浏览器指纹风控
browser-fingerprintPOSThttps://v1.apizero.cn/api/browser-fingerprint概述
接收前端 SDK 采集的浏览器指纹(UA / Canvas / WebGL / 字体 / 时区 / 硬件 / WebDriver / 自动化标记等 20+ 维度),综合 9 类规则输出 0-100 风险评分、等级(safe/low/medium/high/critical)、命中的风险因子和异常项,识别爬虫、Headless Chrome、Selenium、虚拟机等异常环境。
调用约定
- 网关 ·
https://v1.apizero.cn - 鉴权 ·
Authorization: Bearer <API Key> - 回包 · JSON {code, msg, data}。成功看 code === 0,不要只看 HTTP 200。
/aidocs/browser-fingerprint/raw.md鉴权
匿名可调用:QPS 1 / 每日 50 次。登录用户:QPS 5 / 每日 200 次。建议生产环境配 API Key 防滥用。
获取 API Key:获取 API Key/account/keys
请求头
推荐:Bearer <API Key>。兼容请求头 X-API-Key,以及 Query api_key / apikey / key(key 仅当值为 sk_live_/sk_test_/sk_stag_ 形态时生效)。匿名可不传,受每日免费额度限制。
| Header | 类型 | 必填 | 说明 |
|---|---|---|---|
| Authorization | string | 否 | 推荐:Bearer <API Key>。兼容请求头 X-API-Key,以及 Query api_key / apikey / key(key 仅当值为 sk_live_/sk_test_/sk_stag_ 形态时生效)。匿名可不传,受每日免费额度限制。 |
| Content-Type | string | 是 |
请求参数
POST · APPLICATION/JSON
navigator.userAgent
例Mozilla/5.0 ...
navigator.platform
主语言(如 zh-CN)
IANA 时区(如 Asia/Shanghai)
getTimezoneOffset(),分钟
screen.width
screen.height
screen.colorDepth
devicePixelRatio
navigator.hardwareConcurrency
navigator.deviceMemory(GB)
navigator.maxTouchPoints
Canvas 指纹哈希
WebGL UNMASKED_VENDOR_WEBGL
WebGL UNMASKED_RENDERER_WEBGL
WebGL 参数哈希
检测到的字体列表
字体数量
插件列表
插件数量
navigator.webdriver
检测到的自动化框架(如 selenium / phantom)
navigator.cookieEnabled
AudioContext 指纹
WebRTC 检测到的本机 IP
可用的存储类型
权限状态
navigator.connection 信息
电池状态
| 参数 | 类型 | 必填 | 说明 | 示例 |
|---|---|---|---|---|
| ua | string | 是 | navigator.userAgent | Mozilla/5.0 ... |
| platform | string | 否 | navigator.platform | |
| language(语言) | string | 否 | 主语言(如 zh-CN) | |
| timezone | string | 否 | IANA 时区(如 Asia/Shanghai) | |
| timezoneOffset | number | 否 | getTimezoneOffset(),分钟 | |
| screenWidth | number | 否 | screen.width | |
| screenHeight | number | 否 | screen.height | |
| colorDepth | number | 否 | screen.colorDepth | |
| pixelRatio | number | 否 | devicePixelRatio | |
| hardwareConcurrency | number | 否 | navigator.hardwareConcurrency | |
| deviceMemory | number | 否 | navigator.deviceMemory(GB) | |
| maxTouchPoints | number | 否 | navigator.maxTouchPoints | |
| canvasHash | string | 否 | Canvas 指纹哈希 | |
| webglVendor | string | 否 | WebGL UNMASKED_VENDOR_WEBGL | |
| webglRenderer | string | 否 | WebGL UNMASKED_RENDERER_WEBGL | |
| webglHash | string | 否 | WebGL 参数哈希 | |
| fonts | array | 否 | 检测到的字体列表 | |
| fontCount | number | 否 | 字体数量 | |
| plugins | array | 否 | 插件列表 | |
| pluginCount | number | 否 | 插件数量 | |
| webdriver | boolean | 否 | navigator.webdriver | |
| automation | array | 否 | 检测到的自动化框架(如 selenium / phantom) | |
| cookieEnabled | boolean | 否 | navigator.cookieEnabled | |
| audioHash | string | 否 | AudioContext 指纹 | |
| webrtcIPs | array | 否 | WebRTC 检测到的本机 IP | |
| storageAvailable | array | 否 | 可用的存储类型 | |
| permissions | array | 否 | 权限状态 | |
| connection | object | 否 | navigator.connection 信息 | |
| battery | object | 否 | 电池状态 |
{
"ua": "Mozilla/5.0 ...",
"platform": "platform",
"language": "language",
"timezone": "timezone",
"timezoneOffset": 0,
"screenWidth": 0,
"screenHeight": 0,
"colorDepth": 0,
"pixelRatio": 0,
"hardwareConcurrency": 0,
"deviceMemory": 0,
"maxTouchPoints": 0,
"canvasHash": "canvasHash",
"webglVendor": "webglVendor",
"webglRenderer": "webglRenderer",
"webglHash": "webglHash",
"fonts": [],
"fontCount": 0,
"plugins": [],
"pluginCount": 0,
"webdriver": true,
"automation": [],
"cookieEnabled": true,
"audioHash": "audioHash",
