Skip to main content
Blog
Blog

Device fingerprinting solutions: how they work and what to look for

How device fingerprinting solutions identify devices with browser, hardware and network signals that survive cookie-clearing, incognito and VPN use.

Aug 03, 2026 9 min read
Device fingerprinting solutions: how they work and what to look for
Table of Contents

TL;DR: identify devices across incognito and VPN

  • Must survive cookie clears: If your fingerprint breaks the moment someone clears cookies, it is a session identifier with extra steps. Fraudsters clear cookies, open incognito, and rotate VPN exits between attempts. Your identifier has to survive all three or it is not a fingerprint.
  • Hardware-based, cookie-free: cside reads more than 250 device, network, and behavioral signals per session, so the hash comes from hardware state (GPU output, canvas entropy, WebGL) not stored files. No cookie is set, so no consent banner is needed, and legitimate interest under GDPR Article 6(1)(f) holds.
  • Ask your vendor one thing: does the fingerprint stay identical across incognito plus cookie clear plus VPN, on the same laptop, in a live test. If they cannot show it in a demo session, you are buying tracking, not fraud evidence.

Short on time? See cside's AI-agent detection. It covers everything below in one deployment.

Device fingerprinting solutions identify a device by reading browser, hardware and network properties during a live session and combining them into a stable identifier. Because that identifier comes from the device itself rather than a stored cookie, it keeps working when a user clears cookies, opens an incognito window or routes through a VPN, which are the exact conditions fraudsters operate in. The main thing that separates one solution from another is how stable that identifier stays under those conditions.

The 8 best device fingerprinting solutions in 2026

Below are the eight vendors that actually deliver a stable, hardware-derived fingerprint under the conditions that matter for fraud: incognito mode, cleared cookies, and VPN routing. Anything that breaks under those conditions is a session identifier with extra steps, not a fingerprint.

1. cside — best for browser-layer signal depth and GDPR posture

cside reads more than 250 signals per session and combines them into a device hash that stays identical across incognito, cookie-cleared, and VPN sessions. That is the pass/fail test for fraud, and cside is engineered around it.

Two things separate cside from FingerprintJS: the width of the signal set (100+ vs Pro's ~70), and the fact that every fingerprint response also carries AI-agent detection (Playwright, Puppeteer, Selenium, OpenAI Operator, Claude for Chrome), a VPN flag from TLS handshake fingerprinting, and cross-account device correlation — in one call. No cookie is set, so no consent banner is required, and legitimate interest under GDPR Article 6(1)(f) is the legal basis. SOC 2 Type II certified.

cside fingerprinting dashboard

Best for: Any fraud, ATO, or PCI use case where the fingerprint has to survive adversarial conditions and you want AI-agent signals in the same call. Watch out for: cside is a signal provider, not a decisioning platform — bring your own rules engine. See cside device intelligence. Pricing: Free tier of 1,000 API calls/month, paid plans from $99/month.

2. FingerprintJS Pro — the developer-friendly incumbent

FingerprintJS launched the modern category on the back of a widely-adopted open-source library, and Pro is the tool most fraud engineers reach for first. Documentation is excellent, integration is fast, signal set is well-tuned. Narrower than cside but proven.

Best for: Teams that want a proven, developer-friendly fingerprint API and do not need AI-agent detection or the wider fraud-signal set in the same call. Watch out for: No AI-agent detection, no VPN flag, no cross-account correlation — you get identity, not the surrounding signals. Consortium data model also means your device data feeds their global map. Pricing: Free tier available, Pro from $200/month. See cside vs FingerprintJS for the full comparison.

3. ThreatMetrix (LexisNexis Risk Solutions) — the enterprise consortium standard

ThreatMetrix has been the enterprise fingerprinting standard for a decade and still sits inside most bank and PSP fraud stacks. Strength: the LexisNexis consortium — billions of transactions worth of shared data. Weakness: platform age and enterprise-only sales.

Best for: Regulated financial services with a LexisNexis relationship already in place. Watch out for: Six-figure minimum contracts, six-month procurement cycles, and consortium data-sharing that your competitors also feed into.

4. Iovation (TransUnion) — legacy ATO defense

Now part of TransUnion. Long history in ATO defense, especially gaming and iGaming. Strong device reputation database from years of consortium data collection.

Best for: Enterprises with an existing TransUnion relationship. Watch out for: The platform has not seen the same modernization investment as newer entrants. Ask for a live demo before assuming the fingerprint holds under incognito + VPN.

5. SEON — device fingerprinting inside a broader fraud platform

SEON bundles device fingerprinting with digital footprint enrichment, email + phone lookups, and a full rules engine. Not a pure fingerprinting play — you are buying the whole fraud stack. No consortium data sharing (their differentiator vs ThreatMetrix).

Best for: Growth-stage fraud teams that want fingerprinting + platform in one contract. Watch out for: If you already have a rules engine, you are paying for pieces you will not use.

6. Sardine — behavioral biometrics on top of fingerprinting

Sardine leads with behavioral signals (typing rhythm, cursor movement, phone-holding) layered on device fingerprinting. Especially strong in fintech and crypto.

Best for: Fintech and crypto merchants where user behavior is a stronger signal than device state alone. Watch out for: Overkill when all you need is a stable device hash.

7. IPQualityScore — cheapest per-lookup option at high volume

IPQS is the price-per-call option. The fingerprint is thinner than cside or FingerprintJS but the API is fast, cheap, and volume-friendly. Big user base at the top of the funnel: registration screening, IP scoring, proxy detection.

Best for: High-volume, top-of-funnel deployments where cost per API call matters more than signal depth. Watch out for: Signal set is shallower — do not use as your only fraud signal on high-value transactions.

