glassprint — tell humans from bots and agents
Server-authoritative device intelligence for fraud and risk teams. A spoof-resistant device ID, a typed human / agent / automation verdict, and additive fraud signals — delivered straight into the risk engine you already run. Privacy-respecting and lawful by construction.
A typed verdict, not a bare device ID
Bots are now more than half of web traffic, and AI agents are a new class of their own. glassprint returns a typed verdict for every request — human, declared agent, undeclared automation, or unknown when confidence is too low to label. Built for the agent era, not bolted on after.
Server-generated device ID
The visitorId is computed on the server, never in the browser — so it tolerates drift and resists the spoofing that decays client-only fingerprints in weeks.
Human vs agent
A typed class on every request, with cryptographically declared bots (Web Bot Auth) authenticated but still scored — never blindly trusted.
Feed your engine
Additive Suspect Score and Smart Signals (bot, incognito, tampered, inconsistency) land in your existing decision engine. Land-and-expand, not rip-and-replace.
Spoof-resistant by design
A JA4 network tier behind a validated trust boundary, anti-spoof scoring, and an attestation route when a fingerprint is too common to call.
Honest accuracy
Population-stated rates with confidence intervals, and a plain section on where our bullets stop. No magic "99.5%" number — client collection is forgeable, and we say so.
Lawful by construction
Privacy-respecting by default, with built-in subject-rights handling — so your fraud stack never becomes your compliance problem.
Self-host today, in your own perimeter
glassprint ships as a self-hostable container with Docker, Helm and Terraform, Postgres and Redis adapters, and a vendor-neutral JA4 tier — Cloudflare worker, CloudFront, a self-host Go proxy, or none at all. Your device signals never leave your cloud. A fully managed SaaS and a trained ML linker are on the roadmap; the self-host path and exact-match linking are live and deployable today.
Put a real device signal into your risk engine
Spoof-resistant device intelligence that tells humans from agents — privacy-respecting by construction. Pairs well with noidme.js for in-browser network enforcement.