The Transparent FingerprintJS Alternative & Bot Detection API.
Add a 6KB client script to your web application. It measures 140+ hardware and behavioral signals in under 12ms. Pass the token to our REST API to identify automated bots, stop multi-accounting with returning visitor flags, and protect your trial API credits. Free tier included — then just $15 per 100,000 checks.
2-Step Integration. Complete Signal Transparency.
Unlike traditional vendors that return an opaque score without explanation, BotRefund provides full forensic telemetry — headless browser leaks, automation runtime hooks, mouse tremor entropy, and persistent returning visitor device hashes.
<!-- 1. Include the lightweight script in your HTML <head> -->
<script src="https://cdn.botrefund.com/seatext.js?id=YOUR_PROJECT_ID" async></script>
<script>
async function handleSubmit() {
// Retrieve session-bound token (generated in <12ms)
const token = window.__botrefundToken || await window.BotRefund?.getToken();
// Send token along with your form or auth request
await fetch("/api/auth/register", {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({
email: document.getElementById("email").value,
deviceToken: token
})
});
}
</script>
// Node.js (Express / Next.js Route Handler)
import { BotRefundClient } from "@botrefund/sdk";
const botRefund = new BotRefundClient({
apiKey: process.env.BOTREFUND_SECRET_KEY
});
app.post("/api/auth/register", async (req, res) => {
const { deviceToken, email } = req.body;
// Verify token and retrieve detailed device signals
const result = await botRefund.verify(deviceToken);
if (result.is_bot || result.bot_score > 0.65) {
return res.status(403).json({ error: "Automated access blocked" });
}
if (result.is_returning) {
// Prevent multi-accounting and free trial token churning
console.warn("Returning device detected: " + result.visitor_id);
return res.status(409).json({ error: "Free trial already claimed" });
}
// Proceed to create human user account
return createUser({ email, visitorId: result.visitor_id });
});
POST /v1/verify (JSON Output)
{
"is_bot": false,
"bot_score": 0.02, // 0.00 = human, 1.00 = automated headless bot
"bot_type": "none", // "headless_chrome", "playwright_stealth", "ai_agent"
"visitor_id": "v_8f90a2b918cc7", // Persistent hardware fingerprint hash
"is_returning": true, // MULTI-ACCOUNT FLAG: true if device seen previously
"first_seen": "2026-09-18T10:14:02Z",
"signals": {
"headless_browser": false,
"stealth_evasion": false, // Detects navigator overrides & CDP hooks
"datacenter_proxy": false,
"mouse_tremor_entropy": 0.94, // Real human biomechanical micro-movements
"webrtc_ip_leak_matched": true
}
}
Why Developers Switch from Fingerprint Pro & reCAPTCHA
Fingerprint locks bot detection behind a $99/mo starting tier. reCAPTCHA hurts UX. We built what developers actually asked for.
| Feature / Metric | BotRefund API | Fingerprint Pro | Cloudflare Turnstile | Google reCAPTCHA v3 |
|---|---|---|---|---|
| Cost per 100,000 Checks | $15 flat (free tier first) | $99+ base + expensive overages | Free (no custom risk API) | Free tier, then Enterprise |
| Bot Detection Smart Signals | Included on all plans | Pro Plus & Enterprise only | Basic challenge pass/fail | 0.0 – 1.0 opaque score |
| Returning Visitor / Multi-Account Flag | Included (is_returning) |
Included (expensive) | No visitor tracking | No visitor identity |
| User Friction & UX | 100% Invisible (0ms delay) | 100% Invisible | Interactive widget / checkbox | Floating badge & puzzles |
| Headless & Stealth Evasion Detection | 140+ browser collectors | Proprietary collectors | WAF heuristic checks | Google session heuristics |
| Sales Call Required? | Never (Instant Self-Serve) | Mandatory for high volume | Self-serve | Self-serve |
| Ad Click Fraud & PPC Refund Evidence | Integrated Core Dossier | No ad platform claims | No refund disputes | None |
Engineered to Stop Fraud Without Breaking Conversion
Every API request evaluates client hardware entropy, automation hooks, and session replay signals in real-time.
Returning Visitor & Multi-Account Flag
Prevent trial token abuse on your AI SaaS. When a user clears localStorage, rotates residential IPs, or launches an incognito window to grab free trial credits, our 140-signal entropy hash catches the physical device and returns is_returning: true.
Headless & Stealth Framework Detection
Catches Puppeteer-Extra-Stealth, Playwright stealth flags, Patchright, CDP runtime hooks, Selenium, and Undetected-Chromedriver. Inspects WebGL extensions, worker concurrency, and prototype modifications directly in browser memory.
Mouse Tremor & Biomechanical Entropy
Bots click in straight Euclidean vectors with uniform acceleration. Human hands possess micro-tremors, variable curve deceleration, and physiological entropy. Our script evaluates mouse curves without sending video or sensitive DOM state.
Silent reCAPTCHA Alternative
Stop punishing your genuine paying users with infuriating fire hydrant puzzles and crosswalk images. BotRefund runs silently in the background, completing all tests in under 12ms without blocking the main browser thread.