8. Incognia — mobile-first device + location intelligence

Incognia specializes in mobile and combines device fingerprinting with location behavior over time. Distinctive positioning: they know where a device usually is.

Best for: Mobile-first apps where location behavior is part of the fraud story (delivery, ride-share, gig, mobile banking). Watch out for: Not the right pick if your traffic is 80%+ web.

Side-by-side comparison of the 8 vendors

VendorSignals per sessionIncognito + cookie-clear + VPNAI-agent detectionConsortium dataGDPR base
cside100+YesYesNoLegitimate interest
FingerprintJS Pro~70YesNoYesConsent or LI
ThreatMetrixUndisclosedPartialLimitedYesConsent
IovationUndisclosedPartialLimitedYesConsent
SEON~50+YesLimitedNoLegitimate interest
Sardine~50+YesYesPartialConsent
IPQualityScore~30PartialNoYesConsent
IncogniaMobile-heavyYes (mobile)LimitedPartialConsent

How to evaluate a device fingerprinting vendor in one demo

Three questions separate a real fingerprint from a session identifier:

  1. On the same laptop, does the fingerprint stay identical across incognito + cookie clear + VPN? Watch a live test. If the hash changes when the user opens an incognito window, the tool is not a fingerprint — it is a cookie in a costume.
  2. Which signals feed the fingerprint, and are any of them stored personal data under GDPR? If any signal is a personal identifier, your legal basis becomes consent, not legitimate interest, and you need a banner.
  3. Is my session data pooled into a consortium? For some sectors that is an advantage (shared fraud intelligence); for others it is a competitive risk (your fingerprint data feeds a map your competitors also buy).

If the vendor cannot answer those three in 15 minutes, they should not be on the shortlist.

Which fingerprinting solution powers which fraud use case

Device fingerprinting is the input for four high-value fraud use cases. Match the vendor to the use case, not the other way round.

  • Account takeover detection. When a known account logs in from a device fingerprint that has never been tied to it, that is credential compromise until proven otherwise. Real-time fingerprint matching at authentication triggers step-up or block. See account takeover.
  • Multi-accounting detection. One fingerprint tied to many accounts is a fake-account ring. Highest impact in iGaming (bonus abuse), marketplaces (seller manipulation), and fintech (synthetic identity). See multi-accounting.
  • Chargeback evidence. A device ID captured at checkout creates a persistent record linking device to transaction. cside packages this into chargeback evidence for dispute responses under Visa CE 3.0.
  • AI agent detection. Automation tools produce distinctive device environments (low-entropy canvas, uniform WebGL, limited fonts). Device fingerprinting feeds AI agent detection alongside cursor-geometry and session-cadence signals, and flags named agents (Playwright, Puppeteer, Selenium, OpenAI Operator, Claude for Chrome).

Is device fingerprinting GDPR-compliant in 2026?

Yes, when the vendor stores no personal data and uses legitimate interest under Article 6(1)(f) as the legal basis. No cookie is set, no consent banner is required, and the fingerprint hash is not a personal identifier under the regulation.

cside stores a hash of device properties, not the raw values or any linked personal data. The fingerprint identifies the device configuration, not the person behind it — no name, email, or IP is stored against it. cside is SOC 2 Type II certified, which matters for enterprise procurement in financial services and healthcare.

Further reading

Mike Kutlu
Client-Side Security Consultant

Client-side security consultant at cside. 10+ years of experience implementing technology solutions for enterprises (previously at Oracle, Cloudflare, and Splunk). Now helping teams use client-side intelligence to catch & reduce fraud.

FAQ

Frequently Asked Questions

Device fingerprinting solutions identify individual devices by collecting browser, hardware and network properties during a live web session and combining them into a stable hash. Unlike cookies, that hash needs no stored file on the user's device, so it persists across cookie-clearing, incognito sessions and VPN use.

Fraud teams use it to link returning devices to known accounts, spot multi-accounting, flag account takeover attempts and build transaction evidence for chargeback disputes.

Accuracy varies between solutions and depends mostly on signal depth and how stable the fingerprint stays under adversarial conditions. Solutions that lean on browser-surface signals degrade when users clear cookies or switch to incognito.

Solutions that read hardware-level signals such as GPU output, canvas entropy, WebGL results and audio-context fingerprints stay stable, because those signals come from physical device state rather than stored identifiers. cside reads more than 250 signals per session to hold fingerprints steady across incognito mode, VPN routing and cookie-cleared sessions.

Yes, when the solution reads hardware and browser-environment signals instead of relying on cookies or stored identifiers. Incognito mode blocks cookie storage but does not change canvas rendering output, GPU behavior, font availability or WebGL results.

VPN routing changes the IP address but leaves those hardware and browser-environment signals untouched, so the device fingerprint holds across both conditions.

Device fingerprinting for fraud prevention is lawful under GDPR when it stores no personal data and relies on a legitimate-interest legal basis. The fingerprint is a hash of device properties, not a personal identifier, and fraud prevention is a recognized legitimate interest under Article 6(1)(f).

Because no cookie is set, no consent mechanism is required. cside is SOC 2 Type II certified and stores no raw personal data in its fingerprinting pipeline.

Monitor and Secure Your Third-Party Scripts

Gain full visibility and control over every script delivered to your users to enhance site security and performance.

Start free, or try Business with a 14-day trial.

cside dashboard interface showing script monitoring and security analytics
Related Articles
Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

We'll show you:

Which third-party scripts are running on your site right now
Where you stand on PCI DSS 6.4.3 and 11.6.1
How much of your traffic is bots and AI agents

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead