
The Device Tracking Add-On for the minFraud services identifies devices as they
move across networks and enhances the ability of the minFraud services to detect
fraud. If a fraudster changes proxies while they are using your site or app, or
between sessions, you may observe an increased risk score in the minFraud output
associated with their transactions.

We may increase the risk score if we detect order velocity on the device. We
also return a
[Device ID](/minfraud/api-documentation/responses#schema--response--device__id)
in minFraud Insights and Factors so that you can do your own modeling around
Device ID.

<!-- prettier-ignore-start -->

### Guides


- heading: "Web"
  url: "/minfraud/track-devices/web"
  text: "Track devices on your website using JavaScript."
- heading: "Android"
  url: "/minfraud/track-devices/android"
  text: "Track devices in your Android app using Kotlin or Java."
- heading: "iOS"
  url: "/minfraud/track-devices/ios"
  text: "Track devices in your iOS app using Swift or Objective-C."


<!-- prettier-ignore-end -->

## Explicit device linking

By default, the minFraud service matches devices using IP addresses. This works
well in most cases, but IP-based matching can be less reliable when multiple
users share the same IP address. Common scenarios include:

- **Shared or corporate IPs** where many employees or users share a single
  public IP address.
- **Carrier-Grade NAT (CGNAT)** where an ISP assigns the same public IP to many
  subscribers.
- **VPNs** where multiple users route traffic through the same VPN endpoint.

Explicit device linking solves this by using a `tracking_token` to match devices
with high confidence, independent of the IP address.

### How it works

The client-side tracking code returns a tracking token string. When you pass
this token to the minFraud API in the
[`/device/tracking_token`](/minfraud/api-documentation/requests#schema--request--device)
field, the service uses it to match the device directly. When a valid token is
found, the device is matched with high confidence regardless of IP address
changes.

### Implementation steps

1. Collect the tracking token on the client side using the appropriate SDK for
   your platform.
2. Pass the token to your backend (e.g., via a hidden form field, session
   storage, or API call).
3. Include the token in your minFraud API request's `device` object as
   `tracking_token`.

See the [Web](/minfraud/track-devices/web#explicit-device-linking-examples),
[Android](/minfraud/track-devices/android#explicit-device-linking-examples), and
[iOS](/minfraud/track-devices/ios#explicit-device-linking-examples) guides for
platform-specific examples.

### Token handling

- The tracking token is an **opaque string**. Do not parse it or make
  assumptions about its format, as the format may change without notice.
- Tokens should be treated as **transient**. Generate a fresh token for each
  session or transaction rather than storing tokens long-term.

## [Android](/minfraud/track-devices/android/)
> **⚠️ Warning**
> 
 The MaxMind Device SDK for Android is currently in beta.

<p>The MaxMind Device SDK for Android collects device data and sends it to MaxMind
so that the minFraud service can assign a Device ID and begin collecting
fingerprint information.</p>
## Installation
<p>Add the MaxMind Device SDK dependency to your app-level <code>build.gradle</code> file.</p>


```kotlin
// build.gradle.kts (Kotlin DSL)
dependencies {
    // Check https://search.maven.org/artifact/com.maxmind.device/device-sdk for the latest version.
    implementation("com.maxmind.device:device-sdk:0.2.0")
}
```

```groovy
// build.gradle (Groovy DSL)
dependencies {
    // Check https://search.maven.org/artifact/com.maxmind.device/device-sdk for the latest version.
    implementation 'com.maxmind.device:device-sdk:0.2.0'
}
```


<p>Check
[Maven Central](https://search.maven.org/artifact/com.maxmind.device/device-sdk)
for the latest version.</p>

## [iOS](/minfraud/track-devices/ios/)
> **⚠️ Warning**
> 
 The MaxMind Device SDK for iOS is currently in beta.

<p>The MaxMind Device SDK for iOS collects device data and sends it to MaxMind so
that the minFraud service can assign a Device ID and use it to detect fraud
across sessions. The SDK exposes both a Swift API and an Objective-C API;
Objective-C classes use an <code>MM</code> prefix.</p>
## Requirements
<ul>
<li>iOS 15.0+</li>
<li>Swift 5.9+</li>
<li>Xcode 15.0+</li>
</ul>
## Installation
<p>Add the MaxMind Device SDK as a Swift Package dependency. In Xcode, choose
<strong>File &gt; Add Package Dependencies…</strong> and enter the repository URL
<code>https://github.com/maxmind/device-ios.git</code>.</p>

## [Web](/minfraud/track-devices/web/)
<p>The Device Tracking Add-On is JavaScript code for you to add to your website. It
runs on a visiting device so that the minFraud service can assign a Device ID
and begin collecting fingerprint information. We recommend including the
JavaScript below on your product and landing pages as well as all the pages
within your purchase flow. This will help detect fraudsters if they change or
enable proxies while browsing your website.</p>

