{"id":15294,"plugin_id":"plugin_asdk_app_69d3e530928c819191a9738ef3f4def6","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:11:08.803Z","digest":"22b645f452b4290f6ee04f2b84c73c1704d992f2580ac1dc1238c2c354bf4cbd","against":null,"payload":{"name":"fingerprint-smart-signals","description":"Use the full set of Fingerprint Smart Signals (bot, VPN, proxy, tampering, incognito, IP blocklist, velocity, suspect score, location spoofing, and more) from the v4 Server API to make richer server-side trust decisions. Use after the basic identification + verification is in place, when you want detailed insights about a visitor beyond confidence.","included_files":[{"relative_path":"skill.json","size_in_bytes":307},{"relative_path":"snippets/signals-policy.js","size_in_bytes":1619}],"skill_md_contents":"---\nname: fingerprint-smart-signals\ndescription: Use the full set of Fingerprint Smart Signals (bot, VPN, proxy, tampering, incognito, IP blocklist, velocity, suspect score, location spoofing, and more) from the v4 Server API to make richer server-side trust decisions. Use after the basic identification + verification is in place, when you want detailed insights about a visitor beyond confidence.\n---\n\n# Fingerprint — Smart Signals (v4 Server API)\n\nMaps to the dashboard **\"Access detailed insights about a visitor\"** Get Started step. Once your\nbackend fetches an event server-side, the same `getEvent(eventId)` response carries 100+ signals.\nThis skill is about *acting on the full set*, not just `confidence`. All of these are\nserver-verified — never trust client-reported equivalents.\n\n## Prerequisite\nA working server-side flow (in whatever backend you run) that already calls `getEvent(eventId)`\nwith your `FINGERPRINT_SECRET_API_KEY`.\n\n## Signals (flat v4 event shape)\nEach Smart Signal is a top-level field on the event. The web-relevant set:\n\n| Field | Meaning | Typical action |\n| --- | --- | --- |\n| `bot` | `\"bad\" \\| \"good\" \\| \"not_detected\"` | Block `\"bad\"` on protected endpoints |\n| `vpn` | behind a VPN | Step-up / score for high-risk flows |\n| `proxy` | behind a public proxy | Step-up / score |\n| `tampering` | bool — anomalous browser signature / anti-detect browser | Reject for sensitive actions |\n| `incognito` | private browsing | Score; don't hard-block alone |\n| `ip_blocklist` | object: `attack_source`, `email_spam`, `tor_node` (IP on known-malicious lists) | Block or step-up on any sub-flag |\n| `velocity` | object of interval counts (`5_minutes`/`1_hour`/`24_hours`) per visitor/IP/linked_id | Rate-limit abuse / ATO |\n| `suspect_score` | integer — weighted aggregate of Smart Signals | Threshold-based routing |\n| `location_spoofing` | GPS/timezone spoofing | Score for geo-gated actions |\n| `developer_tools` | devtools open | Score for scraping/automation |\n| `virtual_machine` | running in a VM | Score |\n| `raw_device_attributes` | low-level device attributes | Custom heuristics |\n\n> Field availability depends on your plan and platform (web vs. mobile), so guard each access\n> (`event.vpn ?? false`) so a missing signal doesn't throw. Event schema: OpenAPI\n> (https://github.com/fingerprintjs/fingerprint-pro-server-api-openapi) or the Fingerprint MCP\n> event-schema resource.\n\n## How to apply\n1. **Don't gate on a single signal.** Combine them into a per-action policy: e.g. block on\n   `bot === \"bad\"` or `tampering`, step-up auth on `vpn || proxy || ip_blocklist`, and log\n   `suspect_score` for analytics.\n2. **Tune by action risk.** Login/checkout/password-reset warrant strict, fail-closed policies;\n   read-only or low-risk actions can score-and-allow.\n3. **Use `velocity` for abuse/ATO.** A spike of identifications for one `visitor_id` (or many\n   visitors hitting one account) is a strong takeover/credential-stuffing signal.\n4. **Persist signal outcomes** alongside your own fraud events so you can iterate on thresholds.\n5. **Smart Signals require enablement.** Some are off by default in the workspace — enable them in\n   the dashboard (Smart Signals settings) for the environment whose secret key you use.\n\n## Best practices\n- Server-side only — Smart Signals are never trustworthy when reported by the client.\n- Fail closed on lookup errors for high-risk actions.\n- Don't log the raw secret key or full event payloads containing PII.\n- Re-evaluate signals on **every** sensitive action; each `event_id` is single-use.\n\nSee `snippets/signals-policy.js` for a composable scoring helper.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}