Device fingerprint
Integrate DEUNA's device fingerprint for anti-fraud and payment engines, with version-specific behavior for Web SDK / Cross-domain.
Integrate DEUNA's device fingerprint for anti-fraud and payment engines in your application.
You must generate your own fingerprints for most engines.
DEUNA offers a script / SDK that creates all necessary fingerprints to avoid manual tasks for each fingerprint script.
Integrates the device fingerprint of anti-fraud and payment engines.
Version behaviorCredential handling depends on your SDK version.
- Web SDK < 1.6 / Cross-domain < 1.2: the merchant sends
fraudCredentials(current behavior). Follow Section A.- Web SDK ≥ 1.6 / Cross-domain ≥ 1.2: the DEUNA team configures the credentials. The merchant no longer sends them. Follow Section B. SIGNIFYD exception: SIGNIFYD still needs the
generateFraudId.
Web SDK < 1.6
This section describes the current, published behavior. Use it if you run Web SDK below 1.6 or Cross-domain below 1.2.
1. Add the Mercado Pago script
This script automatically loads everything needed to create the Device Fingerprint, which is sent when processing with Mercado Pago or whatever the anti-fraud or payment engine is.
Mercado Pago and other providers require this information to secure the transaction.
window.DEUNA_CREDENTIALS = {
<provider name>: {},
}
// example
window.DEUNA_CREDENTIALS = {
MERCADOPAGO: {},
}
Without the script, your transaction is more likely to be rejected. Mercado Pago uses this identifier to ensure your transaction isn't fraudulent..
2. Select the suppliers (only needed for Web SDK < 1.6)
Select anti-fraud engine providers.
Refer to Global suppliers and to Anti-fraud engines for the entire offering list.
The following table contains attributes for the engines supported by the widget:
| Engine | Attributes | Example |
|---|---|---|
| BAZ | orgId, merchantId | BAZ: { orgId: '', merchantId: '' } |
| CLEARSALE / CLEARSALE-BRASIL | ClientId | CLEARSALE: { clientId: '' } CLEARSALE-BRASIL: { clientId: '' } |
| CYBERSOURCE | orgId, merchantId | CYBERSOURCE: { orgId: '', merchantId: '' } |
| MERCADOPAGO | Does not require parameters at the merchant_id level | MERCADOPAGO: {} |
| SIFT | accountId, restApiKey | SIFT: { accountId: '', restApiKey: '' } |
| SIGNIFYD | Account and Email: Required for all implementations. Session ID is only required if your merchant system generates the sessionId before DEUNA. This usually applies when you send events directly to Signifyd and need the events sent by DEUNA to be matched to the same Signifyd session. In this case, you must send the same sessionId to DEUNA so that all events can be properly linked in Signifyd. If you do not generate a sessionId or do not send events directly to Signifyd, you do not need to generate or send this field to DEUNA.s Org ID is required for native apps implementation. This requirement difference from Web comes from Signifyd and NOT from DEUNA. The reason Signifyd mentions is: The orgId is required for the mobile SDK because, unlike web—where the TMX script automatically associates the session with the Signifyd account through the JavaScript snippet—the mobile SDK needs it to be configured in order to correctly link the device fingerprint to the corresponding account. | SIGNIFYD: {account: '', email: '', sessionId: '', orgId: '<needed for native apps>} |
| STRIPE | API_KEY | STRIPE: { apiKey: '' } |
| RISKIFIED | storeDomain | RISKIFIED: { storeDomain: '' } |
| ACCERTIFY | src, collectorHostSrc, sid, id, dvc | ACCERTIFY: { src: '', collectorHostSrc: '', sid: '', id: '', dvc: '' } |
| KOUNT | clientId, environment, isSinglePageApp | KOUNT: { clientId: '', environment: '', isSinglePageApp: ''}, |
| KOIN | orgId | KOIN: { orgId: ''} |
| PAYU | Does not require parameters at the merchant_id level | PAYU: {} |
3. Generate the fingerprints
Generate fingerprints depending on your integration type.
