is actually built — and the 11 correlated signals that collapsed the whole cluster back into a single fraudster. - [Canvas Fingerprinting Beyond the Basics: Why Two Identical Chromes Render Different Pixels](https://tracio.ai/blog/canvas-fingerprinting-beyond-basics): Two devices with the same Chrome, OS, and GPU still render different canvas pixels. Why the rendering pipeline is non-deterministic, why privacy noise injection backfires, and where canvas fits in a modern detection stack. - [How Puppeteer Detection Actually Works: 12 Signals That Give Bots Away](https://tracio.ai/blog/puppeteer-detection-signals): Automation frameworks inherit a real browser's fingerprint but change it in dozens of observable ways. A field guide to the 12 JavaScript, network, and behavioral signals defenders use to catch Puppeteer and Playwright. - [How device fingerprinting actually works: the engineering behind a 50ms verdict](https://tracio.ai/blog/how-device-fingerprinting-works): The engineering version of device fingerprinting: what gets collected across five signal layers, how signals become a stable identifier, why polymorphic code matters, and how it adds up to a 50ms verdict. - [Click fraud is bleeding $100B from AdTech. Here's where the money actually goes.](https://tracio.ai/blog/adtech-click-fraud-100b): Ad fraud losses topped $84B in 2025 and will exceed $100B in 2026. A breakdown of the five major fraud categories, why post-bid verification isn't enough, and what pre-bid architecture actually works. - [Sybil resistance for Web3 protocols: why most airdrops fail and what works](https://tracio.ai/blog/sybil-resistance-web3-airdrops): Without proper defense, 50-80% of an airdrop reaches farmers rather than the intended community. Here's how professional farming operations work in 2026 and what defensive architecture actually holds up. - [Account takeover in 2026: why credential stuffing keeps winning and what stops it](https://tracio.ai/blog/account-takeover-2026): Credential stuffing keeps succeeding because password reuse makes the attack economics overwhelmingly favor attackers. 2FA covers only the enrolled minority — device intelligence at login is the leverage point. - [Which verticals lose the most to fraud, and why the patterns differ](https://tracio.ai/blog/fraud-loss-by-vertical): A breakdown of the five verticals that lose the highest percentage of revenue to fraud — iGaming, Crypto/Web3, FinTech, AdTech, and E-commerce — and the structural factors that make each one a target. - [AI agents are the new fraud vector. Here's why your detection probably misses them.](https://tracio.ai/blog/ai-agents-fraud-vector): LLM-powered agents drive real browsers, reason about pages, and look human at the surface. The behavioral and CAPTCHA signals that caught script bots are noticeably weaker against them. - [Inside iGaming fraud: how operators lose 8–20% of revenue and what to do about it](https://tracio.ai/blog/igaming-fraud-revenue-loss): iGaming operators lose 8–20% of revenue to bonus abuse, risk-free bet exploitation, collusion, and account takeover. Here's why single-layer defenses fail and what a layered device-intelligence program actually catches. - [The state of bot traffic in 2026: what your traffic actually looks like](https://tracio.ai/blog/state-of-bot-traffic-2026): Roughly half of all inbound traffic is automation, and the 2026 threat mix has shifted from dumb scripts to LLM-driven agents. Here's what's hitting your platform and what actually defends against it. - [TRACIO vs Fingerprint: Honest Comparison (2026)](https://tracio.ai/blog/tracio-vs-fingerprint): A fair, detailed comparison of tracio.ai and Fingerprint Pro across accuracy, latency, bot detection, pricing, and anti-detect browser coverage. - [How to Detect Anti-Detect Browsers (Multilogin, GoLogin, Dolphin Anty)](https://tracio.ai/blog/detect-anti-detect-browsers): Technical deep-dive into how anti-detect browsers work, why they're used for fraud, and the detection techniques that catch them. - [49.6% of Your Traffic Is Bots: What That Means for Your