Device signals (v2)
This version of this step type is in preview / alpha. The functionality and subsequently the documentation can still change.
Evaluates the trustworthiness of the customer’s device and produces structured device context and risk assessment data
Collects device intelligence from the customer’s browser using FingerprintJS Pro and evaluates whether the device appears safe, familiar, and genuine or if there are signs of unusual activity, automation, or manipulation. The Step produces a DeviceContext data block with the collected device data and a DeviceRiskAssessment data block that drives route selection.
Key features
- Structured risk assessment: the verdict is exposed as a
DeviceRiskAssessmentdata block containing the composite result, the confidence score (0–100), the visitor history, and vault references to the raw provider responses. - Device context output: a
DeviceContextdata block with browser, operating system, IP address, geolocation, and detection details is produced on every route, giving downstream Steps access to the collected device data. - Smart Signals: bot detection, browser tampering, virtual machines, developer tools, location spoofing, jailbroken devices, emulators, cloned apps, man-in-the-middle attacks, high-activity devices, proxies, VPNs, and Tor exit nodes are captured as per-IP or device-level detections.
- Provider evidence: the full, raw FingerprintJS Server API response is stored in the vault and referenced from the assessment, so verdicts remain auditable.
- Configurable risk thresholds:
suspiciousUserThreshold,notTrustedUserThreshold, andconfidenceScoreThresholdare all optional and fall back to sensible defaults.
Configuration
| Option | Type | Required | Description |
|---|---|---|---|
provider | string | No | Device signals provider. Accepted values: FINGERPRINT. |
suspiciousUserThreshold | integer | No | Suspect score at or above which the device is routed to the suspicious route. |
notTrustedUserThreshold | integer | No | Suspect score at or above which the device is routed to the not_trusted route. |
confidenceScoreThreshold | integer | No | Minimum confidence score (0–100) below which the result is inconclusive. |
Example configuration
Thresholds omitted — defaults apply
{}
Custom thresholds
{
"provider": "FINGERPRINT",
"suspiciousUserThreshold": 75,
"notTrustedUserThreshold": 90,
"confidenceScoreThreshold": 60
}
Input data blocks
This step does not consume any input data blocks.
Routes
| Route | Description |
|---|---|
trusted | The device is considered trustworthy as the suspect score is below the suspicious threshold. |
suspicious | The device is flagged as suspicious because the suspect score has reached the suspicious threshold. |
not_trusted | The device is deemed not trusted as the suspect score has reached the high-risk (not trusted) threshold. |
inconclusive | A verdict could not be determined because the confidence score was below the required threshold. |
Output data blocks
| Route | Data blocks produced |
|---|---|
trusted | DeviceContext, DeviceRiskAssessment |
suspicious | DeviceContext, DeviceRiskAssessment |
not_trusted | DeviceContext, DeviceRiskAssessment |
inconclusive | DeviceContext, DeviceRiskAssessment |
Output mapping
| Result | Route |
|---|---|
confidenceScore < confidenceScoreThreshold | inconclusive |
suspectScore < suspiciousUserThreshold | trusted |
suspectScore >= suspiciousUserThreshold and suspectScore < notTrustedUserThreshold | suspicious |
suspectScore >= notTrustedUserThreshold | not_trusted |
The confidence score returned by the provider (0–1) is converted to a 0–100 scale before comparison with confidenceScoreThreshold. The score stored in the DeviceRiskAssessment data block is on the same 0–100 scale.
Output data blocks are persisted to the vault automatically. The raw FingerprintJS Server API response is also stored in the vault as providerResult evidence and referenced from the DeviceRiskAssessment data block, so verdicts remain auditable.
Example payloads
DeviceContext — desktop, no detections
{
"provider": "fingerprint",
"platform": "web",
"collectedAt": "2026-02-10T14:00:01.000Z",
"deviceId": "Rp7k3mN2xQwL9dVc",
"collectionId": "1770700801123.Qk7xPz",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36",
"browserName": "Chrome",
"browserVersion": "124.0.0.0",
"osName": "Mac OS X",
"osVersion": "10.15.7",
"deviceType": "desktop",
"deviceModel": null,
"deviceManufacturer": null,
"sdkVersion": null,
"appBundleId": null,
"timezone": "Europe/Berlin",
"language": null,
"ipAddresses": [
{
"version": "v4",
"address": "82.64.123.45",
"geolocation": {
"latitude": 48.8566,
"longitude": 2.3522,
"city": "Paris",
"country": "FR",
"timezone": "Europe/Paris"
},
"vpn": false,
"tor": false
}
],
"incognito": false,
"detections": {
"bot": false,
"tampering": false,
"virtualMachine": false,
"developerTools": null,
"locationSpoofing": null,
"jailbroken": null,
"emulator": false,
"clonedApp": null,
"mitmAttack": null,
"highActivityDevice": null,
"proxy": false
}
}
DeviceRiskAssessment — trusted
{
"provider": "fingerprint",
"timestamp": "2026-02-10T14:00:01.000Z",
"result": "trusted",
"confidenceScore": 98,
"visitorFound": true,
"firstSeenAt": 1704067200000,
"lastSeenAt": 1770732001000,
"evidence": [
{
"type": "providerResult",
"ref": {
"$ref": "vault",
"$id": "e8f1b2c3-4d5e-6f7a-8b9c-0d1e2f3a4b5c"
}
}
]
}
DeviceRiskAssessment — not_trusted
{
"provider": "fingerprint",
"timestamp": "2026-02-10T14:00:01.000Z",
"result": "not_trusted",
"confidenceScore": 91,
"visitorFound": true,
"firstSeenAt": 1704067200000,
"lastSeenAt": 1770732001000,
"evidence": [
{
"type": "providerResult",
"ref": {
"$ref": "vault",
"$id": "e8f1b2c3-4d5e-6f7a-8b9c-0d1e2f3a4b5c"
}
}
]
}