Skip to main content
On this page

Integrate DEUNA's device fingerprint for anti-fraud and payment engines in your application.

You must generate your own fingerprints for most engines.

DEUNA offers a script / SDK that creates all necessary fingerprints to avoid manual tasks for each fingerprint script.

Integrates the device fingerprint of anti-fraud and payment engines.

Web SDK < 1.6

This section describes the current, published behavior. Use it if you run Web SDK below 1.6 or Cross-domain below 1.2.

1. Add the Mercado Pago script#

This script automatically loads everything needed to create the Device Fingerprint, which is sent when processing with Mercado Pago or whatever the anti-fraud or payment engine is.

Mercado Pago and other providers require this information to secure the transaction.

javascrptJavaScript
window.DEUNA_CREDENTIALS = {  
  <provider name>: {},  
}

// example
window.DEUNA_CREDENTIALS = {  
  MERCADOPAGO: {},  
}

2. Select the suppliers (only needed for Web SDK < 1.6)#

Select anti-fraud engine providers.

The following table contains attributes for the engines supported by the widget:

Engine

Attributes

Example

BAZ

orgId, merchantId

BAZ: { orgId: '', merchantId: '' }

CLEARSALE / CLEARSALE-BRASIL

ClientId

CLEARSALE: { clientId: '' } CLEARSALE-BRASIL: { clientId: '' }

CYBERSOURCE

orgId, merchantId

CYBERSOURCE: { orgId: '', merchantId: '' }

MERCADOPAGO

Does not require parameters at the merchant_id level

MERCADOPAGO: {}

SIFT

accountId, restApiKey

SIFT: { accountId: '', restApiKey: '' }

SIGNIFYD

Account and Email: Required for all implementations.

Session ID is only required if your merchant system generates the sessionId before DEUNA. This usually applies when you send events directly to Signifyd and need the events sent by DEUNA to be matched to the same Signifyd session.

In this case, you must send the same sessionId to DEUNA so that all events can be properly linked in Signifyd.

If you do not generate a sessionId or do not send events directly to Signifyd, you do not need to generate or send this field to DEUNA.s

Org ID is required for native apps implementation. This requirement difference from Web comes from Signifyd and NOT from DEUNA. The reason Signifyd mentions is: The orgId is required for the mobile SDK because, unlike web—where the TMX script automatically associates the session with the Signifyd account through the JavaScript snippet—the mobile SDK needs it to be configured in order to correctly link the device fingerprint to the corresponding account.

SIGNIFYD: {account: '', email: '', sessionId: '', orgId: '<needed for native apps>}

STRIPE

API_KEY

STRIPE: { apiKey: '' }

RISKIFIED

storeDomain

RISKIFIED: { storeDomain: '' }

ACCERTIFY

src, collectorHostSrc, sid, id, dvc

ACCERTIFY: { src: '', collectorHostSrc: '', sid: '', id: '', dvc: '' }

KOUNT

clientId, environment, isSinglePageApp

KOUNT: { clientId: '', environment: '', isSinglePageApp: ''},

KOIN

orgId

KOIN: { orgId: ''}

PAYU

Does not require parameters at the merchant_id level

PAYU: {}

3. Generate the fingerprints#

Generate fingerprints depending on your integration type.

3.1 DEUNA Payment widget

See the Web SDK example for initPaymentWidget.


3.2 Direct API

Add the fingerprint script.

The script includes a DEUNA SDK that is capable of generating fingerprints from any provider under a single integration.

Web SDK

  1. Follow the steps to add and initialize the Web SDK.
  2. Use the script to generate the fingerprint.
html
<script>
    var script = document.createElement("script");
    script.id = "deuna-sdk";
    script.src = "https://cdn.deuna.io/web-sdk/v1.6/index.js";
    
    script.onload = async function () {  // ✅ Make function async
        // Initialize the SDK
        await DeunaSDK.initialize({
            publicApiKey: "<public api key>",
            env: "sandbox"  // "sandbox" or "production"
        });

        // Get the MasterDeviceId from DEUNA
        const fraudId = await DeunaSDK.generateFraudId({
            someProvider: {  // ✅ Replace with actual provider name
                // provider-specific data
            }
        });

        console.log("Fraud ID:", fraudId);
    };

    document.body.appendChild(script);
</script>

iOS SDK

  1. Follow the steps to add and initialize the DEUNA SDK.
  2. Use the function generateFraudId to generate the fingerprint.
Swift
deunaSDK.generateFraudId(
  params: [
    "RISKIFIED": [
      "storeDomain": "volaris.com"
    ]
  ]
) { fraudId in
   
}

Android SDK

  1. Follow the steps to add and initialize the DEUNA SDK.
  2. Use the function generateFraudId to generate the fingerprint.
Kotlin
deunaSDK.generateFraudId(
  context = context,
  params = mapOf(
    "RISKIFIED" to mapOf(
      "storeDomain" to "deuna.com"
    )
  ),
  callback = { fraudId ->
  }
)
  1. Get the value of the device fingerprint and send it through Purchase V2:
JSON
  {
    "payer_info": {
      "email": "john@doe.com",
      "card_holder_dni": "12345678"
    },
    "payment_source": {
      "method_type": "debit_card",
      "card_info": {
        "card_id": "<card id>"
      }
    },
    "order": {
      "order_id": "DEUNA-NOW-69553619",
       // ...
    },
    "anti_fraud_info": { // dentro de este objeto se manda el fingerprint
      "device": {
        // mandar el fingerprint como base64
        "id": "<device fingerprint generated by the DEUNA Fraud SDK>"
      }
    }
  }

3.3 VTEX Connector

See this section: /docs/vtex-device-fingerprin

Web SDK ≥ 1.6

Use this section if you run Web SDK 1.6 or later.

In these versions, the DEUNA team configures the anti-fraud credentials. This changes the integration in three ways:

  • You do not add the Mercado Pago script. The window.DEUNA_CREDENTIALS object is no longer required.
  • You do not use the DEUNA Payment widget fingerprint step. It is no longer necessary.
  • The merchant no longer sends fraudCredentials. DEUNA sets these values for you.

SIGNIFYD exception#

SIGNIFYD is the one provider that still needs merchant input in these versions. The merchant must pass the email from the user session in generateFraudId.

Initialization script#

Add and initialize the SDK. In these versions you call generateFraudId without merchant-supplied credentials:

HTML
<script>
    var script = document.createElement("script");
    script.id = "deuna-sdk";
    script.src = "https://cdn.deuna.io/web-sdk/v1.6/index.js";

    script.onload = async function () {  // ✅ Make function async
        await DeunaSDK.initialize({
            publicApiKey: "<public api key>",
            env: "sandbox"  // "sandbox" or "production"
        });

        const fraudId = await DeunaSDK.generateFraudId();
        console.log("Fraud ID:", fraudId);
    };

    document.body.appendChild(script);
</script>

SIGNIFYD snippet (≥ 1.6)#

For SIGNIFYD, pass the email from the user session:

JavaScript
const fraudId = await DeunaSDK.generateFraudId({
    SIGNIFYD: { email: "<email from user session>" }
});