Business](https://tracio.ai/blog/bot-traffic-statistics-2026): Nearly half of all internet traffic is automated. Here's what the data says, what it costs, and what you can do about it. - [Device Fingerprinting Without Cookies: How It Works](https://tracio.ai/blog/device-fingerprinting-without-cookies): Cookies are dying. Here's how device fingerprinting provides persistent identification that survives cookie clearing, incognito mode, and browser updates. - [How Digital Footprint Tracking Works Under the Hood](https://tracio.ai/blog/digital-footprint-tracking): From TLS handshakes to canvas rendering — how we reconstruct a device's digital footprint from over 300 passive signals, without depending on stored state. - [Cross-Device Tracking: Linking Sessions Without Login](https://tracio.ai/blog/cross-device-tracking-deep-dive): How our device identification algorithm connects anonymous sessions across browsers and devices using probabilistic signal matching and graph analysis. - [Trial Abuse Is Killing SaaS Revenue — Here's How Midjourney Lost Millions](https://tracio.ai/blog/trial-abuse-saas): SaaS companies lose an estimated $4.5B annually to trial abuse. Device fingerprinting is the only defense that works against anti-detect browsers. - [Building a Real-Time Fraud Analytics Pipeline](https://tracio.ai/blog/fraud-analytics-pipeline): Architecture walkthrough: ingesting 50K events/second, enriching with smart signals, and scoring risk in under 10ms using our streaming engine. - [TLS Fingerprinting and JA4 Hashes Explained](https://tracio.ai/blog/tls-fingerprinting-ja4): Why TLS Client Hello messages are a goldmine for device identification — and how JA4 hashes give us a stable fingerprint that survives browser updates. - [GDPR-Compliant Device Fingerprinting: A Legal and Technical Guide](https://tracio.ai/blog/gdpr-compliant-device-fingerprinting): Device fingerprinting and GDPR aren't mutually exclusive. Here's how to implement fraud-prevention fingerprinting that satisfies your DPO and your security team. - [Stopping Credential Stuffing at the Edge](https://tracio.ai/blog/credential-stuffing-defense): How tracio.ai identifies automated login attempts before they hit your auth system — combining device fingerprints, velocity checks, and behavioral signals. - [Canvas and WebGL Fingerprinting in 2026](https://tracio.ai/blog/canvas-webgl-fingerprinting): The state of GPU-based fingerprinting: what changed with Chrome's privacy sandbox, how we adapted, and why hardware signals remain the most stable identifiers. - [Zero Trust Starts with Device Verification](https://tracio.ai/blog/zero-trust-device-verification): Why trusting the user without verifying the device is like checking ID but not the car. How device intelligence fits into zero-trust architectures. - [Detecting Headless Browsers: Playwright, Puppeteer, and Beyond](https://tracio.ai/blog/bot-detection-headless-browsers): Our Bot Detection engine identifies 15+ automation frameworks through signal inconsistencies, missing APIs, and behavioral patterns that bots can't fake. - [Real-Time Fraud Scoring at Scale](https://tracio.ai/blog/real-time-fraud-scoring): How tracio.ai processes 50K events/second with sub-50ms scoring using stream processing, pre-computed signal vectors, and edge caching. - [Device Tracking vs Cookie Tracking: A Technical Comparison](https://tracio.ai/blog/device-vs-cookie-tracking): Cookies are dying. Device fingerprinting provides persistent identification without storage. A side-by-side analysis of accuracy, privacy, and implementation. - [How We Built tracio.ai's Sub-30ms Pipeline](https://tracio.ai/blog/traceid-sub-30ms-pipeline): From signal collection to visitor ID in under 30ms: our architecture using Go, ClickHouse, Redis, and distributed processing. - [Rust in Production: Why We Rewrote Our Signal Processor](https://tracio.ai/blog/rust-in-production): We rewrote our signal processing engine from Go to Rust. Here's why, what we learned, and the 4x throughput improvement we achieved. - [The Math Behind Cross-Session Device