Server-side siteverify gates /api/identify when enabled. Off by default
(soft mode) so the demo runs without configuration.
Confidence
–
stable signals contributing
Identification
Client signals
Edge / network
Fingerprint hash
–
stable
SHA-256 over normalized client + edge signals. The visitor id is an HMAC-SHA256 of this
hash keyed by a server secret, so it cannot be forged client-side.