3.1 DEUNA Payment widget
See for example the web SDK for the initPaymentWidget here.

3.2 Direct API
Add the fingerprint script.
The script includes a DEUNA SDK that is capable of generating fingerprints from any provider under a single integration.
Web SDK
- Follow the steps to add and initialize the Web SDK.
- Use the script to generate the fingerprint.
<script>
var script = document.createElement("script");
script.id = "deuna-sdk";
script.src = "{{use latest Web SDK version: https://docs.deuna.com/reference/first-steps-web}}";
script.onload = async function () { // ✅ Make function async
// Initialize the SDK
await DeunaSDK.initialize({
publicApiKey: "<public api key>",
env: "sandbox" // "sandbox" or "production"
});
// Get the MasterDeviceId from DEUNA
const fraudId = await DeunaSDK.generateFraudId({
someProvider: { // ✅ Replace with actual provider name
// provider-specific data
}
});
console.log("Fraud ID:", fraudId);
};
document.body.appendChild(script);
</script>iOS SDK
- Follow the steps to add and initialize the DEUNA SDK.
- Use the function
generateFraudIdto generate the fingerprint.
deunaSDK.generateFraudId(
params: [
"RISKIFIED": [
"storeDomain": "volaris.com"
]
]
) { fraudId in
}Android SDK
- Follow the steps to add and initialize the DEUNA SDK.
- Use the function
generateFraudIdto generate the fingerprint.
deunaSDK.generateFraudId(
context = context,
params = mapOf(
"RISKIFIED" to mapOf(
"storeDomain" to "deuna.com"
)
),
callback = { fraudId ->
}
)- Get the value of the device fingerprint and send it through the Payments API.
- For V1 Purchase:
{
"token": "e4caabfb-3ed5-4930-a4fc-dd6e4812bd03", // order token
"email": "john.doe@gmail",
"method_type": "credit_card",
...
// mandar el fingerprint como base64
"device_id": "<device fingerprint generated by the DEUNA Fraud SDK>",
...
}- ForV2 Purchase:
{
"payer_info": {
"email": "[email protected]",
"card_holder_dni": "12345678"
},
"payment_source": {
"method_type": "debit_card",
"card_info": {
"card_id": "<card id>"
}
},
"order": {
"order_id": "DEUNA-NOW-69553619",
// ...
},
"anti_fraud_info": { // dentro de este objeto se manda el fingerprint
"device": {
// mandar el fingerprint como base64
"id": "<device fingerprint generated by the DEUNA Fraud SDK>"
}
}
}3.3 VTEX Connector
See this section: https://docs.deuna.com/docs/vtex-device-fingerprin
Web SDK ≥ 1.6
Use this section if you run Web SDK 1.6 or later.
In these versions, the DEUNA team configures the anti-fraud credentials. This changes the integration in three ways:
- You do not add the Mercado Pago script. The
window.DEUNA_CREDENTIALSobject is no longer required. - You do not use the DEUNA Payment widget fingerprint step. It is no longer necessary.
- The merchant no longer sends
fraudCredentials. DEUNA sets these values for you.
SIGNIFYD exception
SIGNIFYD is the one provider that still needs merchant input in these versions. The merchant must pass the email from the user session in generateFraudId.
Initialization script
Add and initialize the SDK. In these versions you call generateFraudId without merchant-supplied credentials:
<script>
var script = document.createElement("script");
script.id = "deuna-sdk";
script.src = "{{use latest Web SDK version: https://docs.deuna.com/reference/first-steps-web}}";
script.onload = async function () { // ✅ Make function async
await DeunaSDK.initialize({
publicApiKey: "<public api key>",
env: "sandbox" // "sandbox" or "production"
});
const fraudId = await DeunaSDK.generateFraudId();
console.log("Fraud ID:", fraudId);
};
document.body.appendChild(script);
</script>SIGNIFYD snippet (≥ 1.6)
For SIGNIFYD, pass the email from the user session:
const fraudId = await DeunaSDK.generateFraudId({
SIGNIFYD: { email: "<email from user session>" }
});Updated 15 days ago