How device IDs work
There is no single "device ID". The term covers several kinds of identifiers that differ in who creates them, how long they last and how easily they can be reset. Mobile platforms provide advertising and vendor identifiers that users can reset or restrict. Websites store their own ID in a cookie or local storage. Fraud prevention systems add a third kind: an ID assigned by matching the device's traits and history, so it survives when stored IDs are wiped.
In practice, a strong device ID combines these sources. A stored ID gives an exact match when it is present. A trait-based match fills the gap when storage is cleared, a private window is used, or the app is reinstalled.
Device ID vs cookie vs fingerprint
| Cookie or stored ID | Device fingerprint | Fraud-grade device ID | |
|---|---|---|---|
| Created by | The website or app | Computed from device traits | A risk platform combining both |
| Survives clearing data | No | Usually | Usually |
| Survives spoofing tools | No | Often not | Designed to link the rotations |
| Exact or probabilistic | Exact | Probabilistic | Match with a confidence level |
| Typical use | Sessions, preferences | Recognizing a browser | Linking accounts, trusting devices |
Why device IDs matter for fraud and trust
A reliable device ID changes what a fraud team can see. Instead of reviewing accounts one by one, it can ask how many accounts a device has touched, whether the device was linked to chargebacks before, and whether a login comes from a device this customer has used for years or one seen for the first time a minute ago.
That works in both directions. Known, trusted devices let good customers skip extra checks. New devices on an established account, especially combined with a new network or impossible travel, are a classic sign of account takeover. And many accounts sharing one device point to multi-accounting or a fraud ring.
- Count accounts per device at signup and at reward or withdrawal time.
- Keep a list of trusted devices per account and compare every login with it.
- Mark devices tied to confirmed fraud and recognize them when they return.
- Let customers see and revoke their own trusted devices.
How fraudsters attack device IDs
Stored IDs are the easiest target: clear cookies, reinstall the app or open a new antidetect browser profile, and the old ID is gone. Resettable mobile identifiers fall to a factory reset or an emulator. Trait-based IDs are harder to shake, so fraud tools rotate the traits themselves, giving each session a new screen, graphics card or font list. A device ID that treats each rotation as a brand new device ends up counting one fraudster as hundreds of customers.
How Kavra assigns device IDs
Kavra recognizes returning devices across visits and links them to accounts, while issuing opaque visitor IDs rather than exposing the fingerprint. When a device changes its fingerprint but the evidence shows the same actor, it stays one device with a count of rotations. Your backend can mark devices good or bad, keep trusted devices per account and revoke them through the API. See how this helps with account takeover.