Matching](https://tracio.ai/blog/fuzzy-device-matching-math): The mathematical foundations of matching devices across changing signals — how AI-powered analysis reconnects returning visitors despite signal drift. - [Enterprise SSO Integration Guide](https://tracio.ai/blog/enterprise-sso-guide): Integrating tracio.ai with SAML, OIDC, and custom identity providers. Step-by-step for Okta, Auth0, and Azure AD with code examples. - [WebRTC IP Leak Detection: From Bug to Feature](https://tracio.ai/blog/webrtc-ip-leak-detection): WebRTC STUN/TURN probes reveal real IPs behind VPNs. How we turned a privacy leak into a fraud detection signal. - [Device Graph Analysis: Connecting the Dots Across Sessions](https://tracio.ai/blog/device-graph-analysis): How graph databases reveal hidden connections between devices, enabling multi-account detection and fraud ring identification at scale. - [Running ClickHouse in Production: Ingestion, Merges & Cost at 2B Rows](https://tracio.ai/blog/clickhouse-billion-rows): Our experience running ClickHouse in production: schema design, query optimization, and how we achieve sub-second analytics across 100M+ device events. - [Chrome Privacy Sandbox: What It Means for Device Fingerprinting](https://tracio.ai/blog/privacy-sandbox-impact): Chrome is restricting userAgent, Client Hints, and third-party cookies. How tracio.ai maintains 99.5% accuracy despite these restrictions. - [Detecting Multi-Accounting in Gaming and SaaS](https://tracio.ai/blog/multi-accounting-detection): When one person creates dozens of accounts, traditional detection fails. Device fingerprinting reveals the hardware behind the accounts. - [Which Signals Survive Browser Updates? A Stability Analysis](https://tracio.ai/blog/signal-stability-browser-updates): We analyzed signal stability across 50 Chrome, Firefox, and Safari updates. Here are the most and least stable fingerprinting signals. - [Fraud Detection at the Edge: Cloudflare Workers + tracio.ai](https://tracio.ai/blog/edge-computing-fraud-detection): Run device fingerprint validation in Cloudflare Workers before requests hit your origin. Sub-5ms fraud decisions at the edge. ## API - [API overview](https://tracio.ai/anti-fraud-api): Server API base URL is https://api.tracio.ai/v1; authenticate with a secret key created in the dashboard — `Authorization: Bearer tracio_sk_...` — available from the Pro plan up - The Server API is read-only: five GET endpoints — /v1/visitors/{visitorId}, /v1/visitors/{visitorId}/sessions, /v1/visitors/{visitorId}/sessions/latest, /v1/visitors/{visitorId}/velocity, /v1/sessions/{requestId}. Lists are cursor-paginated (nextCursor / hasMore); there are no write routes and no CORS headers, so it is called from your backend, never from browser code - Webhooks push four event types — identification, account_takeover, attack_detected, reputation_changed — signed with HMAC-SHA256 in the X-Tracio-Signature header and optionally Ed25519, whose public keys are served at https://api.tracio.ai/.well-known/webhook-keys. Failed deliveries are retried up to 8 times across roughly 9 hours - Field vocabularies in responses and webhook payloads: decision.action is real, suspicious, or fake; bot.result is human, bot, or uncertain; guidance advice is allow, challenge, review, or deny. In payload version 2 both bot.score and decision.riskScore are normalised to 0-100 - [SDKs](https://tracio.ai/sdks): install in the browser with , or via the npm package @tracio/sdk — Tracio.init({ publicKey }) returns an instance with getVisitorId() and getResult(). The public key is safe to ship in page source; the secret key is not. Served from your own subdomain (see https://tracio.ai/docs/custom-domains) the script keeps loading where third-party analytics domains are blocked ## Key pages - [Pricing](https://tracio.ai/pricing): Free tier (2,500 API calls/mo), Pro from $119/mo, 14-day free trial - [How it works](https://tracio.ai/how-it-works): architecture of signal collection, matching, and the verdict engine - [Open source](https://tracio.ai/open-source): MIT-licensed client SDK and framework wrappers