Skip to the operations

Fraud prevention

Fingerprint in a decision flow.

2 Fingerprint operations a decision flow can call directly, with the credentials your own contract issued. The response is data the rest of the flow reads, branches on, and keeps in the trace.

Category
Fraud prevention
Type
Integration
Authentication
API key
Test environment
Production host only

Who they are

Device identification that survives cleared cookies.

Fingerprint identifies the device behind a request — the same browser or app returning under a new account, a fresh cookie or a private window. It grew out of the open-source FingerprintJS library and now sells a commercial identification service with a server API for confirming what the browser reported. It is used for account takeover and multi-account abuse rather than for credit assessment.

What a flow can call

2 operations, each one a step you can place on the canvas.

  1. GET/v4/events/$data.fingerprint_event_id

    Read device-intelligence event

    Retrieves the full server-side event emitted by the Fingerprint client agent.

  2. PATCH/v4/events/$data.fingerprint_event_id

    Flag a device event as suspicious

    Adds a stable application link, tags, or a suspicious flag after a human review.

Where it sits in the decision

Fraud prevention calls have a natural place in a flow.

Device and behavioural signals are contested rather than assessed — the applicant is actively trying to affect the answer. They are cheap enough to call on every event and most useful combined with history, so they usually sit alongside an entity read rather than on their own.

Whatever Fingerprint returns is part of the run, so it is part of the record. When someone asks months later why an applicant was declined, the answer cites what came back at the time rather than re-fetching from a service whose answer has since changed.

  • 01Add Fingerprint as a connection authenticating with an API key.
  • 02Fingerprint has one host for both environments, so guard test runs with your own credentials and limits.
  • 03Place a Connection node and pick an operation — “Read device-intelligence event” is usually the first one a flow needs.
  • 04Map the response into the fields your rules read, then test the whole path before it carries live traffic.

Common questions

Using Fingerprint in a flow.

How do I connect Fingerprint to a decision flow?

Add Fingerprint as a connection in your workspace authenticating with an API key, with the credentials your own contract issued — ArboRule calls the provider as you, and never holds a contract on your behalf. Once the connection exists, any flow in the workspace can place a Connection node and choose one of its operations. The credentials live on the connection, not in the flow, so a policy owner can use Fingerprint in a decision without ever seeing the secret.

Can I test Fingerprint without touching production?

Fingerprint exposes one host for both environments, so there is no separate sandbox to point at. Test runs still execute in Sandbox and are recorded separately in decision history, but the call goes to the same place as production — so guard it with your own test credentials, rate limits, or data.

What can a flow call on Fingerprint?

2 operations: “Read device-intelligence event”, “Flag a device event as suspicious”. Each one is a step you place on the canvas and map into the fields your rules read, and most flows start with “Read device-intelligence event”. The list comes from the same manifest the engine uses to make the call, so this page cannot describe an operation the product does not have.

Where in a decision should Fingerprint be called?

Device and behavioural signals are contested rather than assessed — the applicant is actively trying to affect the answer. They are cheap enough to call on every event and most useful combined with history, so they usually sit alongside an entity read rather than on their own.

Ready when you are

Wire Fingerprint into a real decision.

Build the flow in Sandbox, connect your account, and watch the decision pull what it needs before it answers.

Read the docs