Custom CAPTCHA & Challenges Developed for Your Needs
Have a specialized verification workflow or need custom Proof-of-Work puzzles and adaptive challenge screens for suspicious spikes? Our engineering team develops, tailors, and tunes challenge logic directly for your platform's specific security needs.
Integrated Ad Click Refund Engine
Are you spending money on Google Ads or Meta Ads? BotRefund doesn't just block bots — our core system packages forensic server logs, click timestamps, and IP clusters into audited dossiers to negotiate direct refunds from ad platforms.
Developer Pricing Built to Scale
Start free. When your traffic grows, pay flat and predictable rates without talking to an enterprise sales rep.
Hacker / Free Tier
For side projects, indie hackers, and early-stage validation.
- Up to 10,000 checks / month free
- Full 140+ device entropy signal collection
-
Returning visitor flag (
is_returning) - Headless & stealth detection hooks
- REST API & client JS SDK access
Pay-As-You-Go Pro
For growing startups, SaaS apps, and high-volume APIs.
- $15 per 100k requests ($0.00015 / check)
- Zero monthly minimums • Auto-scale as you grow
- Multi-account & trial churn prevention
- Unlimited domains & API keys
- 99.99% Global Edge SLA (<10ms response)
- Priority email & developer Slack support
Frequently Asked Questions for Developers & Security Engineers
Everything you need to evaluate BotRefund API against Fingerprint Pro, Cloudflare Turnstile, and reCAPTCHA.
FingerprintJS & Fingerprint Pro Comparison
How does BotRefund API serve as a FingerprintJS alternative?
Fingerprint's open-source library (`fingerprintjs`) only provides static browser entropy without server-side validation. Fingerprint Pro charges a steep $99/month minimum base fee and restricts actual Bot Detection and Smart Signals to higher-priced tiers. BotRefund gives you device identification and real-time bot scoring in a single REST API with a generous free tier and $15/100k pricing.
Why is Fingerprint Pro so expensive for high-volume apps?
Fingerprint Pro utilizes an enterprise-heavy pricing model where overages quickly reach thousands of dollars per month, forcing growing teams into annual enterprise contracts. BotRefund was built developer-first: flat $15 per 100,000 checks, pay-as-you-go, zero minimum commitments, and no mandatory sales calls.
Can I replace my existing Fingerprint Pro agent with BotRefund without frontend refactoring?
Yes. The integration flow is conceptually identical: include our lightweight script in your frontend HTML <head>, retrieve the generated `deviceToken`, and send it to your backend route to call `POST /v1/verify`. Your backend receives a structured JSON payload with `visitor_id`, `is_bot`, `bot_score`, and risk signals.
How does BotRefund handle browser fingerprint stability across browser updates?
Browser vendors frequently release patches that randomize canvas noise or shift WebGL renderer strings. BotRefund decouples hardware invariants (GPU geometry, audio buffer decay, screen color depths) from mutable software attributes, maintaining 99.4% cross-session visitor identification stability.
reCAPTCHA & Cloudflare Turnstile Differences
Why not just use Cloudflare Turnstile for free?
Cloudflare Turnstile is an effective replacement for visual CAPTCHA boxes, but it is strictly a pass/fail human challenge widget. Turnstile does not provide persistent hardware device identification, returning visitor flags, multi-accounting detection, or granular forensic signal breakdowns needed to protect backend API routes.
How is this superior to Google reCAPTCHA v3?
Google reCAPTCHA v3 produces opaque 0.0 to 1.0 scores that heavily penalize users who browse in privacy mode, use VPNs, or are not logged into Google accounts. Furthermore, reCAPTCHA provides zero insight into *why* a visitor was scored down. BotRefund exposes the exact signals (e.g., CDP automation leaks, headless flags, proxy ASNs).
Does BotRefund show intrusive visual puzzles to real users?
No. BotRefund is 100% invisible. Real human users experience zero latency, zero checkboxes, and zero visual disruptions. The evaluation occurs entirely in the background via passive biomechanical and hardware entropy.
Can BotRefund be used alongside Cloudflare Turnstile?
Yes. Many developers use Cloudflare Turnstile as a frontend gatekeeper and pair it with BotRefund's backend API to track persistent visitor IDs, block multi-account promo abuse, and prevent trial credit churning.
Multi-Accounting & Trial Abuse Prevention
How does the returning visitor flag (`is_returning`) prevent multi-accounting?
Attackers who automate account signups to exploit free trial AI credits (e.g., OpenAI or Anthropic API tokens) routinely rotate residential proxies, clear localStorage, and use incognito windows. BotRefund computes an invariant hardware fingerprint from 140+ device entropy sources. If the device was previously seen on your tenant, the API immediately returns `is_returning: true`.
Can users bypass the returning visitor flag by opening Incognito or Private Browsing?
No. Incognito mode clears cookies, indexedDB, and cache upon closing the session, but it does not alter underlying hardware invariants such as WebGL shader float precision, audio oscillator harmonics, CPU concurrency, or GPU driver signatures.
Does rotating residential IP addresses trick BotRefund?
No. IP addresses are treated as low-confidence transient network attributes. A user switching between 50 different VPN or mobile proxy IPs from the same physical laptop retains the exact same `visitor_id`.
