All articles Integration

Load Prynt Device Intelligence with Google Tag Manager

Google Tag Manager lets you deploy the Prynt agent without touching your codebase, which is ideal when engineering bandwidth is tight or the site is managed by marketing. The trade-off: GTM only collects the signal, and the real decision still has to happen on your server.

This guide loads Prynt with a custom HTML tag, pushes the visitor ID into the dataLayer, and verifies events from your backend. It is the fastest way to start collecting device signals when a full code deploy is weeks away, and it keeps the loader decoupled from your application release cycle.

Fire the agent with a custom HTML tag

Create a Custom HTML tag that loads the CDN build and initializes the agent. Trigger it on the pages where you need a signal, such as login or checkout.

<script src="https://api.pryntid.com/cdn/prynt.umd.js"></script>
<script>
  Prynt.load({
    apiKey: "{{Prynt Public Key}}",
    endpoint: "https://api.pryntid.com"
  }).then(function (agent) {
    window.__pryntAgent = agent;
  });
</script>

Store the public key as a GTM variable so it is easy to rotate. The CDN build needs no bundler.

Push the visitor ID to the dataLayer

When a user submits a form, identify and push the requestId so downstream tags and your own scripts can read it.

<script>
  document.querySelector('#login').addEventListener('submit', function () {
    window.__pryntAgent.identify().then(function (result) {
      window.dataLayer.push({
        event: 'prynt_identified',
        pryntId: result.requestId
      });
    });
  });
</script>

The dataLayer value is only a transport mechanism. It is not trustworthy until your server verifies it.

Verify the event server-side

Send the requestId to your backend and look it up with your secret key. This is the only place a decision belongs.

const res = await fetch(
  `https://api.pryntid.com/v1/events/${pryntId}`,
  { headers: { Authorization: `Bearer ${process.env.PRYNT_SECRET}` } }
)
const event = await res.json()
if (event.confidence < 0.5) {
  requireStepUp()
}

Never treat the dataLayer value as proof of anything, because anything client-side can be forged. Store event.visitorId against the account for later fraud rules. The field reference is in the server-side verification docs.

A word of caution on trigger scope: firing the agent on every page view through GTM is wasteful and can add noise to your analytics. Scope the tag to the pages where a decision actually happens, using GTM’s page-path or element-visibility triggers, and let it initialize once per session. This keeps the client light and ensures the event ID you push corresponds to a real, meaningful interaction rather than an idle pageview a bot never engaged with.

Guard forms directly

You can also let Form Shield watch a form from the same tag, adding behavioral signals for scripted fills.

<script>
  window.__pryntAgent.protectForm(document.querySelector('#login'), {
    autoGuard: true,
    expectedScripts: ['latin']
  });
</script>

expectedScripts flags submissions in unexpected writing systems, a cheap spam signal for Latin-script audiences. It runs entirely in the browser, so it complements, rather than replaces, the server-side verification step.

Keep the decision off the client

GTM is a convenient loader, not a security boundary. Anyone can inspect and tamper with what runs in the browser, so treat the dataLayer purely as a way to move the event ID to your server, where verification happens. Because Prynt is a managed cloud service, geolocation, proxy, and bot signals arrive with no infrastructure to run, and the free tier covers early traffic.

Used this way, GTM buys you speed without giving up safety: marketing ships the loader, engineering owns the decision, and neither blocks the other. Add the tag, push the ID, and verify on your backend. See the pricing and free plan to start deploying device intelligence through GTM without a code release.

Try it free

Prynt is device intelligence with a free tier — visitor IDs, bot & fraud Smart Signals, and behavioral biometrics, powered by a cross-site network. Start free.

Keep reading