Guides
Inside a TraceTail fingerprint: every signal explained
The 45 measurements TraceTail's browser SDK takes, grouped into five families: what each one contributes, how they become a visitor ID, and what TraceTail deliberately leaves out.
TraceTail TeamUpdated 3 min read

When TraceTail's browser SDK identifies a visitor, it takes 45 measurements in five groups, hashes them, and returns a visitor ID. This post lists every one of them, explains what each contributes, and covers what the SDK deliberately leaves out.
The full list
| Group | What's measured | Values |
|---|---|---|
| Browser and system | Browser family, operating system family, language, platform, whether cookies are enabled, time zone | 6 |
| Screen | Long side, short side, color depth | 3 |
| Hardware | CPU cores, touch points, device memory | 3 |
| Canvas | Pixel sums from four regions of a reference drawing | 4 |
| WebGL | Vendor, renderer, version, unmasked vendor, unmasked renderer | 5 |
| Fonts | Whether each of 24 common fonts is installed | 24 |
That's 45 values, which is why we describe TraceTail as using 40+ browser signals.
Browser and system
The browser and operating system are read from the user agent as families (Chrome, Safari, Firefox, Edge; Windows, macOS, iOS, Android, Linux, ChromeOS) without version numbers, so a browser update doesn't change the visitor ID. Language, platform, the cookie setting and the IANA time zone (for example Europe/Lisbon) add more distinguishing detail at almost no cost.
Screen
The screen is recorded as its long side and short side rather than width and height, so turning a phone from portrait to landscape doesn't change the ID. Color depth separates otherwise similar displays.
Hardware
The number of logical CPU cores, the maximum number of touch points and the approximate device memory describe the machine itself. Device memory is only exposed by Chromium-based browsers; in other browsers it's recorded as unavailable.
Canvas
The SDK draws a fixed 256×256 scene (text in two fonts, gradients, emoji, curves, shadows and blend modes) and sums the pixels in four regions of the result. Graphics hardware, drivers and font rendering all leave small marks on those pixels, which makes this one of the most distinctive signals there is.
WebGL
WebGL reports the graphics vendor and renderer. Where the browser allows it, the unmasked strings name the actual GPU, such as "ANGLE (Apple, Apple M1 Pro, OpenGL 4.1)".
Fonts
The SDK checks for 24 widely installed fonts, such as Arial, Calibri, Helvetica and Menlo, by measuring how text renders in each one compared with a fallback font. Which of them are present differs between operating systems and between people who install their own fonts.
From signals to a visitor ID
The values are serialized with their keys in a fixed order, hashed with SHA-256, and the first 16 hex characters become the ID, prefixed with fp3_. The ID is the same whether or not you use an API key, so switching from a keyless trial to a keyed integration doesn't change anyone's ID.
The result also includes a confidence between 0 and 1 that reflects how many of the most distinctive signals were available: it's 0.99 when canvas, WebGL and fonts all are.
You can see all of this for your own browser on the live demo, or in code:
import { TraceTail } from '@tracetail/js';
const tracetail = new TraceTail(); // keyless: computed in the browser, nothing is sent
const { visitorId, components } = await tracetail.generateFingerprint({ verbose: true });
console.log(visitorId); // "fp3_…"
console.log(components.basic.timezone); // e.g. "Europe/Lisbon"What TraceTail doesn't collect
- No cookies or local storage. Nothing is written to the visitor's device.
- No behavior. There are no mouse, keyboard or scroll listeners.
- No audio, plugin, battery or WebRTC probing.
The SDK also reads one flag that is not part of the ID: whether the browser reports itself as automated (navigator.webdriver). With an API key, TraceTail uses it to flag automated browsers such as headless Chrome and WebDriver.
Where the signals go
Without an API key, the SDK computes the visitor ID in the browser and sends nothing to TraceTail. With an API key, TraceTail stores each visitor ID together with the browser signals the SDK collected, the IP address and the user agent, until 180 days after that visitor's last visit. You can erase a visitor at any time from Settings in your dashboard, or with DELETE /api/visitors/:visitorId while signed in.
Limits
- Identical devices can share an ID. Two phones of the same model with the same settings can produce the same 45 values.
- Hardware and driver changes can change the ID. A new GPU driver or a major operating system update can alter canvas and WebGL output.
- Some browsers resist fingerprinting on purpose. Brave, and Firefox with
privacy.resistFingerprintingenabled, vary or flatten some of these values, which can change the ID between sessions.
Learn more
- How browser fingerprinting works: the techniques in depth
- Documentation: integration guides and the API reference
- Signals
- Browser fingerprinting
- SDK