How does this protect AI SaaS products from LLM token exhaustion?
AI wrappers frequently suffer financial bleed when bots farm free trial accounts to make free API calls against expensive models. By checking `is_returning` during registration, you can reject duplicate trial claims before issuing API keys or GPU compute.
Headless Browsers & Anti-Detect Bot Detection
Does BotRefund detect Puppeteer-Extra-Stealth and Playwright Stealth?
Yes. Stealth plugins attempt to mask automation by overriding `navigator.webdriver` and spoofing Chrome runtime properties. BotRefund executes deep prototype pollution checks, evaluates Chrome DevTools Protocol (CDP) execution stack traces, and probes hidden iframe behavior where stealth mocks leak.
Can anti-detect browsers like Multilogin, AdsPower, or Octo Browser evade detection?
Anti-detect browsers modify canvas noise and font metrics, but often introduce inconsistent entropy combinations (e.g., matching a macOS user agent with a Windows DirectX WebGL shader compile signature). BotRefund cross-references 140+ hardware layers to flag cross-platform synthetic tampering.
How does mouse tremor entropy distinguish bots from real humans?
Automated scripts (even those using bezier curve libraries) generate synthetic cursor paths with unnatural acceleration curves and zero neuromuscular micro-tremors. Real human hands exhibit biomechanical micro-variations. BotRefund analyzes these curve dynamics passively in real time.
Does BotRefund detect headless browsers running inside Docker or AWS Lambda?
Yes. Containerized and serverless environments lack real hardware GPUs and rely on software renderers (like SwiftShader or llvmpipe). BotRefund inspects WebGL UNMASKED_RENDERER strings and CPU timing profiles to detect virtualized execution environments instantly.
Integration, Performance & Core Web Vitals
How much latency does the client script add to page load?
Zero critical path latency. The script is approximately 6KB gzipped, loads asynchronously via `async`, and executes signal collection in under 12 milliseconds in a non-blocking background thread. It has zero negative impact on Largest Contentful Paint (LCP) or Interaction to Next Paint (INP).
What is the server verification API response time?
Our REST API verification endpoint (`POST /v1/verify`) operates on globally distributed edge compute with an average response time of under 10 milliseconds, making it suitable for inline authentication and checkout validation.
Can I integrate BotRefund with Next.js, React, Vue, or Webflow?
Yes. BotRefund works with any frontend framework. You can load it via a standard `<script>` tag in your HTML `<head>`, inside a Next.js `<Script strategy="afterInteractive">` tag, or via Google Tag Manager.
Can I protect pure backend REST or GraphQL endpoints?
Yes. Require your web or mobile client to include a fresh BotRefund token in request headers (`X-Device-Token`). Your backend middleware calls our `/v1/verify` endpoint before executing business logic, returning a `403 Forbidden` if an automated bot is identified.
Privacy, GDPR & Security Compliance
Is BotRefund compliant with GDPR and CCPA?
Yes. BotRefund is built with privacy-first data minimization. We do not collect Personally Identifiable Information (PII) such as names, passwords, credit card numbers, or email addresses. Hardware invariants are securely hashed and evaluated strictly for fraud prevention under Legitimate Interest provisions.
Does BotRefund track users across unrelated websites?
No. Fingerprint hashes and session tokens are strictly scoped to your specific tenant account ID (`YOUR_PROJECT_ID`). Cross-site tracking is not performed, ensuring complete compliance with modern privacy standards.
Can client-side code be inspected by our internal security team?
Yes. BotRefund maintains an open-code policy. All client-side JavaScript is cleanly readable and readily inspectable by your corporate security and engineering teams.
Where is data processed and stored?
API verification requests are processed globally at the edge and persisted in SOC-2 Type II compliant data centers with strict encryption in transit (TLS 1.3) and encryption at rest (AES-256).
Pricing, Custom Development & Ad Refunds
How does billing work after the free tier?
Every account includes 10,000 free checks per month forever. Beyond the free tier, usage is billed at a flat $15 per 100,000 checks ($0.00015 per check). There are no setup fees, no monthly minimum commitments, and no surprise overage penalties.
Can you develop custom CAPTCHA or Proof-of-Work challenges for our app?
Yes! We develop and customize challenge logic for your specific requirements. If your application requires adaptive Proof-of-Work mathematical puzzles, custom branded CAPTCHAs, or specialized edge rate-limiting rules, our engineering team can custom-build them for your integration.
How does this connect with BotRefund's ad click spend recovery?
If you also run paid traffic on Google Ads or Meta Ads, our core product uses the exact same forensic signals to track invalid paid ad clicks. We automatically compile certified forensic dossiers and file formal refund claims with Google and Meta, recovering up to 20% of wasted ad spend.
How do I get my API key and start testing today?
Click "Get Free API Key on Seatext" to register your developer account at login.seatext.com. You will receive your project ID and secret API key immediately to begin verifying requests in minutes.
Ready to Stop Bot Fraud & Trial Abuse?
Create your free developer account on Seatext today. Get your API keys in under 60 seconds and start verifying requests immediately.