TL;DR: identify devices across incognito and VPN
- Must survive cookie clears: If your fingerprint breaks the moment someone clears cookies, it is a session identifier with extra steps. Fraudsters clear cookies, open incognito, and rotate VPN exits between attempts. Your identifier has to survive all three or it is not a fingerprint.
- Hardware-based, cookie-free: cside reads more than 250 device, network, and behavioral signals per session, so the hash comes from hardware state (GPU output, canvas entropy, WebGL) not stored files. No cookie is set, so no consent banner is needed, and legitimate interest under GDPR Article 6(1)(f) holds.
- Ask your vendor one thing: does the fingerprint stay identical across incognito plus cookie clear plus VPN, on the same laptop, in a live test. If they cannot show it in a demo session, you are buying tracking, not fraud evidence.
Short on time? See cside's AI-agent detection. It covers everything below in one deployment.
Device fingerprinting solutions identify a device by reading browser, hardware and network properties during a live session and combining them into a stable identifier. Because that identifier comes from the device itself rather than a stored cookie, it keeps working when a user clears cookies, opens an incognito window or routes through a VPN, which are the exact conditions fraudsters operate in. The main thing that separates one solution from another is how stable that identifier stays under those conditions.
The 8 best device fingerprinting solutions in 2026
Below are the eight vendors that actually deliver a stable, hardware-derived fingerprint under the conditions that matter for fraud: incognito mode, cleared cookies, and VPN routing. Anything that breaks under those conditions is a session identifier with extra steps, not a fingerprint.
1. cside — best for browser-layer signal depth and GDPR posture
cside reads more than 250 signals per session and combines them into a device hash that stays identical across incognito, cookie-cleared, and VPN sessions. That is the pass/fail test for fraud, and cside is engineered around it.
Two things separate cside from FingerprintJS: the width of the signal set (100+ vs Pro's ~70), and the fact that every fingerprint response also carries AI-agent detection (Playwright, Puppeteer, Selenium, OpenAI Operator, Claude for Chrome), a VPN flag from TLS handshake fingerprinting, and cross-account device correlation — in one call. No cookie is set, so no consent banner is required, and legitimate interest under GDPR Article 6(1)(f) is the legal basis. SOC 2 Type II certified.
Best for: Any fraud, ATO, or PCI use case where the fingerprint has to survive adversarial conditions and you want AI-agent signals in the same call. Watch out for: cside is a signal provider, not a decisioning platform — bring your own rules engine. See cside device intelligence. Pricing: Free tier of 1,000 API calls/month, paid plans from $99/month.
2. FingerprintJS Pro — the developer-friendly incumbent
FingerprintJS launched the modern category on the back of a widely-adopted open-source library, and Pro is the tool most fraud engineers reach for first. Documentation is excellent, integration is fast, signal set is well-tuned. Narrower than cside but proven.
Best for: Teams that want a proven, developer-friendly fingerprint API and do not need AI-agent detection or the wider fraud-signal set in the same call. Watch out for: No AI-agent detection, no VPN flag, no cross-account correlation — you get identity, not the surrounding signals. Consortium data model also means your device data feeds their global map. Pricing: Free tier available, Pro from $200/month. See cside vs FingerprintJS for the full comparison.
3. ThreatMetrix (LexisNexis Risk Solutions) — the enterprise consortium standard
ThreatMetrix has been the enterprise fingerprinting standard for a decade and still sits inside most bank and PSP fraud stacks. Strength: the LexisNexis consortium — billions of transactions worth of shared data. Weakness: platform age and enterprise-only sales.
Best for: Regulated financial services with a LexisNexis relationship already in place. Watch out for: Six-figure minimum contracts, six-month procurement cycles, and consortium data-sharing that your competitors also feed into.
4. Iovation (TransUnion) — legacy ATO defense
Now part of TransUnion. Long history in ATO defense, especially gaming and iGaming. Strong device reputation database from years of consortium data collection.
Best for: Enterprises with an existing TransUnion relationship. Watch out for: The platform has not seen the same modernization investment as newer entrants. Ask for a live demo before assuming the fingerprint holds under incognito + VPN.
5. SEON — device fingerprinting inside a broader fraud platform
SEON bundles device fingerprinting with digital footprint enrichment, email + phone lookups, and a full rules engine. Not a pure fingerprinting play — you are buying the whole fraud stack. No consortium data sharing (their differentiator vs ThreatMetrix).
