Skip to main content
Blog
Blog

9 best ThumbmarkJS alternatives in 2026, ranked and compared

Looking for a ThumbmarkJS alternative? Compare the 9 best options for 2026, ranked, with cside first for a first-party device ID plus a fraud verdict.

Aug 21, 2026 Updated Aug 22, 2026 15 min read
9 best ThumbmarkJS alternatives in 2026, ranked and compared
Table of Contents

If you are searching for a ThumbmarkJS alternative, you already know what a fingerprint library gives you: a stable visitor ID computed in the browser from canvas, fonts, WebGL, audio, and hardware signals. The reason you are looking elsewhere is usually not the ID itself. It is what the ID does not tell you: is this a human, an AI agent, or a bot? Is the connection hidden behind a VPN or a residential proxy? Can I use this to win a chargeback or pass a PCI DSS audit? This guide ranks the nine best ThumbmarkJS alternatives for 2026, with cside first, and is honest about when a cheaper or open-source option is the right call.

One distinction is worth clearing up first, because it changes the whole shortlist. ThumbmarkJS is two things: a free, MIT-licensed open-source library that runs entirely client-side and reaches roughly 80% uniqueness, and a commercial cloud API at thumbmarkjs.com that adds server-side signals (TLS, HTTP headers, connection data) to push accuracy past 99% and adds bot, VPN, and datacenter flags. Replacing the free library is a different exercise from replacing the paid API, so decide which one you are actually leaving before you read the list.

Why teams outgrow ThumbmarkJS

ThumbmarkJS is a well-built, developer-friendly fingerprint library, and for a lot of use cases it is genuinely the right tool. Teams still outgrow it, and the reasons cluster into four:

  • Browser-only accuracy has a ceiling. The open-source library reaches roughly 80% uniqueness on its own. That is fine for analytics de-duplication and returning-visitor recognition, but it is thin for high-stakes decisions where a wrong match blocks a real payment or locks out a real customer. Closing that gap means adding server-side signals, which is what the commercial API (and most commercial alternatives) exist to do.
  • A visitor ID answers "who is here", not "what is happening". The library returns an identifier and, on the API, a threat level. It does not natively tell you whether the visitor is an AI agent, whether the session is running through a VPN or residential proxy, whether it is incognito, or whether your payment page meets PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1. If your real problem is fraud or compliance, you are buying half a solution and building the rest.
  • Open source means you own the operations. There is no support contract, no pre-built rules, and no managed enrichment behind the MIT library. You read the signal and write the logic. That is a feature if you have the engineering capacity and a cost if you do not.
  • Self-hosting a client-side collector still leaves you exposed on the pages you care about. A fingerprint library sees the device; it does not see the third-party scripts executing next to your checkout. That is a separate class of risk, and a fingerprinting tool never addresses it.

Device fingerprinting is the primary pre-authentication signal for stopping the credential-stuffing campaigns that drive account takeover at scale. Javelin Strategy & Research put US account takeover losses at $13.5 billion in 2025, up 18% year on year. A fingerprint alone does not close that gap; a fraud verdict does. That is the lens this list uses.

How to evaluate a ThumbmarkJS alternative

Before the ranking, here is the checklist that separates the options. Score any candidate against these and the shortlist writes itself:

  1. Are you replacing the library or the API? Answer this first; it halves the list. Leaving the free library for accuracy means a different free library will not solve it. Leaving the paid API for cost means dropping back to a library reintroduces the accuracy gap you were paying to close.
  2. Do you need identification, or a verdict? A raw ID feeds your own rules engine. A verdict (AI agent, VPN/proxy, incognito, bot) is usable the moment it arrives.
  3. What does a wrong identification cost you? For analytics de-duplication, open-source accuracy is usually fine. For blocking a payment or locking an account, a false match has a real cost and commercial accuracy pays for itself.
  4. How often will you call it? Per-call pricing punishes per-page-view usage. Check the included volume and the overage rate, not just the entry price. A self-hosted library has no per-call cost at all.
  5. Is the collector blockable? A third-party collector origin can sit on privacy filter lists (uBlock Origin, AdGuard, Brave), so it produces no signal for privacy-conscious visitors. A first-party script loaded from your own origin has no third-party domain to block.
  6. Do you also need to know what is running on your pages? If PCI DSS 6.4.3 and 11.6.1 are in scope, a fingerprinting library does not address them and you will be buying a second tool.
  7. Web only, or mobile too? Confirm platform coverage and whether mobile SDKs are generally available or in beta.

