# TraceTail > TraceTail is a browser fingerprinting API for recognizing returning visitors without cookies. Its JavaScript SDK (a script tag or the npm package @tracetail/js) turns 40+ browser signals into a stable visitor ID with over 99.5% accuracy, the same in normal and incognito windows. It works without an API key for a quick start; with a key, every identification is registered with the API, checked for automation and shown in a dashboard. 1,000 identification requests are free every month, then $0.10 per 1,000. Use it to recognize a browser or device across visits without storing anything in it: stopping free-trial and promo abuse, linking multiple accounts, flagging account takeover and unfamiliar sign-in devices, checking payments for fraud, metering paywalls, and spotting automated browsers (headless Chrome, WebDriver). It runs in any browser-based app: plain HTML, React, Next.js, Vue, Nuxt, Angular, Svelte and the rest. ## Quick start for AI coding agents No sign-up is needed to get a visitor ID. Add this before ``: ```html ``` With a bundler, `npm install @tracetail/js` (React, Vue and Angular use the same package): ```ts import { TraceTail } from '@tracetail/js'; const tracetail = new TraceTail({ apiKey: 'YOUR_API_KEY', endpoint: 'https://tracetail.io/api' }); const { visitorId } = await tracetail.generateFingerprint(); ``` Until there is an API key, leave out `data-api-key` (or `apiKey`): the SDK then runs keyless. To register identifications (usage, dashboard, `requestId`, bot check), get keys with a setup link: `POST https://tracetail.io/api/v1/setup-links` with `{"domains": ["example.com", "localhost"], "serverKey": true}`, give the person the `setupUrl` it returns (they sign in with an emailed code, then add a card or continue without a card), then check `GET https://tracetail.io/api/v1/setup-links/{id}` with `Authorization: Bearer {token}` every few seconds: the first check after they finish returns an API key for each site, to put in place of `YOUR_API_KEY`, and, for an account the link created, the server key, once. Keys are public by design: they ship in page HTML and only work on their own domain (and its subdomains), so a key belongs in frontend code. People can also sign up at https://tracetail.io/auth and create keys under Settings → API keys. Before trusting a visitor ID for a sign-up, login or payment, verify it on the server: send the `requestId` the browser got to `GET https://tracetail.io/api/v1/identifications/{requestId}` with a secret server key (`Authorization: Bearer tts_…`, created in Settings → API keys) and check that `visitorId` matches. ## For AI agents - MCP server: https://tracetail.io/mcp (Streamable HTTP, no authentication). Tools: integration code for any framework, documentation search, pricing, and setup links that get the API keys. Claude Code: `claude mcp add --transport http tracetail https://tracetail.io/mcp` - Agent skill: `npx skills add https://tracetail.io` (https://tracetail.io/.well-known/agent-skills/index.json) - OpenAPI: https://tracetail.io/openapi.json - Every page as Markdown: add .md to its URL, or request it with `Accept: text/markdown`. ## Facts - Pricing: 1,000 identification requests free every month (UTC), no credit card required; then $0.10 per 1,000 requests, the same rate at every volume. Keyless use and failed requests are free. - Accuracy: over 99.5%. The visitor ID (`fp3_` followed by 16 hex characters) is the same in normal and incognito windows, and adding an API key never changes it. - SDK: under 10 KB gzipped. It collects nothing until `generateFingerprint()` is called, so it can wait for consent. - API: the SDK calls `POST https://tracetail.io/api/id` (or `/id/detail` for the risk assessment); errors are JSON `{ error, code }`. - Rate limits: 100 requests a second per API key and 600 a minute per IP address (429 RATE_LIMITED with Retry-After). - First-party setup: the SDK and API can be served from a path on your own site (one click on Cloudflare), so blockers that filter by domain never see TraceTail. - Data: the visitor ID, signals, IP address and user agent are kept until 180 days after a visitor's last visit, and request logs for 90 days. A visitor can be erased from the dashboard or with `DELETE /api/visitors/:visitorId`. - Support: support@tracetail.io ## Docs - [Documentation](https://tracetail.io/docs.md): quick start, keys and domains, install (script tag, npm, React, Next.js, Vue, Nuxt, Angular, Svelte), AI coding agents, first-party setup, SDK reference, REST API, Server API, privacy, troubleshooting and migrating from FingerprintJS. - [Everything in one file](https://tracetail.io/llms-full.txt): the documentation, pricing and comparison pages. - [Pricing](https://tracetail.io/pricing.md): 1,000 identification requests free every month, no credit card required. Then $0.10 per 1,000 requests, the same rate at every volume. - [TraceTail vs FingerprintJS — pricing and features compared](https://tracetail.io/vs-fingerprintjs.md): TraceTail and Fingerprint, the company behind FingerprintJS, compared on price, free allowance, rate limits and platforms, using Fingerprint's published pricing as of October 4, 2026. - [FingerprintJS alternatives compared: TraceTail, Fingerprint, ThumbmarkJS and ClientJS](https://tracetail.io/fingerprintjs-alternatives.md): Browser fingerprinting libraries and APIs compared on price at 10,000 to 1 million requests a