← FingerprintCONTENT HISTORY

Update to Fingerprint

Snapshot Sep 30, 2026 · 23:11 UTC · version 1.0.0

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "name": "fingerprint-python",
  "description": "Integrate the Fingerprint Server API into a Python backend (FastAPI / Django / Flask) — fetch an event by event_id and read the verified identification and Smart Signals.",
  "included_files": [
    {
      "relative_path": "skill.json",
      "size_in_bytes": 278
    },
    {
      "relative_path": "snippets/client.py",
      "size_in_bytes": 697
    },
    {
      "relative_path": "snippets/verify.py",
      "size_in_bytes": 2213
    }
  ],
  "skill_md_contents": "---\nname: fingerprint-python\ndescription: Integrate the Fingerprint Server API into a Python backend (FastAPI / Django / Flask) — fetch an event by event_id and read the verified identification and Smart Signals.\n---\n\n# Fingerprint — Python (Server API)\n\nIntegrate the Fingerprint Server API into a Python backend: take the single-use `event_id` your\nfrontend sends, fetch the event server-side, and read the verified identification and Smart\nSignals. The server is the source of truth — never trust a `visitor_id` or a decision sent straight\nfrom the client.\n\n> Docs: https://docs.fingerprint.com/reference/python-server-sdk · event schema: OpenAPI (https://github.com/fingerprintjs/fingerprint-pro-server-api-openapi) or the Fingerprint MCP event-schema resource.\n\n## Package\n`fingerprint-server-sdk` — install the latest version.\n\n## Env var\n- `FINGERPRINT_SECRET_API_KEY` — the secret key. Server-side only; never sent to the browser.\n\n> Load `.env` with `python-dotenv` (`load_dotenv()`) and read the key via `os.environ`. Keep the\n> secret key out of any client bundle, logs, or version control.\n\n## Steps\n\n1. **Install** `fingerprint-server-sdk`.\n\n2. **Create one client** at startup with the secret key and region (`Region.US` | `Region.EU`\n   | `Region.AP`, matching the workspace). Call `load_dotenv()` before the key is read — Python\n   does not auto-load `.env`. See `snippets/client.py`.\n\n3. **Fetch and check the event.** Given the `event_id`, call `client.get_event(event_id)` and apply\n   the checks below before trusting the action. See `snippets/verify.py`.\n\n## v4 event shape (flat — per the Server API event schema)\n`get_event` returns the event object directly:\n- `event.identification.visitor_id` — the trusted visitor id\n- `event.identification.confidence.score` — 0..1 (probability of a false-positive identification)\n- `event.timestamp` — Unix ms of the event (root-level, **not** under `identification`)\n- `event.replayed` — `True` if the payload was replayed (root-level)\n- `event.bot` — `BotResult.NOT_DETECTED` | `good` | `bad`\n- `event.vpn`, `event.proxy`, `event.tampering`, `event.incognito` — booleans\n- `event.suspect_score` — weighted Smart-Signals score (integer)\n- `event.velocity` (object), `event.ip_blocklist` (object: `attack_source`, `email_spam`,\n  `tor_node`)\n\n## Checks (do all of them)\n- **Found:** `event.identification.visitor_id` exists.\n- **Replay / freshness:** reject if `event.replayed` is `True`, or if `event.timestamp` is older\n  than your window (e.g. 2 minutes) — prevents reuse of an old `event_id`.\n- **Confidence:** require `event.identification.confidence.score >= 0.9` for the action.\n- **Smart Signals** (fail-closed for high-risk actions): `event.bot != BotResult.NOT_DETECTED`,\n  `event.vpn`, `event.proxy`, `event.tampering`.\n- **Identity match:** bind `visitor_id` ↔ user on first trusted use; re-check on later actions.\n\n## Notes\n- Fetch and check server-side on **every** sensitive action.\n- Fail closed on lookup errors for high-risk flows.\n- Each `event_id` is single-use per action — don't cache a pass/fail across requests.\n- Keep the secret key out of logs and any client bundle.\n"
}

SHA-256: e9fed722ef6a7bcb26a54c13a65b969b8b074d11d4cfd7cca9124ea143c9aa2d