@echoscan/browser-verifier
v1.0.8
Published
Browser-side verifier for EchoScan pre-login device trust and browser fingerprinting.
Maintainers
Readme
EchoScan Browser Verifier
EchoScan Browser Verifier runs in the browser to support pre-login device trust and browser
fingerprinting. It uses a publishable Browser Environment ID to return a server-issued imprint;
your trusted backend then queries EchoScan Report API v1 and applies your business policy.
Install
npm install @echoscan/browser-verifierCreate a Browser Environment in EchoScan, register the exact Allowed Origin where the verifier will
run, and copy its publishable environmentId. The Environment ID is not a Secret API Key or
Workspace ID.
Generate an imprint
import { createEchoScan } from '@echoscan/browser-verifier'
const verifier = createEchoScan({
environmentId: 'env_0123456789abcdef0123456789abcdef',
})
const { imprint } = await verifier.run()A successful run returns { imprint }. New imprints use the imp_<32 lowercase hex> format. Send
the imprint to your trusted backend with the protected sign-in, registration, payment, or other
business request.
Your backend uses its server-only Secret API Key to query Report API v1:
GET https://api.echoscan.org/api/v1/fingerprint/report/{imprint}
X-API-Key: <server-secret-api-key>
Accept: application/jsonNever place a Secret API Key or Workspace ID in browser code. Keep the full Report and final allow, challenge, review, or deny decision on your backend.
ESM, UMD, and CDN
The npm package provides ESM, TypeScript declarations, and a single-file UMD build exposed as
window.EchoScan. When self-hosting the ESM build, publish its matching chunks/ directory too.
EchoScan also serves the current supported CDN builds at:
- ESM:
https://cdn.echoscan.org/v1/echoscan.esm.js - UMD:
https://cdn.echoscan.org/v1/echoscan.umd.js
Documentation
- Developer API and integration guide
- OpenAPI contract
- EchoScan platform overview
- Public Scan — a first-party product demonstration, not a replacement for a customer Browser Environment or trusted-backend integration.
