Application Environment Verification API

Security / API Key Intermediate HTTPS CORS
Varies by plan (check documentation)

Overview

Application Environment Verification (AEV) is an Android library and API from FingerprintJS that checks whether a user device is safe to use. It detects rooted devices, emulators, and other risk signals that could indicate fraud or tampering. Developers use it to enforce security policies before granting access to sensitive app features.

Beginner Tip

Start by integrating the Android SDK into your app first — the API works alongside the library to verify results server-side. Always validate device signals on your backend rather than trusting the client alone.

Available Data

Application Environment Verification data via REST API

Example Response

JSON Response
{
  "title": "The Great Gatsby",
  "authors": [
    "F. Scott Fitzgerald"
  ],
  "publishedDate": "1925-04-10",
  "pageCount": 218,
  "categories": [
    "Fiction"
  ],
  "imageLinks": {
    "thumbnail": "https://books.google.com/..."
  },
  "averageRating": 4
}

Field Reference

isRooted True if the device appears to be rooted or jailbroken.
isEmulator True if the app is running inside an emulator rather than a real device.
riskLevel Overall device risk assessment: low, medium, or high.
requestId Unique ID for this verification request, useful for support and auditing.

Implementation Example

Request
const url = "https://github.com/fingerprintjs/aev";
// Replace headers or query params with the values required by this API.
const response = await fetch(url, {
  headers: {
  "X-API-Key": "YOUR_API_KEY"
  }
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();
console.log(data);

What Can You Build?

Note: These code examples are AI-generated and unverified. Always refer to the official API documentation for accurate usage.

Common Errors & Troubleshooting

401 Unauthorized Missing or invalid API key in the request header.
Include your API key in the Authorization header as Bearer YOUR_API_KEY.
Device token expired The verification token generated by the SDK has a short TTL.
Re-request a fresh device token from the SDK immediately before sending it to your server.
SDK integration mismatch The server-side API version does not match the Android SDK version in use.
Check the FingerprintJS changelog and ensure your SDK and API versions are compatible.

Metadata Score Breakdown

Estimated from metadata — endpoint not independently tested

This score is estimated from observable metadata — HTTPS support, authentication model, declared CORS, and documentation reachability — because the API requires authentication or exposes no publicly testable endpoint. The five-signal breakdown is only shown for live-tested APIs.

Metadata estimate · endpoint not independently tested

Technical Specifications

Auth API Key
HTTPS REQUIRED
CORS YES
Category Security
Difficulty Intermediate
Verified: 2026-04-04

Related Tags

Similar APIs

View All →