The 9 best ThumbmarkJS alternatives in 2026

Ranked for teams who want more than a browser-only device ID. If a free, self-hosted identifier is genuinely all you need, skip to the open-source entries near the end.

1. cside, the best all-in-one ThumbmarkJS alternative

cside is a single first-party JavaScript snippet that returns a high-accuracy device fingerprint and a real-time fraud verdict, so you replace ThumbmarkJS and the extra tools you would otherwise bolt on around it. It is the strongest ThumbmarkJS alternative for teams whose threat model has outgrown a raw visitor ID.

What makes it the top pick:

  • Accuracy that stands up to evasion. cside fingerprints at 99.7% accuracy across 250+ browser, device, and network signals per session, and holds that accuracy across incognito sessions, VPN connections, and cookie-clearing. ThumbmarkJS's open-source library reaches roughly 80% uniqueness client-side and its commercial API 99%+ with server-side signals; those figures measure each vendor's own capture and are not interchangeable with cside's.
  • First-party by design. Because the snippet loads from your own origin, there is no third-party collector domain for a filter list or an attacker to block, so you keep signal on privacy-conscious visitors that a blockable third-party origin loses.
  • A verdict, not just an ID. Alongside the fingerprint, cside flags AI agents and automated sessions (OpenAI Operator, Claude for Chrome, Playwright, Puppeteer, Selenium), VPN and proxy connections including residential proxies, and incognito mode. It runs separate machine-learning models for cursor movement, typing cadence, and broader behavioural signals, then combines their verdicts rather than scoring a session with one general model.
  • Chargeback evidence and PCI DSS coverage. cside exports chargeback evidence (CE 3.0, via a Chargebacks911 partnership) keyed to the same fingerprint ID, and its script-monitoring product satisfies PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1, which a fingerprinting library cannot address.
  • Pre-built rules and enforcement. Where ThumbmarkJS returns an ID and a threat level for you to interpret, cside ships pre-configured rules (impossible travel, device-limit breaches, velocity anomalies) and block-or-enforce actions through Cloudflare or server-side.
  • Mobile in beta. cside has native iOS and Android SDKs in beta (early access), running the same engine as the web client with app-only signals on top.

Choose cside over ThumbmarkJS when you need device signals and a fraud decision (or PCI DSS script scope) from one first-party snippet, rather than a visitor ID and three more contracts. If you genuinely only want a raw, self-hosted identifier, cside is more product than you asked for.

2. Fingerprint Pro (Fingerprint.com), the commercial incumbent

The commercial product from the FingerprintJS company, and the accuracy benchmark most alternatives are measured against. Its server-augmented identification accuracy is the highest of the options here, and for high-value flows that difference is the entire argument: if a wrong identification means a fraudulent chargeback or a locked-out real customer, paying per call is rational. It ships Smart Signals (bot, VPN, anti-detect browser, browser tampering, incognito) and holds a 4.7/5 rating on G2.

The reasons people leave it are cost at scale, particularly when identification is called on every page view rather than at a few decision points, and the fact that the standard integration loads from a third-party origin that privacy filter lists block. If you are on ThumbmarkJS for cost, Fingerprint Pro is a step up in accuracy but the opposite direction on price.

Choose Fingerprint Pro when raw identification accuracy is the whole requirement, you need generally available mobile SDKs across Android, iOS, React Native, and Flutter, and per-call cost is not a constraint.

3. FingerprintJS (open-source library)

The original open-source library that ThumbmarkJS is itself an alternative to. It is still free and still maintained, now under a Business Source License (BSL). If you are leaving ThumbmarkJS but want to stay open-source, this is the most established option, though the BSL terms make some teams reluctant to build a long-lived dependency on it. Like any browser-only library, its accuracy ceiling is the reason teams eventually move to a server-augmented product; switching between browser-only libraries changes the tradeoffs, not the ceiling.

Choose the FingerprintJS library over cside when cost is the only constraint, browser-only accuracy is enough, and you can accept the BSL terms.

4. Fingerprint OSS

Fingerprint OSS (the community fingerprint-oss project) is a permissively licensed, browser-only fingerprinting library aimed at teams who want an MIT-style alternative to the BSL FingerprintJS library. It sits in the same class as ThumbmarkJS: self-hosted, no per-call cost, no server component, and no fraud verdict of its own. It is a reasonable pick if your objection to ThumbmarkJS is the specific library rather than the open-source model itself, but it inherits the same browser-only accuracy ceiling.

Choose Fingerprint OSS over cside when you want a permissively licensed, self-hosted library and do not need enrichment, a verdict, or a managed service behind it.

