# What is canvas fingerprinting?

Source: https://kavralab.com/glossary/canvas-fingerprinting/

**Canvas fingerprinting** is a technique where a web page tells the browser to draw hidden text and shapes on an HTML canvas, then reads back the pixels. Small differences in graphics hardware, drivers, fonts and operating system make the result vary between machines, so the output helps recognize a device and check whether it is what it claims.

## How canvas fingerprinting works

The canvas is a normal browser feature that lets pages draw graphics, used by charts, games and photo editors. A fingerprinting script uses it quietly. It creates a canvas the visitor never sees, writes a line of text in a chosen font, adds colored shapes, gradients and maybe an emoji, then exports the result as data and turns it into a short code, called a hash.

Two computers given the same drawing instructions rarely produce exactly the same pixels. Font smoothing, anti-aliasing, the graphics card, its driver and the operating system's text engine all shape the edges of letters and the blending of colors. The differences are invisible to the eye but show up clearly in the data.

## What happens during a canvas check

1. **Draw**: The script renders fixed text, shapes and colors on an off-screen canvas.
2. **Read back**: It exports the pixels, the same way a web app saves an image.
3. **Hash**: The pixel data is reduced to a short code that can be compared across visits.
4. **Compare**: The code is checked against earlier visits and against what the claimed device should produce.

## Why it matters in fraud and real traffic

On its own, a canvas hash is not unique: identical phones on the same software version draw the same image. Its real value for fraud teams is as a consistency check. A browser that says it runs on a Mac with Apple graphics should draw like one. If the canvas output matches a Windows machine with a different graphics card, the device is misrepresenting itself.

That is why [antidetect browsers](https://kavralab.com/glossary/antidetect-browser/) and privacy extensions go after the canvas. Some replace the output with a stored image from another device. Others add random noise so the hash changes on every read. Noise defeats simple tracking, but it creates a new tell: a real device draws the same image the same way every time, while a noisy one does not. A hash that changes between two reads on the same page is a strong sign of [device spoofing](https://kavralab.com/glossary/device-spoofing/) or [fingerprint rotation](https://kavralab.com/glossary/fingerprint-rotation/).

## Canvas fingerprinting vs other rendering checks

Canvas is one of several ways to measure how a device renders. They work best together.

| Technique | What it measures | What it reveals |
|---|---|---|
| Canvas (2D) | Text and shapes drawn flat | Fonts, text engine, graphics stack |
| 3D graphics | A small 3D scene and the reported graphics card | Real GPU family, software rendering on servers |
| Audio | How the device processes a generated sound | Audio stack and platform differences |
| Font list | Which fonts render at what size | Operating system and installed software |

## Detecting canvas spoofing

Useful checks go beyond reading the hash. Draw more than once and compare. Compare the canvas result with the 3D graphics result and the claimed hardware. Watch for canvas output that exactly matches a known stock image shared by many unrelated visitors. Kavra combines these rendering checks with network, browser integrity and behavior signals, so a faked canvas is caught by the contradiction it creates rather than by the hash alone. See [how Kavra detects antidetect browsers](https://kavralab.com/detect/antidetect-browsers/).

## FAQ

### Is canvas fingerprinting unique to each device?

No. Devices with the same model, operating system, browser version and fonts often produce the same canvas output. Canvas fingerprinting narrows down the type of device and its software, and it is very good at catching a device that claims to be something it is not. It should always be combined with other signals before recognizing a specific device.

### Can you block canvas fingerprinting?

Partly. Some browsers and extensions ask permission before a page reads canvas data, return a blank image, or add random noise to the output. These defenses reduce tracking but also make the browser stand out, because most real browsers draw consistently. Fraud detection treats them as context, not as proof of bad intent.

### Does canvas fingerprinting work on mobile apps?

Canvas is a web feature, so it applies to mobile browsers and in-app web views. Native iOS and Android apps have their own ways to read device and graphics traits through the platform, often combined with operating system attestation. A fraud platform with native SDKs uses those signals instead of a canvas drawing.

---
Kavra Lab: bot and fraud detection that explains every decision. Book a demo: https://kavralab.com/contact/
