How canvas fingerprinting works
The canvas is a normal browser feature that lets pages draw graphics, used by charts, games and photo editors. A fingerprinting script uses it quietly. It creates a canvas the visitor never sees, writes a line of text in a chosen font, adds colored shapes, gradients and maybe an emoji, then exports the result as data and turns it into a short code, called a hash.
Two computers given the same drawing instructions rarely produce exactly the same pixels. Font smoothing, anti-aliasing, the graphics card, its driver and the operating system's text engine all shape the edges of letters and the blending of colors. The differences are invisible to the eye but show up clearly in the data.
What happens during a canvas check
- 01
Draw
The script renders fixed text, shapes and colors on an off-screen canvas.
- 02
Read back
It exports the pixels, the same way a web app saves an image.
- 03
Hash
The pixel data is reduced to a short code that can be compared across visits.
- 04
Compare
The code is checked against earlier visits and against what the claimed device should produce.
Why it matters in fraud and real traffic
On its own, a canvas hash is not unique: identical phones on the same software version draw the same image. Its real value for fraud teams is as a consistency check. A browser that says it runs on a Mac with Apple graphics should draw like one. If the canvas output matches a Windows machine with a different graphics card, the device is misrepresenting itself.
That is why antidetect browsers and privacy extensions go after the canvas. Some replace the output with a stored image from another device. Others add random noise so the hash changes on every read. Noise defeats simple tracking, but it creates a new tell: a real device draws the same image the same way every time, while a noisy one does not. A hash that changes between two reads on the same page is a strong sign of device spoofing or fingerprint rotation.
Canvas fingerprinting vs other rendering checks
Canvas is one of several ways to measure how a device renders. They work best together.
| Technique | What it measures | What it reveals |
|---|---|---|
| Canvas (2D) | Text and shapes drawn flat | Fonts, text engine, graphics stack |
| 3D graphics | A small 3D scene and the reported graphics card | Real GPU family, software rendering on servers |
| Audio | How the device processes a generated sound | Audio stack and platform differences |
| Font list | Which fonts render at what size | Operating system and installed software |
Detecting canvas spoofing
Useful checks go beyond reading the hash. Draw more than once and compare. Compare the canvas result with the 3D graphics result and the claimed hardware. Watch for canvas output that exactly matches a known stock image shared by many unrelated visitors. Kavra combines these rendering checks with network, browser integrity and behavior signals, so a faked canvas is caught by the contradiction it creates rather than by the hash alone. See how Kavra detects antidetect browsers.