Best for: Growth-stage fraud teams that want fingerprinting + platform in one contract. Watch out for: If you already have a rules engine, you are paying for pieces you will not use.
6. Sardine — behavioral biometrics on top of fingerprinting
Sardine leads with behavioral signals (typing rhythm, cursor movement, phone-holding) layered on device fingerprinting. Especially strong in fintech and crypto.
Best for: Fintech and crypto merchants where user behavior is a stronger signal than device state alone. Watch out for: Overkill when all you need is a stable device hash.
7. IPQualityScore — cheapest per-lookup option at high volume
IPQS is the price-per-call option. The fingerprint is thinner than cside or FingerprintJS but the API is fast, cheap, and volume-friendly. Big user base at the top of the funnel: registration screening, IP scoring, proxy detection.
Best for: High-volume, top-of-funnel deployments where cost per API call matters more than signal depth. Watch out for: Signal set is shallower — do not use as your only fraud signal on high-value transactions.
8. Incognia — mobile-first device + location intelligence
Incognia specializes in mobile and combines device fingerprinting with location behavior over time. Distinctive positioning: they know where a device usually is.
Best for: Mobile-first apps where location behavior is part of the fraud story (delivery, ride-share, gig, mobile banking). Watch out for: Not the right pick if your traffic is 80%+ web.
Side-by-side comparison of the 8 vendors
| Vendor | Signals per session | Incognito + cookie-clear + VPN | AI-agent detection | Consortium data | GDPR base |
|---|---|---|---|---|---|
| cside | 100+ | Yes | Yes | No | Legitimate interest |
| FingerprintJS Pro | ~70 | Yes | No | Yes | Consent or LI |
| ThreatMetrix | Undisclosed | Partial | Limited | Yes | Consent |
| Iovation | Undisclosed | Partial | Limited | Yes | Consent |
| SEON | ~50+ | Yes | Limited | No | Legitimate interest |
| Sardine | ~50+ | Yes | Yes | Partial | Consent |
| IPQualityScore | ~30 | Partial | No | Yes | Consent |
| Incognia | Mobile-heavy | Yes (mobile) | Limited | Partial | Consent |
How to evaluate a device fingerprinting vendor in one demo
Three questions separate a real fingerprint from a session identifier:
- On the same laptop, does the fingerprint stay identical across incognito + cookie clear + VPN? Watch a live test. If the hash changes when the user opens an incognito window, the tool is not a fingerprint — it is a cookie in a costume.
- Which signals feed the fingerprint, and are any of them stored personal data under GDPR? If any signal is a personal identifier, your legal basis becomes consent, not legitimate interest, and you need a banner.
- Is my session data pooled into a consortium? For some sectors that is an advantage (shared fraud intelligence); for others it is a competitive risk (your fingerprint data feeds a map your competitors also buy).
If the vendor cannot answer those three in 15 minutes, they should not be on the shortlist.
Which fingerprinting solution powers which fraud use case
Device fingerprinting is the input for four high-value fraud use cases. Match the vendor to the use case, not the other way round.
- Account takeover detection. When a known account logs in from a device fingerprint that has never been tied to it, that is credential compromise until proven otherwise. Real-time fingerprint matching at authentication triggers step-up or block. See account takeover.
- Multi-accounting detection. One fingerprint tied to many accounts is a fake-account ring. Highest impact in iGaming (bonus abuse), marketplaces (seller manipulation), and fintech (synthetic identity). See multi-accounting.
- Chargeback evidence. A device ID captured at checkout creates a persistent record linking device to transaction. cside packages this into chargeback evidence for dispute responses under Visa CE 3.0.
- AI agent detection. Automation tools produce distinctive device environments (low-entropy canvas, uniform WebGL, limited fonts). Device fingerprinting feeds AI agent detection alongside cursor-geometry and session-cadence signals, and flags named agents (Playwright, Puppeteer, Selenium, OpenAI Operator, Claude for Chrome).
Is device fingerprinting GDPR-compliant in 2026?
Yes, when the vendor stores no personal data and uses legitimate interest under Article 6(1)(f) as the legal basis. No cookie is set, no consent banner is required, and the fingerprint hash is not a personal identifier under the regulation.
cside stores a hash of device properties, not the raw values or any linked personal data. The fingerprint identifies the device configuration, not the person behind it — no name, email, or IP is stored against it. cside is SOC 2 Type II certified, which matters for enterprise procurement in financial services and healthcare.









