Identity verification
Stop anyone from creating fake users or changing a user's email through your public snippet.
Your tracking ID is public, because it sits in your page source. Identity verification makes your server sign each user ID with a secret, and Atlis rejects snippet calls that don't carry a valid signature (userHash).
- 1
Generate a secret
Go to Settings → Advanced → Identity verification and click Generate secret. Copy it straight away; it's shown only once. Store it as a server environment variable, for example
ATLIS_IDENTITY_SECRET. Never put it in browser code. - 2
Create the userHash on your server
It's an HMAC-SHA256 of the user ID, as a hex string.
- 3
Send it with every identify and track call
Add
userHashto the properties of everyidentify()andtrack()call. - 4
Turn verification on
Only when every call sends
userHash, click Turn on verification. From then on, calls without a validuserHashare rejected with403 identity_verification_failed.
// Node.js — on your server
const crypto = require("crypto");
const userHash = crypto
.createHmac("sha256", process.env.ATLIS_IDENTITY_SECRET)
.update(String(user.id))
.digest("hex");// In the browser, pass the userHash your server generated
window.Atlis.identify(user.id, user.email, { name: user.name, userHash });
window.Atlis.track("page_view", { page: location.pathname, userHash });Using window.AtlisConfig?
The automatic AtlisConfig setup can't send a userHash. Switch to window.Atlis.identify() before turning verification on.
- The heartbeat that keeps last active time fresh doesn't need a
userHash. - Server API calls to
/api/v1use your API key instead and aren't affected. - Clicking Regenerate secret replaces the old one. If verification is on, tracking stops until your server uses the new secret.
More in Install tracking
Try it in your own workspace
Start with a 14-day trial with Growth features. No credit card needed.
Start free