5. SEON Device Intelligence

SEON's device module sits inside a larger fraud platform that also does email, phone, and IP enrichment plus KYC and AML workflow. Buying it for device fingerprinting alone is unusual; buying it because you want the device signal to sit next to digital-footprint enrichment in one decision is the normal path. It is a bigger jump from ThumbmarkJS than a like-for-like fingerprint swap.

Choose SEON over cside when you want fraud decisioning and compliance workflow in one suite rather than a focused first-party signal layer with client-side security.

6. IPQualityScore (IPQS)

IPQS is a fraud-prevention API that combines device fingerprinting with proxy and VPN detection, email and phone validation, and bot scoring, delivered as a risk score rather than a raw ID. It has usage-based pricing and a free tier for evaluation. It is a reasonable pick when you want a scored fraud signal from an API and are not tied to a first-party collector or to script monitoring.

Choose IPQS over cside when you want a hosted fraud-scoring API with broad enrichment and do not need first-party delivery or PCI DSS coverage.

7. ClientJS

An older, lightweight open-source (MIT) browser fingerprinting library. Like ThumbmarkJS it runs entirely in the browser with no server component, but it is less actively maintained and its signal surface is narrower, so expect a lower identification rate than ThumbmarkJS. It is a fit for simple, low-stakes de-duplication where you want a dependency-light library and accuracy is not critical.

Choose ClientJS over cside when you need a minimal, self-hosted fingerprint for non-critical use and want no external service at all.

8. CreepJS

CreepJS is an open-source fingerprinting research and diagnostic tool. Rather than a production visitor-ID library you drop into an app, it is best known for surfacing how much entropy a browser leaks and for exposing lies and spoofing (anti-detect browsers, tampered user agents, mismatched signals). Teams use it to understand fingerprint entropy and evasion, not usually as the fingerprint that ships to production. If you picked ThumbmarkJS to learn what signals matter, CreepJS is the better teaching tool; it is not a like-for-like replacement.

Choose CreepJS over cside when your goal is researching fingerprint entropy and detecting spoofing, not shipping a production identification or fraud pipeline.

9. imprint

imprint is a minimal open-source browser fingerprinting library in the same class as ClientJS: dependency-light, browser-only, community-maintained, and free to self-host. It is a fit when you want the smallest possible fingerprint dependency and are comfortable that a lean signal surface means a lower identification rate and no enrichment or verdict. Like every browser-only library on this list, it does nothing for compliance, chargebacks, or bot and agent detection.

Choose imprint over cside when you want the lightest self-hosted fingerprint possible and accuracy, enrichment, and a verdict are all non-goals.

cside vs ThumbmarkJS: feature comparison

The head-to-head that most buyers actually care about. This is where the "fraud verdict, not just an ID" difference shows up concretely.

FeaturecsideThumbmarkJS
Open-source libraryNoYes (MIT, self-hostable)
Uniqueness / accuracy99.7% across incognito, VPN, cookie-clearing~80% library, 99%+ commercial API
Signals per session250+Broad client-side set (+ server signals on API)
CollectorFirst-party (your origin, not filter-list blockable)Client-side library, or third-party API
AI agent detectionYes (Operator, Claude, Playwright, Puppeteer, Selenium)No
VPN/proxy detectionYes (incl. residential proxies)VPN + datacenter (API only)
Incognito detectionYesNo
Pre-built rules + enforcementYes (Cloudflare or server-side)Threat level only, build your own
Client-side script monitoringYes (separate product, bundleable)No
PCI DSS 4.0.1 evidenceYes (Req 6.4.3 + 11.6.1)No
Chargeback evidence exportYes (CE 3.0, Chargebacks911)No
Mobile SDKsBeta (native iOS, Android)No (web only)
Entry price$99/mo, 50,000 API callsFree library; API from ~€15/mo, 15,000 calls
Free tierYes (1,000 API calls/month, no card)Yes (library free; API 1,000 calls/month)

How cside builds a high-accuracy fingerprint

cside analyses more than 250 browser, device, and network signals per visit. The signals include canvas entropy, font-rendering differences, WebGL fingerprint, screen metrics, timing patterns, and headless-browser flags.

On top of standard browser attributes, cside layers TLS handshake fingerprinting. The TLS handshake captures how a device negotiates a connection, a signal that persists even when the user rotates through multiple VPNs or clears cookies. That is how cside keeps fingerprint accuracy at 99.7% across incognito sessions, VPN connections, and cookie-clearing behaviour, where a browser-only library like ThumbmarkJS tops out near 80%.

