A device fingerprint is an identifier computed from the characteristics of a browser or device, such as how it renders graphics, which features it supports and how it is configured, so that the same device can be recognised again without a cookie.
Fraud teams use fingerprints to link several accounts to one device, spot repeat sign-ups and recognise returning customers. Unlike a cookie, a fingerprint works without storing anything the user can easily see or delete.
Is a device fingerprint the same as bot detection?
No. A fingerprint answers “have I seen this device before?” Bot detection answers “is a person driving this browser?” A bot can have a perfectly stable fingerprint, and thousands of real people can share the fingerprint of one popular phone model.
How Hextner uses it
DetectBT is bot detection. It reads browser characteristics, including some that fingerprinting also uses, to judge automation, and returns no visitor or device ID to you. It keeps a non-extractable, per-site device key in IndexedDB (with a signed device certificate in localStorage) that signs each evaluation, so a returning browser is recognised on your site only. Clearing the site's data deletes both, and they cannot link visitors across sites. A consent gate (data-consent="false" on the script tag) holds collection until you call DetectBT.grantConsent(). See the DetectBT reference.
Related reading
Browse every definition in the glossary.