Glossary

What is a device ID?

A device ID is an identifier a service uses to recognize the same phone, tablet or computer each time it returns. It can be assigned by the operating system, stored by an app or cookie, or derived from the device's traits. Fraud teams use device IDs to link accounts, trust known devices and flag logins from unfamiliar ones.

How device IDs work

There is no single "device ID". The term covers several kinds of identifiers that differ in who creates them, how long they last and how easily they can be reset. Mobile platforms provide advertising and vendor identifiers that users can reset or restrict. Websites store their own ID in a cookie or local storage. Fraud prevention systems add a third kind: an ID assigned by matching the device's traits and history, so it survives when stored IDs are wiped.

In practice, a strong device ID combines these sources. A stored ID gives an exact match when it is present. A trait-based match fills the gap when storage is cleared, a private window is used, or the app is reinstalled.

Cookie or stored IDDevice fingerprintFraud-grade device ID
Created byThe website or appComputed from device traitsA risk platform combining both
Survives clearing dataNoUsuallyUsually
Survives spoofing toolsNoOften notDesigned to link the rotations
Exact or probabilisticExactProbabilisticMatch with a confidence level
Typical useSessions, preferencesRecognizing a browserLinking accounts, trusting devices

Why device IDs matter for fraud and trust

A reliable device ID changes what a fraud team can see. Instead of reviewing accounts one by one, it can ask how many accounts a device has touched, whether the device was linked to chargebacks before, and whether a login comes from a device this customer has used for years or one seen for the first time a minute ago.

That works in both directions. Known, trusted devices let good customers skip extra checks. New devices on an established account, especially combined with a new network or impossible travel, are a classic sign of account takeover. And many accounts sharing one device point to multi-accounting or a fraud ring.

  • Count accounts per device at signup and at reward or withdrawal time.
  • Keep a list of trusted devices per account and compare every login with it.
  • Mark devices tied to confirmed fraud and recognize them when they return.
  • Let customers see and revoke their own trusted devices.

How fraudsters attack device IDs

Stored IDs are the easiest target: clear cookies, reinstall the app or open a new antidetect browser profile, and the old ID is gone. Resettable mobile identifiers fall to a factory reset or an emulator. Trait-based IDs are harder to shake, so fraud tools rotate the traits themselves, giving each session a new screen, graphics card or font list. A device ID that treats each rotation as a brand new device ends up counting one fraudster as hundreds of customers.

How Kavra assigns device IDs

Kavra recognizes returning devices across visits and links them to accounts, while issuing opaque visitor IDs rather than exposing the fingerprint. When a device changes its fingerprint but the evidence shows the same actor, it stays one device with a count of rotations. Your backend can mark devices good or bad, keep trusted devices per account and revoke them through the API. See how this helps with account takeover.

FAQ

Frequently asked questions

Something else? Talk to our team.

Can a device ID be changed?

Some can, easily. Cookies and app-stored IDs vanish when data is cleared or the app is reinstalled, and mobile advertising IDs can be reset in settings. Identifiers derived from device traits and history are much harder to change, because the person would need to change the device itself, and attempts to fake those traits tend to be visible.

Is a device ID personal data?

Under GDPR, an identifier that can single out a device and be linked to a person is generally treated as personal data, even without a name attached. That means it needs a legal basis, a retention limit and erasure support. Using opaque IDs, keeping them separate per customer and never sharing them across companies reduces the risk.

What does a new device login alert mean?

It means the service did not recognize the phone or computer used to sign in, based on its device ID. It can simply be a new laptop or a cleared browser. It can also mean someone else has the password. Services use it to send a notice, ask for a second factor, or hold sensitive actions until the owner confirms.

See who is really on your site.

Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.