All Products
Search
Document Center

Fraud Detection:Device Risk SDK Web/H5 Integration

Last Updated:Aug 26, 2026

This document describes the integration process for the Device Risk SDK (Web/H5), embedding the JS SDK into pages that need protection.

Embed the JS SDK

<script src="https://o.alicdn.com/captcha-frontend/aliyunFP/fp.min.js"></script>
Important

The JS file is updated periodically. Do not download and host the file on a local server to avoid service disruptions caused by outdated versions.

init interface

After embedding the JS SDK, you can initialize the SDK immediately (only one initialization is needed) to obtain the SDK object.

Initialization example:

ALIYUN_FP.use('um', (state, um) => {
  if (state === 'loaded') {
    um.init({
        //Enter the AppKey obtained from the Fraud Detection console
        appKey: 'your_app_key',
        //Enter a custom name for your Web application
        appName: 'your_web_app_name',
        endpoints : ['https://cloudauth-device.ap-southeast-1.aliyuncs.com']
    }, (state) => {
        // state = success indicates that the initialization is successful
        console.info(state);
    });
  }
});
Important

If you do not specify a service address, the endpoints parameter uses the default configuration.

Optional service addresses for endpoints:

Region

Service address

Singapore (default)

https://cloudauth-device.ap-southeast-1.aliyuncs.com

Hong Kong

https://cloudauth-device.cn-hongkong.aliyuncs.com

Germany

https://cloudauth-device.eu-central-1.aliyuncs.com

United States

https://cloudauth-device.us-west-1.aliyuncs.com

getToken interface

Obtain the device fingerprint deviceToken. It is recommended to call this once when a business action is triggered. Allow an interval of at least 2 seconds between the getToken call and the initialization call to ensure initialization has completed.

window.z_um.getToken();

//Pass bizId to bind this token to a unique business ID.
window.z_um.getToken(bizId); 

Integration example

<body>
<button type="button" id='register' onclick="login();">Log on</button>
<script type="text/javascript" src="https://o.alicdn.com/captcha-frontend/aliyunFP/fp.min.js"></script>
<script>

//Initialize at page load time
ALIYUN_FP.use('um', (state, um) => {
  if (state === 'loaded') {
    um.init({
        appKey: 'your_app_key',
        appName: 'your_web_app_name'
        //endpoints : ['https://cloudauth-device.aliyuncs.com']
    }, (state) => {
         //success indicates that the initialization is successful
         console.info(state);
      });
  }
});

//Business function, e.g. login
function login(){
    //Obtain the device fingerprint deviceToken. Allow at least 2 seconds between getToken and init.
    deviceToken = window.z_um.getToken();
    //Pass the deviceToken to your business server
    var data = {
           "deviceToken": deviceToken,
           "otherBusinessParams":""
     };
    //Send a backend request. The server queries risk information based on the deviceToken.
}

</script>
</body>

Call the Fraud Detection API

Pass the deviceToken and other parameters, refer to Server-side API integration, and call the Fraud Detection API for risk identification.

FAQ

For common questions about Device Fraud Detection integration, see FAQ.