Use cases
Multi-accounting and ban evasion on gaming platforms
How browser-based games can use a visitor ID to link alt accounts and catch ban evaders, and where fingerprinting stops helping.
TraceTail TeamUpdated 2 min read

If you run a browser-based game, you know the pattern: a player is banned and is back five minutes later with a new account. Or one person runs ten accounts to farm daily rewards, push rankings or abuse referral bonuses. A visitor ID helps because it survives cleared cookies and new accounts. Here's what it can and can't do.
Linking accounts
Identify the browser whenever a player signs up or signs in, and send the visitor ID with the request:
import { TraceTail } from '@tracetail/js';
const tracetail = new TraceTail({ apiKey: 'YOUR_API_KEY', endpoint: 'https://tracetail.io/api' });
const { visitorId } = await tracetail.generateFingerprint();
await fetch('/api/game/session', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ playerId, visitorId }),
});On your server, keep a map from visitor ID to player accounts. One device behind many accounts is the signal.
What it catches:
- Reward farming: one player collecting daily bonuses on ten accounts
- Ranking manipulation: alt accounts boosting a main account or sinking a rival
- Referral abuse: referring yourself for the bonus
Catching ban evasion
When you ban an account, keep its visitor IDs. When a new account appears, check them:
// Your backend
async function banEvasion(visitorId) {
const ban = await db.bannedDevices.findOne({ visitorId });
return ban ? { evading: true, originalReason: ban.reason } : { evading: false };
}This stops the most common evader: someone who clears cookies, makes a new email address and assumes they're invisible.
Limits
- Browser games only. Native desktop or mobile clients need native device signals or dedicated anti-cheat software.
- Shared devices. Families, school computers and gaming cafés legitimately put several players on one browser. Require more than one signal (same device, similar play patterns, overlapping sessions) before acting.
- Determined evaders. Virtual machines and anti-detect browsers can produce a new fingerprint per account. A visitor ID raises the cost of ban evasion from "free" to "some effort", which stops most of it, but not all. With an API key, TraceTail's flag for automated browsers helps with scripted account creation.
- Forged IDs. The visitor ID is computed in the visitor's browser and sent by your own page, so treat it as a strong signal rather than proof: an attacker who controls their browser can send any ID they like, including one they learned from a victim.
Recommendations
- Log before you act. Collect visitor IDs for a few weeks to learn what normal looks like.
- Set sensible thresholds. Two accounts on one device might be siblings; fifteen almost certainly isn't.
- Combine with gameplay data. "Same device" plus "same behavior" is far stronger than either alone.
- Be open about it. Telling players you use device recognition against cheating builds trust and deters casual abuse.
The SDK computes the visitor ID in the player's browser in milliseconds, with no server work on your side. The free allowance of 1,000 requests a month is enough to prototype multi-account detection. Read the docs or try the live demo.
- Gaming
- Multi-accounting
- Ban evasion


