Skip to content
Blog

Guides

Inside a TraceTail fingerprint: every signal explained

The 45 measurements TraceTail's browser SDK takes, grouped into five families: what each one contributes, how they become a visitor ID, and what TraceTail deliberately leaves out.

TraceTail TeamUpdated 3 min read

When TraceTail's browser SDK identifies a visitor, it takes 45 measurements in five groups, hashes them, and returns a visitor ID. This post lists every one of them, explains what each contributes, and covers what the SDK deliberately leaves out.

The full list

GroupWhat's measuredValues
Browser and systemBrowser family, operating system family, language, platform, whether cookies are enabled, time zone6
ScreenLong side, short side, color depth3
HardwareCPU cores, touch points, device memory3
CanvasPixel sums from four regions of a reference drawing4
WebGLVendor, renderer, version, unmasked vendor, unmasked renderer5
FontsWhether each of 24 common fonts is installed24

That's 45 values, which is why we describe TraceTail as using 40+ browser signals.

Browser and system

The browser and operating system are read from the user agent as families (Chrome, Safari, Firefox, Edge; Windows, macOS, iOS, Android, Linux, ChromeOS) without version numbers, so a browser update doesn't change the visitor ID. Language, platform, the cookie setting and the IANA time zone (for example Europe/Lisbon) add more distinguishing detail at almost no cost.

Screen

The screen is recorded as its long side and short side rather than width and height, so turning a phone from portrait to landscape doesn't change the ID. Color depth separates otherwise similar displays.

Hardware

The number of logical CPU cores, the maximum number of touch points and the approximate device memory describe the machine itself. Device memory is only exposed by Chromium-based browsers; in other browsers it's recorded as unavailable.

Canvas

The SDK draws a fixed 256×256 scene (text in two fonts, gradients, emoji, curves, shadows and blend modes) and sums the pixels in four regions of the result. Graphics hardware, drivers and font rendering all leave small marks on those pixels, which makes this one of the most distinctive signals there is.

WebGL

WebGL reports the graphics vendor and renderer. Where the browser allows it, the unmasked strings name the actual GPU, such as "ANGLE (Apple, Apple M1 Pro, OpenGL 4.1)".

Fonts

The SDK checks for 24 widely installed fonts, such as Arial, Calibri, Helvetica and Menlo, by measuring how text renders in each one compared with a fallback font. Which of them are present differs between operating systems and between people who install their own fonts.

From signals to a visitor ID

The values are serialized with their keys in a fixed order, hashed with SHA-256, and the first 16 hex characters become the ID, prefixed with fp3_. The ID is the same whether or not you use an API key, so switching from a keyless trial to a keyed integration doesn't change anyone's ID.

The result also includes a confidence between 0 and 1 that reflects how many of the most distinctive signals were available: it's 0.99 when canvas, WebGL and fonts all are.

You can see all of this for your own browser on the live demo, or in code:

import { TraceTail } from '@tracetail/js';

const tracetail = new TraceTail(); // keyless: computed in the browser, nothing is sent
const { visitorId, components } = await tracetail.generateFingerprint({ verbose: true });

console.log(visitorId);                 // "fp3_…"
console.log(components.basic.timezone); // e.g. "Europe/Lisbon"

What TraceTail doesn't collect

  • No cookies or local storage. Nothing is written to the visitor's device.
  • No behavior. There are no mouse, keyboard or scroll listeners.
  • No audio, plugin, battery or WebRTC probing.

The SDK also reads one flag that is not part of the ID: whether the browser reports itself as automated (navigator.webdriver). With an API key, TraceTail uses it to flag automated browsers such as headless Chrome and WebDriver.

Where the signals go

Without an API key, the SDK computes the visitor ID in the browser and sends nothing to TraceTail. With an API key, TraceTail stores each visitor ID together with the browser signals the SDK collected, the IP address and the user agent, until 180 days after that visitor's last visit. You can erase a visitor at any time from Settings in your dashboard, or with DELETE /api/visitors/:visitorId while signed in.

Limits

  • Identical devices can share an ID. Two phones of the same model with the same settings can produce the same 45 values.
  • Hardware and driver changes can change the ID. A new GPU driver or a major operating system update can alter canvas and WebGL output.
  • Some browsers resist fingerprinting on purpose. Brave, and Firefox with privacy.resistFingerprinting enabled, vary or flatten some of these values, which can change the ID between sessions.

Learn more

  • Signals
  • Browser fingerprinting
  • SDK

Guides · 4 min read

How browser fingerprinting works: a developer's guide

Canvas, WebGL, fonts and the other browser traits behind a fingerprint: what each one measures, why it differs between devices, and how TraceTail turns them into a visitor ID.

Guides · 3 min read

Detecting bots without cookies

How headless browsers and automation frameworks give themselves away, which checks are worth running, and how to combine them with a visitor ID.

Start identifying visitors today

1,000 requests free every month, no credit card required. Add a card only when you need more.