Identity verification

Stop anyone from creating fake users or changing a user's email through your public snippet.

Your tracking ID is public, because it sits in your page source. Identity verification makes your server sign each user ID with a secret, and Atlis rejects snippet calls that don't carry a valid signature (userHash).

  1. 1

    Generate a secret

    Go to Settings → Advanced → Identity verification and click Generate secret. Copy it straight away; it's shown only once. Store it as a server environment variable, for example ATLIS_IDENTITY_SECRET. Never put it in browser code.

  2. 2

    Create the userHash on your server

    It's an HMAC-SHA256 of the user ID, as a hex string.

  3. 3

    Send it with every identify and track call

    Add userHash to the properties of every identify() and track() call.

  4. 4

    Turn verification on

    Only when every call sends userHash, click Turn on verification. From then on, calls without a valid userHash are rejected with 403 identity_verification_failed.

JavaScript
// Node.js — on your server
const crypto = require("crypto");

const userHash = crypto
  .createHmac("sha256", process.env.ATLIS_IDENTITY_SECRET)
  .update(String(user.id))
  .digest("hex");
Browser
// In the browser, pass the userHash your server generated
window.Atlis.identify(user.id, user.email, { name: user.name, userHash });
window.Atlis.track("page_view", { page: location.pathname, userHash });

Using window.AtlisConfig?

The automatic AtlisConfig setup can't send a userHash. Switch to window.Atlis.identify() before turning verification on.

  • The heartbeat that keeps last active time fresh doesn't need a userHash.
  • Server API calls to /api/v1 use your API key instead and aren't affected.
  • Clicking Regenerate secret replaces the old one. If verification is on, tracking stops until your server uses the new secret.

Try it in your own workspace

Start with a 14-day trial with Growth features. No credit card needed.

Start free