Tell humans from agents — and prove how
glassprint is server-authoritative device intelligence: the browser collects behind a fail-closed consent gate, and the server mints the verdict. Start with the architecture, then read the verdict and signal references, wire it into your risk flows, and self-host it inside your own perimeter.
How it works
Architecture
Archetype B: the browser collects behind a fail-closed consent gate, the server identifies. The visitorId is server-generated — salted-HMAC, epoch-rotated, and tenant-bound.
OpenThe verdict
A typed four-class result — human, declared_agent, undeclared_automation, unknown — with a confidence floor that refuses to guess, the two-tells rule, farble suppression, and Web Bot Auth.
OpenSignals
The nine client probes, the JA4 server tier, and the SmartSignals dictionary {bot, incognito, tampered, inconsistency} plus suspectScore — additive data, not a verdict to act on blindly.
OpenRun it yourself
deviceId field is present but always null today.Server-authoritative, consent-native, honest
A spoof-resistant visitorId, a typed human/agent/automation verdict, and additive fraud signals — built so it can't run without consent.