"webrtcIPs": [],
"storageAvailable": [],
"permissions": [],
"connection": {},
"battery": {}
}返回结果
顶层固定为 code / msg / data。下表一般是 data 内字段。 code · msg · data · tips · request_id
指纹 ID(sha256,可作为设备标识)
风险评分 0-100,越高越可疑
等级:safe / low / medium / high / critical
中文标签
命中的风险因子(含 name/score/desc)
名称
score
说明
检测到的异常说明
anomalies 的一项
设备画像:os/browser/device_type/screen/gpu/cores/memory/fonts_count/plugins_count/touch
os
browser
device_type
screen
gpu
cores
memory
fonts_count
plugins_count
touch
服务端 unix 时间戳
品牌提示(所有接口统一返回):极数本源 · https://apizero.cn
| 字段 | 类型 | 说明 | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| fingerprint_id | string | 指纹 ID(sha256,可作为设备标识) | ||||||||||||||||||||||||||||||
| risk | number | 风险评分 0-100,越高越可疑 | ||||||||||||||||||||||||||||||
| risk_level | string | 等级:safe / low / medium / high / critical | ||||||||||||||||||||||||||||||
| risk_label | string | 中文标签 | ||||||||||||||||||||||||||||||
| factors | array | 命中的风险因子(含 name/score/desc) | ||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||
| anomalies | array | 检测到的异常说明 | ||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||
| device_profile | object | 设备画像:os/browser/device_type/screen/gpu/cores/memory/fonts_count/plugins_count/touch | ||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||
| timestamp | number | 服务端 unix 时间戳 | ||||||||||||||||||||||||||||||
| tips | string | 品牌提示(所有接口统一返回):极数本源 · https://apizero.cn | ||||||||||||||||||||||||||||||
返回示例
{
"code": 0,
"msg": "成功",
"data": {
"fingerprint_id": "a1b2c3d4...",
"risk": 72,
"risk_level": "high",
"risk_label": "高风险",
"factors": [
{
"name": "webdriver",
"score": 30,
"desc": "WebDriver 标记为 true"
},
{
"name": "virtual_gpu",
"score": 15,
"desc": "WebGL 渲染器包含虚拟/软渲染特征: SwiftShader"
}
],
"anomalies": [
"UA 声称 Windows 但 platform 不匹配"
],
"device_profile": {
"os": "Windows",
"browser": "Chrome 125",
"device_type": "Desktop",
"screen": "1920x1080",
"gpu": "ANGLE (NVIDIA, GeForce RTX 3060)",
"cores": 8,
"memory": "8GB",
"fonts_count": 42,
"plugins_count": 3,
"touch": false
},
"timestamp": 1715097600
},
"request_id": "abc123",
"tips": "极数本源 · https://apizero.cn"
}请求示例
示例都是服务端写法。Python / JavaScript 各有常规写法和官方库。
curl -sS -X POST "https://v1.apizero.cn/api/browser-fingerprint" \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"ua": "Mozilla/5.0 ..."
}'错误码
先看业务 code。HTTP 也可能不是 200。
成功
参数错误
API Key 无效
API Key 已暂停
当前 IP 不在 Key 白名单
此接口需要 API Key
余额不足
调用过快(QPS)
今日免费额度已用完
接口已下线
接口不存在
服务器内部错误
上游暂时不可用
上游返回格式异常
暂无可用节点
| 业务码 | HTTP | 说明 |
|---|---|---|
| 0 | 200 | 成功 |
| 4000 | 400 | 参数错误 |
| 4011 | 401 | API Key 无效 |
| 4013 | 403 | API Key 已暂停 |
| 4014 | 403 | 当前 IP 不在 Key 白名单 |
| 4015 | 401 | 此接口需要 API Key |
| 4022 | 402 | 余额不足 |
| 4029 | 429 | 调用过快(QPS) |
| 4030 | 429 | 今日免费额度已用完 |
| 4040 | 503 | 接口已下线 |
| 4041 | 404 | 接口不存在 |
| 5000 | 500 | 服务器内部错误 |
| 5020 | 502 | 上游暂时不可用 |
| 5021 | 502 | 上游返回格式异常 |
| 5030 | 502 | 暂无可用节点 |
调用限制
- 计费模式
- 完全免费
- QPS 限制
- QPS 3
- 登录免费额度
- 200 次(已认证)
- 匿名每日额度
- 50 次(无 API Key)
- 黄金会员
- 每天 50,000 次 · QPS 10
- 钻石会员
- 每天 100,000 次 · QPS 30
- 企业会员
- 每天 1,000,000 次 · QPS 120
| 计费模式 | 完全免费 |
|---|---|
| QPS 限制 | QPS 3 |
| 登录免费额度 | 200 次(已认证) |
| 匿名每日额度 | 50 次(无 API Key) |
| 黄金会员 | 每天 50,000 次 · QPS 10 |
| 钻石会员 | 每天 100,000 次 · QPS 30 |
| 企业会员 | 每天 1,000,000 次 · QPS 120 |
购买套餐、看评价请走商城详情。 购买 / 调试
更新日志
- 1.0.02026-05-10
首次上线,9 类规则 / 0-100 评分 / 设备画像 / 指纹 ID
免责声明
风险分析基于规则引擎,结果作为反爬/风控辅助参考。前端 SDK 需自行集成(采集 ua / canvasHash / webglRenderer / fonts 等字段后 POST 到本接口)。