month, free tiers, licenses and server-side verification, from each vendor's published pages as of October 5, 2026. ## Blog - [How browser fingerprinting works: a developer's guide](https://tracetail.io/blog/how-browser-fingerprinting-works.md): Canvas, WebGL, fonts and the other browser traits behind a fingerprint: what each one measures, why it differs between devices, and how TraceTail turns them into a visitor ID. - [TraceTail vs FingerprintJS: pricing, limits and features compared](https://tracetail.io/blog/tracetail-vs-fingerprintjs.md): How TraceTail compares with Fingerprint, the company behind FingerprintJS, on price, free allowance, rate limits, platforms and data retention, using Fingerprint's published pricing. - [Detecting bots without cookies](https://tracetail.io/blog/detecting-bots-without-cookies.md): How headless browsers and automation frameworks give themselves away, which checks are worth running, and how to combine them with a visitor ID. - [Inside a TraceTail fingerprint: every signal explained](https://tracetail.io/blog/browser-fingerprint-signals-explained.md): The 45 measurements TraceTail's browser SDK takes, grouped into five families: what each one contributes, how they become a visitor ID, and what TraceTail deliberately leaves out. - [What happens when cookies die? Fingerprinting in a privacy-first web](https://tracetail.io/blog/fingerprinting-without-cookies.md): Safari, Firefox and Chrome have each limited cookies in their own way. Where that leaves visitor identification, and where fingerprinting fits. - [Browser fingerprinting and the GDPR: what the law requires](https://tracetail.io/blog/gdpr-compliant-fingerprinting.md): ePrivacy consent, GDPR legal bases, data minimization, retention and erasure: a practical guide for teams adding fingerprinting in the EU. Not legal advice. - [Browser fingerprinting research: what recent papers found](https://tracetail.io/blog/browser-fingerprinting-research-2024-2025.md): What three studies (FP-Inspector, FPTrace and a 2024 review of fingerprinting and privacy) found, and what they mean for teams that rely on fingerprinting. - [Fraud prevention in financial services with browser fingerprinting](https://tracetail.io/blog/banking-fraud-prevention.md): Spot account takeover and credential stuffing by checking which device is signing in, with code for the login flow and a clear look at the limits. - [The future of browser fingerprinting](https://tracetail.io/blog/future-browser-fingerprinting.md): Browser defenses, privacy law and automation are reshaping device identification. What's changing, and what it means for teams that rely on it. - [E-commerce fraud detection with device fingerprinting](https://tracetail.io/blog/ecommerce-fraud-prevention.md): Use a visitor ID to catch promo abuse, card testing, multi-accounting and account takeover in an online store: patterns, thresholds and code. - [Defeating sophisticated fraud: layering device, behavior and network signals](https://tracetail.io/blog/defeating-sophisticated-fraud.md): Why no single signal stops determined fraudsters, and how to layer a device ID, behavioral checks and network context into graduated responses. - [Multi-accounting and ban evasion on gaming platforms](https://tracetail.io/blog/gaming-platform-security.md): How browser-based games can use a visitor ID to link alt accounts and catch ban evaders, and where fingerprinting stops helping. - [Privacy-first fingerprinting: balancing security and user rights](https://tracetail.io/blog/privacy-first-fingerprinting.md): Collect less, say what you do, keep data for a limited time and honor deletion requests: practical habits for using fingerprinting responsibly. - [Protecting travel bookings with device recognition](https://tracetail.io/blog/travel-hospitality-fraud-prevention.md): Loyalty-point farming, booking fraud with stolen cards and price-scraping bots: how travel sites can use a visitor ID against each. - [Building resilient authentication: device recognition beyond passwords](https://tracetail.io/blog/resilient-authentication.md): Use a visitor ID to tell known devices from new ones at sign-in, add friction only when the risk is real, and know where the signal stops. ## Optional - [TraceTail — Browser fingerprinting API with over 99.5% accuracy](https://tracetail.io/index.md): Identify returning visitors without cookies. TraceTail turns 40+ browser signals into a stable visitor ID, the same in normal and incognito windows. 1,000 requests free every month. - [Live demo](https://tracetail.io/live-demo.md): See the visitor ID TraceTail computes for your browser and every signal behind it. No sign-up needed. - [Blog](https://tracetail.io/blog.md): Guides and analysis on browser fingerprinting, bot detection, privacy law and fraud prevention from the TraceTail team. - [System status](https://tracetail.io/status.md): Live health of the TraceTail API and incidents from the last 90 days. - [Contact](https://tracetail.io/contact.md): Questions about integrating TraceTail, billing or privacy? Email support@tracetail.io. - [Privacy Policy](https://tracetail.io/privacy-policy.md): What TraceTail collects on this website and through its API, why, who processes it, how long it's kept and how to exercise your rights. - [Terms of Service](https://tracetail.io/terms-and-conditions.md): The terms that govern your use of TraceTail's website, API and browser SDK.