Identify the device.Get the verdict in the same call.
One verify call returns the device id, the integrity findings behind it and the decision on the request. Hosted in Germany, priced in public.
120,000 calls a month: €119, not $499
A per-call meter bills the bot traffic at the same rate as the real customers.
- 20,000a month$99Pro Plus base€29Scout, 30,000 included
- 30,000a month$139$99 plus 10 × $4€29Scout, still inside the plan
- 120,000a month$499$99 plus 100 × $4€119Scale, 120,000 included
- device id
- device history
- integrity findings
- network class
- 23 flags
- risk score
- reason codes
- verdict
A signal bundle is not a decision
POST /verify- action
- BLOCK
- risk.score
- 88 / 100
- risk.level
- critical
- risk.reason_codes
- 4 returned
One field decides the request. The signals behind it ride in the same response when you want to score them yourself.
A fresh fingerprint is what an anti-detect browser sells
Eight integrity checks come back on every call, so a new id arrives with the reasons to distrust it.
- Anti-detect engineintegrity.anti_detect_browser34
- Platform mismatchintegrity.platform_mismatch22
- Runtime patchedintegrity.runtime_patched18
- Interception patternintegrity.tampered14
- Automation driver
- Virtual machine
- Privacy tooling
- Rendering anomaly
Nothing to deploy at the edge
import { useTrustSig } from "@trustsig/react";
const { getResponse } = useTrustSig();
const { token } = await getResponse();import { TrustSig } from '@trustsig/server';
const ts = new TrustSig({ secretKey: process.env.TRUSTSIG_SECRET_KEY });
app.post('/login', async (req, res) => {
const token = req.headers['x-trustsig-response'];
const { action, identity } = await ts.verifyRemote(token);
// Fail closed: proceed only on an explicit ALLOW.
if (action !== 'ALLOW') {
return res.status(403).json({ error: 'Access denied.' });
}
// degraded marks an id a large cohort shares, so it names a crowd.
if (identity.degraded) {
return completeLogin(req, res);
}
// Your table, keyed on the id the verdict carries.
await devices.bind(req.body.email, identity.device_id, {
first_seen: identity.first_seen,
sightings: identity.sightings,
});
return completeLogin(req, res);
});What a switch costs you
Fingerprint publishes $99 a month for 20,000 API calls, then $4 per 1,000. At 120,000 calls that is $499, against €119 a month on TrustSig Scale with 120,000 requests included. Both are list prices, Fingerprint's as published on 13 August 2026.
No. The verify response carries action, risk.score, risk.level and risk.reason_codes, so a single field decides the request. The raw signals are in the same response if you would rather score them yourself.
The response says so. Eight integrity checks and 23 flags come back on every call, naming the anti-detect engine, the patched runtime and the platform mismatch rather than handing you a fresh id and moving on.
No. Every plan runs the same engine, and the free tier returns the same verdict, score, flags and findings. Scout adds confidence scoring and verified bot detection on top.
Only in Germany. Nothing is written to the visitor's device. Every device id is scoped to one project, so the same machine returns a different id to every customer.
One script tag or one npm package on the client, and one verifyRemote call on the server. Nothing at the edge and no infrastructure change.
Put a verdict on your next request.
23 flags, and a reason code for each one that fires.