Because the same snippet also reads behavioural channels, cside runs dedicated models for cursor movement, typing cadence, and broader in-session behaviour, then combines them into one verdict rather than scoring a session with a single general model.

Where cside goes beyond a device ID

This is the reason cside tops the list rather than sitting mid-pack with the other identification tools. A ThumbmarkJS visitor ID tells you who is here. cside returns a stable ID and then answers what is happening:

  • AI agent and bot detection. The verdict flags automated sessions, including agentic browsers like OpenAI Operator and Claude for Chrome and automation frameworks like Playwright, Puppeteer, and Selenium, on your login and checkout flows.
  • VPN and proxy detection. cside flags connections routed through VPNs and proxies, including the residential proxies that evade IP reputation lists, so you can enforce geographic rules or raise risk on hidden connections.
  • Chargeback evidence. The chargeback evidence export packages device-level proof keyed to the fingerprint ID, so you can prove a fraudster used a specific device when disputing under CE 3.0.
  • PCI DSS script monitoring. cside's script-monitoring product inventories and verifies the integrity of the scripts on your payment pages, which is what PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1 ask for, and which fingerprinting alone never sees.

Bundling these under one first-party snippet is the practical argument: one vendor, one integration, one contract, instead of a fingerprint library plus a bot tool plus a chargeback tool plus a script monitor.

Which ThumbmarkJS alternative should you choose?

  • Need a device ID plus a fraud verdict, chargeback evidence, or PCI DSS scope from one first-party snippet: cside.
  • Need the highest raw identification accuracy and GA mobile SDKs, cost no object: Fingerprint Pro.
  • Want to stay open-source and self-hosted: the FingerprintJS library (BSL), Fingerprint OSS or ClientJS (MIT), or imprint for the lightest dependency.
  • Want device signals inside a full fraud/KYC suite: SEON Device Intelligence, or IPQualityScore for a hosted fraud-scoring API.
  • Researching fingerprint entropy and spoofing rather than shipping to production: CreepJS.

If you want the direct head-to-head instead of this survey, the cside vs ThumbmarkJS comparison puts the two side by side, and the FingerprintJS alternatives guide covers the closely related question of replacing FingerprintJS.

Further reading

Mike Kutlu
Client-Side Security Consultant

Client-side security consultant at cside. 10+ years of experience implementing technology solutions for enterprises (previously at Oracle, Cloudflare, and Splunk). Now helping teams use client-side intelligence to catch & reduce fraud.

FAQ

Frequently Asked Questions

It depends on what you are replacing. If you want to stay open-source and free, the FingerprintJS library, Fingerprint OSS, and ClientJS are the closest self-hosted substitutes. If you need higher raw identification accuracy, Fingerprint Pro is the commercial incumbent. If you need a device ID that arrives with a fraud verdict (AI agent detection, VPN and proxy flagging, chargeback evidence, and PCI DSS script monitoring) from a single first-party script, cside is the strongest all-in-one ThumbmarkJS alternative. This guide ranks nine options so you can match the tool to the problem.

The ThumbmarkJS library is free and open source under an MIT license, and you can use it commercially. It runs entirely in the browser and reaches roughly 80% uniqueness on its own. Thumbmark also sells a commercial cloud API that adds server-side signals and higher accuracy, starting with a free tier of 1,000 calls per month and a Pro plan around €15/month for 15,000 calls. The library trades identification accuracy for cost, so the honest question is whether that accuracy is enough for what you are protecting.

Teams usually move for one of three reasons. The library's browser-only uniqueness (around 80%) is not enough for high-stakes decisions like blocking a payment or locking an account. A raw visitor ID answers who is here but not what is happening, so there is no AI-agent, bot, VPN, or incognito verdict without building it yourself. And an open-source library has no support, no pre-built rules, and no compliance output, so if PCI DSS script monitoring or chargeback evidence is in scope you are buying a second tool anyway.

Yes. The FingerprintJS open-source library, Fingerprint OSS, ClientJS, CreepJS, and imprint are all open-source browser libraries you can self-host at no per-call cost. Among commercial products, cside offers a free tier of 1,000 API calls per month with no credit card, which is enough to validate accuracy on real traffic before you pay. The open-source options trade identification accuracy and enrichment for cost.

