POST /v1/api-keysVerifyNew key from a device seen on 4 trials
- Device linked to 4 trial accounts
- Disposable email domain
- Real browser, human input
Industry
SaaS and AI fraud is abuse of software products through their free tiers, signups and APIs: endless free trials, farmed LLM and GPU credits, stolen or resold API keys, fake signups that inflate metrics and bots scraping generated output. Kavra assesses every signup, key and request, links accounts to one actor and lets real developers straight through.
POST /v1/api-keysVerifyNew key from a device seen on 4 trials
Most software grows through a generous front door: a free tier, a trial, starter credits, an API key in two clicks. SaaS fraud is abuse of that door. One person opens the tenth trial, a script creates a thousand accounts to pool free credits, a leaked API key ends up behind a paid proxy someone else sells, or a bot harvests the content your product generates.
AI products changed the math. A classic SaaS trial costs little to serve, so an abuser mostly costs you a lost sale. An AI trial runs on GPUs. Every farmed credit is real inference you pay a model provider or a cloud bill for, which turns free-trial and credit abuse from a leak into a direct cost that scales with the attacker's patience.
The same product surface serves developers, buyers and attackers. Here is where each threat lands.
| Threat | Where it strikes | Business impact |
|---|---|---|
| Free-trial and credit farming | Signup, trial start, credit grant | GPU and inference spend with no revenue |
| Repeat trials through multi-accounting | Signup, workspace creation | Paid plans never bought, cohorts polluted |
| Fake account creation at scale | Signup, email and phone verification | Inflated signups and active users, noisy funnels |
| API abuse, key sharing and reselling | API key creation, API traffic | Quota drained, capacity taken from paying users |
| Scraping of generated content | Public share pages, output endpoints | Outputs copied or used to train rival models |
| Account sharing | Login, concurrent sessions | One seat paid, a team served |
| Account takeover and credential stuffing | Login, key and billing settings | Stolen keys, data exposure, surprise bills |
| Card testing on checkout | Upgrade and billing forms | Disputes, fees and processor risk |
| SMS pumping | Phone verification | SMS bills for traffic that never becomes users |
Farming runs like a small production line. Each step defeats one classic check.
A headless browser or an HTTP client posing as a browser fills the signup form. Disposable inboxes and plus-address or dot tricks on one mailbox pass email verification.
Every account gets a fresh browser profile, often from an antidetect browser or a cloud virtual machine, and a different IP from a residential proxy pool or a VPN.
The script activates the trial, accepts the starter credits and creates an API key. Some operators also chain referral links between their own accounts, a form of promo abuse, to collect bonus credits on both ends.
Hundreds of keys are loaded into a rotating pool behind one proxy endpoint, so each key stays under its own rate limit while the pool serves heavy traffic.
The pooled capacity runs the operator's own workload or is resold as cheap access to your models. When keys run dry, the line starts again.
Developers hate friction, and they are your best customers. The goal is not to put a gate at every step, but to assess each step quietly and add a check only when the evidence asks for one.
Developers use VPNs, terminals and new laptops. None of that is fraud alone. Contradictions and links between accounts are.
New accounts keep appearing from a device already tied to earlier trials, even after the fingerprint is rotated.
The signup claims to be Chrome on a laptop but behaves like a scripted client: no real rendering, instant typing, identical timing.
Each account looks local, but the IPs belong to commercial proxy pools rather than the home or office networks they claim.
Many keys from unrelated accounts call the API with the same prompts, rhythm and client, from shared infrastructure.
One login active on several devices in distant places at the same time, far beyond normal travel or a second laptop.
Traffic says it is a known AI agent but comes from outside the operator's published ranges and carries no valid signature.
Each common control stops one layer, and each adds friction that honest developers feel first.
| Defense | What it stops | What gets through, or what it costs |
|---|---|---|
| Email domain blocklists | Known disposable inboxes | New throwaway domains and alias tricks on real mailboxes |
| Phone verification | Cheap bulk signups | Virtual numbers, SMS pumping and drop-off from real users |
| Card required for trial | Casual repeat trials | Stolen and prepaid cards, which adds payment fraud, and fewer honest signups |
| Per-key rate limits | One heavy key | Key pools that spread load across many accounts |
| IP limits | Signups from one address | Rotating residential and mobile IPs |
| CAPTCHA on signup | Crude scripts | Solving services, plus friction on developer onboarding |
For AI products, free usage is a line on the compute bill, so abuse shows up as margin loss, not only as churn. It also skews the numbers you run the company on. Fake signups inflate activation and active-user counts, pull conversion rates down and send growth spend toward channels that bring bots. Keys resold by third parties can also expose you to use cases that break your model provider's policies or your own.
Protection has to respect privacy law as well. Under the GDPR and similar rules, device signals used for fraud prevention need a legal basis and must follow the user's consent choices where they apply. Opaque identifiers, strict tenant isolation and clear retention rules make fraud checks easier to defend to customers, auditors and your own security reviewers.
The best setups keep the front door wide for real developers and make farming more expensive than paying.
How Kavra helps
One script on signup and one server call per decision. Kavra analyzes 3,000+ data points and returns an explained verdict your backend can act on.
Returning devices are recognized across accounts, and fingerprint rotation is kept as one actor with N rotations, not N new users.
Headless browsers, automation frameworks, HTTP clients posing as browsers and antidetect profiles are exposed by contradictions between layers.
A request API scores backend and API traffic, so key pools and resellers are caught where they actually hit you.
Known agents and crawlers are verified by signature and published ranges. You choose to allow, check or block each one.
No CAPTCHA puzzles. Invisible challenges run first when evidence is unclear, and your rules decide the step-up.
A script under 64 KB that never blocks rendering, one API call, webhooks and native iOS and Android SDKs. First results the same day.
FAQ
Something else? Talk to our team.
Recognize the person, not the email. Repeat trialists change inboxes, IPs and browser profiles, but their device, network and behavior tend to link back to earlier accounts. Assess each signup for those links and act before credits are granted: allow clean signups, reduce or delay credits for mixed evidence and ask for a card only when the account ties to earlier trials.
Credit farming is creating many accounts to collect the free credits each one receives, then pooling them to run workloads or resell access. In AI apps the credits map to GPU inference, so the cost is real and immediate. Farmers use scripts, disposable emails, proxies and spoofed browsers, which is why checks that look at one signal at a time miss them.
Look at how keys behave together. Resold keys often come from unrelated accounts yet call the API with the same client, prompts, timing and infrastructure, rotating to stay under per-key limits. Linking the accounts that created the keys and scoring API traffic server side reveals the pool behind them, so you can revoke the set instead of chasing single keys.
It cuts casual abuse but also cuts honest signups, and determined farmers use stolen or prepaid cards. A middle path works better for most products: let clean signups start without a card, and ask for one only when the signup looks linked to earlier trials or comes from automation. That keeps the funnel open and moves friction onto the abusers.
Compare each session with the account's own history. Sharing shows up as one login used on several devices at once, often in distant locations, or a steady rotation of new devices on a single seat. Flag it for review or ask for a second factor rather than logging users out, since a new laptop or a trip is normal.
They do not have to. Checks that run in the background, with no puzzles and an async script that never blocks the page, add nothing to a normal signup. The friction lands only on accounts with risky evidence, such as automation or links to earlier trials. Start in observe-only mode to confirm the effect before enforcing anything.
Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.