[{"data":1,"prerenderedAt":183},["ShallowReactive",2],{"doc:\u002Fdocs\u002Fsignals":3},{"page":4,"toc":176,"updated":182},{"path":5,"title":6,"seoTitle":7,"description":8,"blocks":9},"\u002Fdocs\u002Fsignals","Signals reference","Signals Reference: Every Signal Group and Default Weight","Every signal group Fingerly scores on web, Android and iOS: what each means, its key in API responses and webhooks, and its default weight.",[10,13,18,148,150,153,155,157,160,162,165,167,170,172],{"type":11,"text":12},"p","Signals are grouped by what they tell you. Events read with a secret key list triggers by group; the identify response and the `visitor.suspect` webhook name the individual signal and its group. The dashboard's **Smart Signals > Signal reference** lists every individual signal.",{"type":14,"level":15,"text":16,"id":17},"heading",2,"Signal groups","signal-groups",{"type":19,"columns":20,"rows":27},"table",[21,22,23,24,25,26],"Group","Key","Meaning","Web","Android","iOS",[28,35,41,46,51,56,61,66,71,77,81,85,89,93,97,101,105,110,114,118,122,126,131,135,139,143],[29,30,31,32,33,34],"Tor exit node","`tor`","The connection arrives from the Tor network.","14","16","17",[36,37,38,32,39,40],"Datacenter proxy","`datacenter_proxy`","The address belongs to a proxy or a hosting provider rather than a consumer connection.","12","15",[42,43,44,45,45,45],"Residential proxy","`residential_proxy`","Traffic is relayed through someone else's home connection.","6",[47,48,49,50,45,45],"VPN","`vpn`","The connection arrives over a VPN.","4",[52,53,54,55,55,55],"IP reputation","`ip_reputation`","The address has a recent history of abuse.","8",[57,58,59,32,60,60],"IP blocklist","`ip_blocklist`","The address is on a public blocklist for sending spam or for attacks.","13",[62,63,64,65,65,65],"Location spoofing","`location_spoofing`","The device's own location settings disagree with where its connection is.","5",[67,68,69,70,70,70],"Network anomaly","`network_anomaly`","The address should not appear on the public internet. Off by default.","0",[72,73,74,75,76,76],"Bot","`bot`","The client is automated, or says it is a bot.","9","n\u002Fa",[78,79,80,32,76,76],"Virtual machine","`virtual_machine`","The browser runs inside a virtual machine.",[82,83,84,32,76,76],"Remote control","`remote_control`","The session is driven through remote desktop software, as in many support scams.",[86,87,88,55,55,55],"Browser tampering","`browser_tampering`","The runtime has been modified, or claims to be something it is not.",[90,91,92,33,33,33],"Fingerprint suppressed","`fingerprint_suppressed`","Too little was collected to identify the device.",[94,95,96,50,76,76],"Incognito mode","`incognito_mode`","The page is in a private browsing window.",[98,99,100,45,76,76],"Privacy settings","`privacy_settings`","The browser runs hardened privacy settings.",[102,103,104,45,65,45],"High activity","`high_activity`","The device has been seen far more often than an ordinary one.",[106,107,108,109,55,55],"Device farm","`device_farm`","The device looks mass-provisioned or freshly reset, or shares traits with many devices at once.","7",[111,112,113,76,55,33],"Developer tools","`developer_tools`","A debugger or developer tooling is attached.",[115,116,117,76,39,76],"Rooted device","`rooted_device`","The Android device is rooted.",[119,120,121,76,75,76],"Android emulator","`android_emulator`","The app runs in an Android emulator.",[123,124,125,76,75,76],"Cloned app","`cloned_app`","The app runs inside a cloning framework, or is not your signed build.",[127,128,129,76,76,130],"Jailbroken device","`jailbroken_device`","The iOS device is jailbroken.","10",[132,133,134,76,76,33],"iOS simulator","`ios_simulator`","The app runs in the iOS Simulator.",[136,137,138,76,32,32],"Instrumentation","`frida_detected`","An instrumentation toolkit is attached to the app.",[140,141,142,76,32,32],"MITM attack","`mitm_attack`","Something is intercepting the app's encrypted traffic.",[144,145,146,76,147,147],"Active call","`active_call`","The device is on a phone call during the action, a common pattern in scams.","3",{"type":11,"text":149},"Weights are the defaults for each platform: a group's weight is its heaviest signal's. `n\u002Fa` means the group does not apply on that platform, which is different from a weight of `0`.",{"type":14,"level":15,"text":151,"id":152},"Network signals","network-signals",{"type":11,"text":154},"Network signals come from the visitor's IP address and apply to every platform. The same lookup fills in `country_code`, `asn`, `asn_name` and `anonymity_network` on the event.",{"type":11,"text":156},"VPN and residential proxy findings carry a confidence from how many independent indications agree. You can weigh them by how they were recognised, or by that confidence. See [weighting modes](\u002Fdocs\u002Frisk-weights#weighting-modes).",{"type":14,"level":15,"text":158,"id":159},"Device and runtime signals","device-and-runtime-signals",{"type":11,"text":161},"Device signals come from the SDK's report and are checked again on the server. On iOS and Android, the native SDKs reach what JavaScript cannot, which is why mobile has signals such as rooted and jailbroken devices, emulators and instrumentation.",{"type":14,"level":15,"text":163,"id":164},"Behaviour signals","behaviour-signals",{"type":11,"text":166},"`high_activity` and the cross-device part of `device_farm` compare a device with your own traffic over the last 5 minutes, hour and day. They learn what normal looks like for each environment and platform first: until there are at least 1,000 identifications and 7 days of history, they are reported but add nothing to the score.",{"type":14,"level":15,"text":168,"id":169},"Signal names are permanent","signal-names-are-permanent",{"type":11,"text":171},"A signal's name never changes meaning. If what a detection measures changes, it becomes a new signal with a new name, so rules you write against today's names stay correct.",{"type":173,"tone":174,"text":175},"callout","tip","Start with the defaults. They are hand-set to reflect how strongly each signal indicates fraud, not trained on your traffic, so tune them once you have your own data. See [risk weights](\u002Fdocs\u002Frisk-weights).",[177,178,179,180,181],{"id":17,"text":16,"level":15},{"id":152,"text":151,"level":15},{"id":159,"text":158,"level":15},{"id":164,"text":163,"level":15},{"id":169,"text":168,"level":15},"2026-09-17T08:28:36.000Z",1789667797513]