[{"data":1,"prerenderedAt":150},["ShallowReactive",2],{"doc:\u002Fdocs\u002Fplanning-your-integration":3},{"page":4,"toc":133,"updated":149},{"path":5,"title":6,"seoTitle":7,"description":8,"blocks":9},"\u002Fdocs\u002Fplanning-your-integration","Plan your integration","Plan Your Fingerly Integration","Decide where to identify, how to tag actions, which keys each environment needs, and how to roll out a risk policy without surprising real customers.",[10,13,18,20,47,51,54,56,59,79,81,84,107,110,113,115,118,120,124],{"type":11,"text":12},"p","A good integration is a few decisions made up front. This page walks through them.",{"type":14,"level":15,"text":16,"id":17},"heading",2,"Where to identify","where-to-identify",{"type":11,"text":19},"Identify at the moments that carry risk or value, not on every page view. Each production identification is billed.",{"type":21,"columns":22,"rows":26},"table",[23,24,25],"Moment","Tag","Typical decision",[27,31,35,39,43],[28,29,30],"Sign-up","`signup`","Limit accounts per visitor; review high-risk sign-ups.",[32,33,34],"Login","`login`","Step up to a second factor on medium; lock on high.",[36,37,38],"Checkout","`checkout:\u003Corder id>`","Hold high-risk orders for review.",[40,41,42],"Promotion redemption","`promo:\u003Ccode>`","One redemption per visitor.",[44,45,46],"Password reset","`password-reset`","Slow down resets from new, high-risk visitors.",{"type":48,"tone":49,"text":50},"callout","tip","The framework SDKs share one identification per page, so a component tree that asks several times still makes one request.",{"type":14,"level":15,"text":52,"id":53},"Tag every identification","tag-every-identification",{"type":11,"text":55},"A tag binds an identification to the action it was made for. When your server checks the tag, a request ID captured on a harmless page cannot be replayed at checkout. Include an identifier from the action itself, such as an order ID, where you have one.",{"type":14,"level":15,"text":57,"id":58},"Keys per environment","keys-per-environment",{"type":21,"columns":60,"rows":65},[61,62,63,64],"Environment","Keys","Billed","Use for",[66,71,74],[67,68,69,70],"Development","Public and secret","No","Laptops and CI.",[72,68,69,73],"Staging","Pre-release testing with realistic traffic.",[75,76,77,78],"Production","Public and secret, optionally a proxy key","Yes","Real visitors.",{"type":11,"text":80},"Each environment's events, dashboards and webhooks are kept apart, so test traffic never shows up in production numbers. See [API keys and environments](\u002Fdocs\u002Fapi-keys).",{"type":14,"level":15,"text":82,"id":83},"Roll out a policy","roll-out-a-policy",{"type":85,"steps":86},"steps",[87,92,97,102],{"title":88,"blocks":89},"Observe",[90],{"type":11,"text":91},"Identify and store results without acting on them. Log what each level would have done.",{"title":93,"blocks":94},"Tune",[95],{"type":11,"text":96},"Review high and medium sessions in the dashboard. Adjust [risk weights](\u002Fdocs\u002Frisk-weights) and the threshold until the levels match what you see.",{"title":98,"blocks":99},"Add friction first",[100],{"type":11,"text":101},"Act on `medium` with friction a real customer can pass, such as a second factor.",{"title":103,"blocks":104},"Enforce",[105],{"type":11,"text":106},"Act on `high` once you trust it: review, block, or limit.",{"type":48,"tone":108,"text":109},"warning","Never make an identification failure fatal for the visitor. If the SDK cannot reach Fingerly, let your server treat the missing request ID as missing evidence.",{"type":14,"level":15,"text":111,"id":112},"Decide on the server","decide-on-the-server",{"type":11,"text":114},"Always read results with a secret key on your backend. Anything the browser reports, including the score, can be changed by whoever controls the browser. See [server-side verification](\u002Fdocs\u002Fserver-side-verification).",{"type":14,"level":15,"text":116,"id":117},"Consent","consent",{"type":11,"text":119},"The SDKs collect as soon as they are called, unless you load them with a `consent` state other than `granted`. If your legal basis requires consent, load with `pending` and pass on your consent tool's answer. See [consent tools](\u002Fdocs\u002Fconsent-tools).",{"type":14,"level":121,"text":122,"id":123},3,"Checklist","checklist",{"type":125,"items":126},"list",[127,128,129,130,131,132],"Identification points chosen and tagged.","Public key origins list every production domain.","Secret key stored only on servers.","Server checks the tag, the age and the level.","Failures degrade to missing evidence, not errors.","Consent gate in place where required.",[134,135,136,137,138,140,142,144,146,147,148],{"id":17,"text":16,"level":15},{"id":53,"text":52,"level":15},{"id":58,"text":57,"level":15},{"id":83,"text":82,"level":15},{"id":139,"text":88,"level":121},"step-observe",{"id":141,"text":93,"level":121},"step-tune",{"id":143,"text":98,"level":121},"step-add-friction-first",{"id":145,"text":103,"level":121},"step-enforce",{"id":112,"text":111,"level":15},{"id":117,"text":116,"level":15},{"id":123,"text":122,"level":121},"2026-09-17T16:57:29.000Z",1789667797513]