ThumbmarkJS is cheaper on raw fingerprinting: the library is free to self-host, and the commercial API starts around €15/month for 15,000 calls. cside is $99/month for 50,000 API calls with $2 per 1,000 overage, plus a free tier of 1,000 API calls per month. If you only need a visitor ID, ThumbmarkJS is the lower-cost path. cside's price reflects a wider platform: a fraud verdict, script monitoring, PCI DSS 4.0.1 controls, and chargeback evidence bundled with fingerprinting.

No. Fingerprinting libraries and device-intelligence products are a data-capture layer: they collect device and browser signals and produce a visitor ID, sometimes with a risk verdict. Those signals still feed downstream systems, an anti-fraud suite, a chargeback tool, or your own rules engine. cside goes further than a raw library by shipping pre-built rules and enforcement, but the decision to block, challenge, or allow still lives in your stack.

ThumbmarkJS is a device-fingerprinting project that exists in two forms. The first is a free, MIT-licensed open-source JavaScript library that runs entirely in the browser, collecting canvas, font, WebGL, audio, and hardware signals to compute a stable visitor ID with roughly 80% uniqueness. The second is a commercial cloud API at thumbmarkjs.com that adds server-side signals such as TLS, HTTP headers, and connection data to push identification accuracy past 99% and layer on bot, VPN, and datacenter flags. When you shop for an alternative, decide which one you are replacing first: swapping the free library for another free library keeps the accuracy ceiling, while leaving the paid API for a library reintroduces the gap you were paying to close.

An open-source library such as ThumbmarkJS, the FingerprintJS library, Fingerprint OSS, or ClientJS gives you a raw visitor ID: it captures browser signals and returns an identifier that answers who is here. You then write the rules that decide what to do with it. A device-intelligence platform such as cside returns the ID and a verdict in the same response: it flags AI agents and automated sessions, VPN and proxy connections including residential proxies, and incognito mode, and it ships pre-built rules and enforcement. The library is a data-capture layer you build on; the platform is closer to a decision you can act on the moment it arrives. That is why cside adds a verdict, not just an ID, which is the main reason a team leaves a library.

A browser-only library like ThumbmarkJS reaches roughly 80% uniqueness because it can only read what JavaScript exposes in the page: canvas, fonts, WebGL, audio, screen metrics, and similar attributes. Identical devices on the same browser version collide, and privacy features, common configurations, and anti-detect browsers erode the rest. Accuracy climbs when server-side signals are added: the ThumbmarkJS commercial API cites 99%+ with TLS and connection data, and cside fingerprints at 99.7% across 250+ signals per session, holding that accuracy across incognito, VPN, and cookie-clearing thanks to TLS handshake fingerprinting. Each vendor's figure measures its own capture, so the numbers are not interchangeable.

Self-hosting an open-source library such as ThumbmarkJS or ClientJS has no per-call cost and keeps the collector under your control, but you own the operations: no support contract, no pre-built rules, no managed enrichment, and an accuracy ceiling you close only by building server-side signals yourself. A managed service trades that engineering time for a monthly fee and gives you a maintained signal set, a fraud verdict, and compliance output. The honest test is your engineering capacity and what a wrong identification costs: for analytics de-duplication, self-hosting is usually fine; for blocking a payment or locking an account, a managed product's accuracy and verdict tend to pay for themselves.

Migrating off a browser-only library is usually a small change on the page: you swap the collector script and read a new identifier field, since most of these tools expose a similar client-side call. Moving to cside means adding one first-party JavaScript snippet loaded from your own origin, which also removes the third-party collector domain that privacy filter lists can block. Fingerprint collection runs asynchronously and does not block page rendering, so the visible latency impact is minimal and the enrichment and verdict are computed without holding up the page. Plan the migration around where you consume the ID, your rules engine or fraud logic, rather than the collection itself.

Device fingerprinting identifies a visitor from browser and device characteristics rather than a stored identifier, so it does not require cookies and keeps working when a user clears them or browses incognito. That is the point of the technique. cside collects no cookies and is built to be privacy compliant, and because its snippet is first-party it is not dropped by the filter lists that block third-party collector origins. Open-source libraries like ThumbmarkJS are likewise cookieless by design. Whichever alternative you pick, fingerprinting is still personal data in many jurisdictions, so document it in your privacy notice and confirm your lawful basis.

Monitor and Secure Your Third-Party Scripts

Gain full visibility and control over every script delivered to your users to enhance site security and performance.

Start free, or try Business with a 14-day trial.

cside dashboard interface showing script monitoring and security analytics
Related Articles
Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

We'll show you:

Which third-party scripts are running on your site right now
Where you stand on PCI DSS 6.4.3 and 11.6.1
How much of your traffic is bots and AI agents

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead