Solution

Free trial abuse prevention for SaaS and AI products

Free trial abuse is when one person or group signs up again and again to restart a free trial or collect free credits they are meant to get once, often with new emails, cards and devices. In AI products it can mean farmed GPU or model credits. Kavra spots the returning actor at signup and trial start.

POST /trial/startVerify

Returning device, new email, fresh trial

  • Device seen on 3 ended trials
  • Fingerprint rotated since last visit
  • Home broadband, no proxy
Risk68
Your actionRequire a payment method
Who it hits
SaaS, AI and API products with free tiers
What it costs
Compute and model spend, lost paid plans
Tools used
Email aliases, antidetect browsers, scripts
Where to stop it
At signup, trial start and API key creation

What is free trial abuse?

Free trial abuse is the repeated use of an offer that is meant to be used once. A user reaches the end of a 14-day trial, signs up again with a new email, and starts a fresh 14 days. Or an account uses up its free monthly credits, and ten more accounts appear to take their share. Each account alone looks like a normal new user. Together they are one person who never intends to pay.

In classic SaaS, the loss is mostly a paid plan that never happens. In AI products, the math is harsher. Every free credit is backed by real compute: model inference, image generation, GPU minutes or paid third-party APIs. A free tier that is cheap to give away to real prospects becomes expensive when a script collects it thousands of times.

At the organized end, trial and credit abuse is a business. Operators farm free credits across many accounts and resell the access, for example as a cheap unofficial API that quietly draws on your free tier. It is a form of multi-accounting aimed at compute instead of cash bonuses.

How free trial and credit farming works

Casual abusers do this by hand once a month. Farms automate every step.

  1. 01

    Generate identities

    Email aliases, plus-addressing, catch-all domains and disposable inboxes give an unlimited supply of new addresses. Virtual numbers cover phone checks.

  2. 02

    Look like a new device

    A private window, a cleared browser or an antidetect browser profile removes the cookies and device details that would link the new account to the old one.

  3. 03

    Pass the payment step

    Where a card is required, prepaid or virtual cards, sometimes with tiny balances, pass the authorization check and are never charged.

  4. 04

    Script the signup

    Automation fills forms, confirms emails, starts the trial and creates API keys, so one operator can open hundreds of accounts a day.

  5. 05

    Pool and resell

    Credits from many accounts are routed through a proxy service or shared API keys and sold as cheap access, or used to run a workload for free.

Who it hits and what it costs

Any product with self-serve signup and something free at the start is exposed. The risk is highest in SaaS and AI products where each free unit has a real marginal cost, and in developer tools where a free API key is instantly useful to a script. Developer products carry extra risk, because the people evaluating the tool are often the same people who know how to automate its signup.

  • Compute and vendor spend: GPU time, model tokens, storage and third-party calls paid for by you and consumed by accounts that never convert.
  • Lost revenue: users who would have paid keep resetting the trial instead.
  • Resold access: your service shows up as a cheaper unofficial offer built on your free tier.
  • Distorted funnel data: signups and activations look healthy while trial-to-paid conversion quietly drops.
  • Collateral abuse: farmed accounts are also used for spam, content generation you do not allow, and API abuse.

Signs of free trial and credit abuse

The signal is almost never in one account. It is in what new accounts share with old ones.

  • Returning devices, new emails

    A device that ran a trial that just ended is back with a different email the same day or the next.

  • Email patterns

    Plus-addressed variants, dot tricks, catch-all domains and fresh disposable inboxes in bulk.

  • Fingerprint rotation

    The same actor keeps showing up with a slightly different device each time, which honest users rarely do.

  • Throwaway payment methods

    Prepaid or virtual cards, the same card behind many trials, or cards that fail as soon as the first charge runs.

  • Burn-and-leave usage

    The full credit allowance used within hours of signup, often through the API, and the account never touched again.

  • API keys on day one

    Keys created seconds after signup and then called from servers or proxy pools, not from the person who signed up.

Why common defenses fail

Each standard gate raises the cost a little. None of them recognizes the same actor coming back.

DefenseWhat it checksHow abusers get past it
Email verificationThat the inbox existsAliases, catch-all domains and disposable inboxes all verify
Disposable email blocklistsKnown throwaway domainsNew domains appear daily, and custom domains are cheap
Card required at signupThat a card authorizesPrepaid and virtual cards pass, and honest trials drop
Phone verificationThat a number receives a codeVirtual numbers are cheap, and each code is an SMS you pay for, a target for SMS pumping
Cookies and local storageA returning browserPrivate windows and new browser profiles start empty
IP limitsSignups per addressResidential proxies give each signup a new home IP

How to prevent free trial abuse

The aim is to keep the free trial generous for real prospects and close it to people who already had one. That means recognizing the actor behind a signup, deciding at the moment value is granted, and matching the response to the evidence instead of treating every signup as a suspect.

  • Assess every signup, trial start, credit grant and API key creation, not only the first page load.
  • Recognize returning devices across emails and accounts, and treat a rotating fingerprint on a known device as a warning.
  • Normalize emails (dots, plus-addressing, casing) before checking for repeats, and flag catch-all and disposable domains as one signal among many.
  • Grade the offer: give full credits to clean signups, smaller or delayed credits to mixed ones, and ask for a payment method or verification only from the risky few.
  • Cap free usage per actor, not per account, so pooling accounts stops paying off.
  • Watch trial-to-paid conversion and credit burn by cohort, and review clusters of linked accounts rather than single users.

A genuine trial user vs a trial farmer

Genuine trial user

  • One account, on a device consistent across visits
  • Explores the product, invites a teammate, reads docs
  • Uses credits gradually over days
  • Converts, or leaves and does not come back as someone else

Trial and credit farmer

  • New email, same actor as earlier trials
  • Skips onboarding and creates an API key at once
  • Burns the full allowance in hours
  • Linked to other accounts by device, network or card

Sources

  1. OWASP Automated Threats to Web Applications: OAT-019 Account Creation
  2. OWASP API Security Top 10: API4:2023 Unrestricted Resource Consumption
  3. OWASP API Security Top 10: API6:2023 Unrestricted Access to Sensitive Business Flows
  4. W3C Group Note: Mitigating Browser Fingerprinting in Web Specifications

How Kavra helps

How Kavra stops free trial and credit abuse

Kavra analyzes 3,000+ data points on each signup and trial start, recognizes the actor behind it, and tells your backend what it found before any credit is granted.

  • Returning actors recognized

    Devices are recognized across visits and accounts, so a new email on an old device is linked to the trials it already used.

  • Rotation counted, not reset

    When a device changes its fingerprint but remains the same actor, Kavra keeps one identity and records the rotations.

  • Clean profiles exposed

    Antidetect browsers, virtual machines and automation frameworks are caught by contradictions between what they claim and how they behave.

  • Proxy intelligence

    Own measurements of residential and mobile proxy exits reveal signups that route each account through a new home IP.

  • Protect key creation and usage

    Assess API key creation, and use the server-side request API to check calls that spend credits.

  • Graded, invisible responses

    Allow, verify or block by your own rules. Real prospects never see a puzzle, and observe-only mode shows the impact first.

FAQ

Frequently asked questions

Something else? Talk to our team.

How do companies know if you already had a free trial?

They link the new signup to the old one through evidence it shares: the device and browser, the network, the payment card, normalized email patterns and behavior. A new email alone does not make a new person. Device recognition that survives cleared cookies and private windows is the strongest link.

Does requiring a credit card stop free trial abuse?

It reduces casual abuse but does not stop determined abusers, who use prepaid or virtual cards that authorize and are never charged. It also lowers trial signups from honest prospects. A better pattern is asking for a card only when a signup looks linked to earlier trials.

What is AI credit farming?

AI credit farming is opening many accounts on an AI product to collect the free credits each one gets, then pooling them. The credits are used for the farmer's own workloads or resold as cheap access to models, image generation or GPU time. The provider pays for the compute behind every farmed credit.

Is creating multiple free trial accounts illegal?

It usually breaks the terms of service rather than a criminal law, so the typical response is closing accounts and revoking credits. It can become fraud when fake identities, stolen cards or resale of access are involved. Either way, you are entitled to limit free offers to one per person.

How do I stop users abusing free credits without hurting conversion?

Keep the default signup frictionless and grade the response to risk. Clean signups get the full offer. Signups linked to earlier trials get fewer credits, delayed credits, or a verification step. Checking invisibly in the background means genuine prospects never notice, while repeat abusers stop getting anything worth farming.

See who is really on your site.

Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.