If you’re evaluating device identification specifically to stop people from opening account after account on your free tier, the two names that come up most often are Fingerprint (formerly FingerprintJS) and Prynt. Both give you a stable visitor identifier that survives cleared cookies and incognito, both verify server side, and both return Smart Signals for bots, VPNs and tampering.
So the useful comparison isn’t “can it identify a device.” Both can. It’s how much of the multi-accounting problem each one solves for you once you have that identifier, and what it costs to run at signup volume. This post stays on that use case. For a broader look, see the best FingerprintJS alternatives.
The job: “this device already made three accounts”
Repeat-trial detection has three moving parts:
- Identify the device on the signup page.
- At signup, find out which of your accounts that device has created before.
- After signup, record the new account against the device so the next attempt sees it.
Step 1 is the identification product. Steps 2 and 3 are bookkeeping, and that bookkeeping is where integrations quietly break. The link step gets skipped on one code path, or the device-to-account table drifts from your user table, and the check silently returns zero.
How Fingerprint approaches it
Fingerprint is a mature, managed device-identification service with a long track record and broad SDK coverage. Its agent returns a visitorId and requestId, you can attach your own linkedId and tag at identification time, and its Server API lets you fetch an event by request id and look up a visitor’s history.
For trial abuse, the common pattern is to store visitorId on your user record at signup and count matching users in your own database at the next signup. That works well and puts the logic fully under your control. The trade-off is that you own the table, the indexes and the edge cases, such as accounts that later log in from other devices. Check Fingerprint’s current documentation for the exact endpoints and filters available today; we won’t describe their API beyond what’s above.
How Prynt approaches it
Prynt treats the account-to-device link as part of the API. The event you fetch at signup already includes the answer:
import { PryntServer } from '@prynt/node';
const prynt = new PryntServer({ secretKey: process.env.PRYNT_SECRET_KEY });
const ev = await prynt.getEvent(req.body.pryntRequestId);
// ev.accountsOnDevice → { count, truncated, accounts: [{ linkedId, events, firstSeenAt, lastSeenAt }] }
if (ev.decision === 'block' || ev.accountsOnDevice.count >= 1) return refuseTrial();
const user = await createUser(req.body);
await prynt.updateEvent(req.body.pryntRequestId, { linkedId: String(user.id) });
accountsOnDevice lists every account id you’ve linked to that device: at signup through PUT /v1/events/{requestId}, and after login by passing linkedId to identify(). The list is capped at 20 with a truncated flag, which matters less than it sounds: a device past 20 accounts doesn’t need an exact count. accountsOnDevice explained covers the field in depth.
On top of the raw list, Prynt computes multiAccount (2+ accounts on a device in 30 days) and accountSharing (more than 3 in 24 hours). Both feed the risk score, emit the MULTI_ACCOUNT and ACCOUNT_SHARING reason codes, and can be used directly in console rules such as distinctAccounts30d gte 3 → challenge.
There are also ready-made signup recipes for Express, Clerk, Supabase and Auth0 that share one policy module (allow, flag, verify or block), so you’re not writing the edge cases from scratch.
Side by side
| Fingerprint | Prynt | |
|---|---|---|
| Stable visitor ID, incognito-resistant | Yes | Yes |
| Server-side event lookup by requestId | Yes | Yes, GET /v1/events/{requestId} |
| Attach your account id | linkedId at identification | linkedId at identification, or PUT after signup |
| Accounts-per-device answer in the event | Built from your own data (check their docs) | accountsOnDevice in every event |
| Pricing model | Metered by API usage | Flat monthly plans with a soft cap |
| Deployment | Managed service | Managed cloud, or self-hosted (open-core) |
Pricing at signup volume
Pricing shape matters more for signup protection than it first appears. To catch a returning device, you identify everyone who reaches the signup page, including the bots and farmers you’re trying to stop. Under per-call metering, an abuse spike drives up your bill. That’s an awkward incentive for a fraud tool, and it pushes teams to identify less.
Prynt’s plans are flat: Free covers 20,000 identifications a month, Pro is $29/month for 250,000, Scale is $99/month for 1 million, and past the quota it keeps serving about 10% more with alerts at 80% and 100%, so an attack doesn’t produce a surprise invoice. For Fingerprint’s current numbers, read their pricing page directly. FingerprintJS pricing explained walks through how to model either at your volume.
Self-hosting and data control
Fingerprint is offered as a managed service. Prynt runs as a managed cloud by default, and its core is open source and self-hostable. That matters to teams with strict data-residency requirements or those who don’t want device data leaving their infrastructure. Both approaches can be made privacy-compliant. The question is whether you want to operate the server yourself.
When each is the better fit
Fingerprint is a strong choice if you want the longest-established vendor in this category, already have a device-to-account model in your database, and per-call economics work at your volume.
Prynt fits if trial and signup abuse is the main problem, you want accounts-per-device in the API response instead of a table you maintain, you prefer flat pricing that doesn’t climb during an attack, or you need a self-hosted option.
Switching
The concepts map one to one. get() is an alias of identify(), visitorId, requestId and linkedId mean the same things, and verification is still “fetch the event with a secret key.” Migrating from FingerprintJS has the field mapping, and the comparison page has the broader feature view. The practical test is to run both side by side on your signup page for a week and see which devices each one would have caught.
Try it free
Prynt is device intelligence with a free tier — visitor IDs, bot & fraud Smart Signals, and behavioral biometrics, powered by a cross-site network. Start free.