Looking for a free, open-source browser fingerprinting library you can self-host? This guide covers FingerprintJS OSS, ThumbmarkJS, ClientJS, CreepJS, and ImprintJS side by side on license, cross-browser identity, maintenance status, and best-fit use case, so you can pick the right tool without a sales call.
The term 'browser fingerprinting library' covers a wide range: free open-source packages you drop into your own bundle, commercial SDKs with a free tier, and full SaaS platforms that happen to include a JavaScript snippet. When developers search for 'open source browser fingerprinting' or 'fingerprintjs free', they usually mean the first category: a library with a genuine open-source license that runs entirely client-side, needs no vendor account, and can be self-hosted without usage limits.
This guide focuses exclusively on that category. It covers five libraries you can install, audit, and run for free with no external API call and no subscription. It also notes where Benny the Doorman, the SDK this site publishes, fits: it is free and self-hosted but closed-source, so it is included for context rather than as a pure OSS pick.
Commercial platforms such as FingerprintJS Pro, SEON, and DataDome are mentioned only briefly as the paid alternative if you outgrow what a free library offers.
Open-source fingerprinting libraries at a glance
| Library | License | Cross-browser ID | Maintenance | Best for |
|---|---|---|---|---|
| FingerprintJS OSS | Open source (see note) | No | Active | Widest signal set, widest community, drop-in per-browser hash |
| ThumbmarkJS | MIT | No | Active | Modern, simple MIT-licensed per-browser hash |
| ClientJS | Apache 2.0 | No | Archived (last release 2021) | Lightweight, readable, permissive license |
| CreepJS | MIT | No | Active | Research, spoofing analysis, entropy auditing |
| ImprintJS | MIT | No | Early stage | Minimal dependency, simple integration |
| Benny the Doorman | Free (closed source) | Yes (client-side) | Active | Cross-browser hardware ID + free anti-spoof, not OSS |
FingerprintJS OSS
FingerprintJS is the most widely known name in browser fingerprinting and its open-source library is the most-starred fingerprinting package on GitHub. It reads a broad set of browser signals, hashes them, and returns a single per-browser identifier. The community is large, the documentation is thorough, and the library is actively maintained.
What the free tier does not include: cross-browser identity (the same physical device in Chrome and Safari produces two different hashes), anti-spoof or automation detection, and persistent server-resolved visitor IDs. Those capabilities live entirely in the paid FingerprintJS Pro platform, which is a separate commercial SaaS product. If you need only a per-browser hash with a wide signal set and a large community behind it, the open-source library is a solid baseline.
See the detailed breakdown in the /vs/fingerprintjs comparison, or the broader roundup in the best browser fingerprinting libraries guide.
ThumbmarkJS
ThumbmarkJS is a modern, MIT-licensed library built for simplicity. It is one of the most actively maintained open-source fingerprinting packages, with a clear MIT license, a readable codebase, and a published API. It produces a single per-browser hash.
It does not separate hardware signals from engine signals, so the same physical device returns a different hash in Chrome versus Safari. Anti-spoof detection is limited to a paid hosted tier. For teams that want a permissive-license, auditable library they can drop in today and know is being maintained, ThumbmarkJS is among the strongest free OSS choices available.
See the /vs/thumbmarkjs comparison for a feature-by-feature breakdown.
ClientJS
ClientJS is one of the original open-source fingerprinting libraries. It is Apache-2.0-licensed, lightweight, and easy to read end-to-end. It wraps a set of browser properties into a single numeric fingerprint with minimal dependencies.
The trade-off is maintenance: ClientJS's last public release was in 2021 and it does not include newer signal categories such as WebGPU or modern canvas techniques. There is no cross-browser identity and no anti-spoof detection. For simple, low-stakes visitor recognition on a project that values a small, auditable, permissively-licensed dependency over maximum entropy, it remains a reasonable pick. For anything that requires resilience to identity churn or active fraud, it is under-equipped.
See the /vs/clientjs page for a side-by-side comparison.
CreepJS
CreepJS is a research and demonstration project rather than a production identification library. Its focus is detecting lies in the browser environment: spoofed user agents, tampered APIs, automation frameworks, and anti-detect browsers. The output is a rich trust report with a lie-detection score, not a stable opaque hash you would store in a database.
Developers use CreepJS to study how identifiable a given browser configuration is, to audit their own fingerprint entropy, and to understand what anti-detect tooling looks like from a collector's perspective. It is MIT-licensed, actively maintained, and excellent at its specific job. It is not designed to be the fingerprinting primitive in a production app.
If you specifically need anti-spoof detection in production, CreepJS will show you what signals to look at, but is not itself the deployment target. See /vs/creepjs for a direct comparison.
ImprintJS
ImprintJS is a newer, MIT-licensed fingerprinting library focused on minimal dependencies and simple integration. It is in an earlier stage of development than FingerprintJS or ThumbmarkJS, with a smaller community and fewer documented integrations.
It produces a per-browser hash and is suitable for teams that want a lightweight, permissive-license option and are comfortable tracking a project early in its maturity arc. Cross-browser identity and anti-spoof detection are not currently offered. See /vs/imprintjs for a detailed comparison.
Benny the Doorman (context only - not OSS)
Benny the Doorman is the SDK this site publishes, so this section is the vendor's own view. It is included here because it is free and self-hosted (no vendor server, no account, no usage fees) but it is closed-source, so it does not belong in a pure OSS list.
Its distinguishing feature relative to the libraries above is cross-browser identity: it tags every signal as hardware-bound or engine-bound and returns two hashes, a per-browser fingerprint and a hardwareFingerprint that stays consistent across Chrome, Safari, Firefox, and Brave on the same physical device. It also ships a rule-based anti-spoof consistency check on every result, included in the free tier.
If your requirement is a genuinely open-source, auditable license, Benny is not the right pick. If your requirement is free, self-hosted, and cross-browser capable, it is the only client-side option in this list that delivers that.
Where commercial platforms fit
If you need capabilities beyond what any free library offers, such as server-resolved persistent visitor IDs that survive browser reinstalls, IP intelligence, native mobile SDKs, or enterprise SLAs, the relevant category shifts from 'free OSS library' to 'commercial platform'. FingerprintJS Pro, SEON, and DataDome are the leading options there.
The distinction is not just cost: a commercial platform routes device data through a vendor server, introduces a third-party dependency, and prices on usage. For teams with genuine enterprise requirements, that trade-off is often worth it. For teams that need a per-browser hash or client-side hardware identity, the free libraries above are sufficient.
The best browser fingerprinting libraries guide covers the full landscape including commercial platforms side by side.
Decision guide by job to be done
| Job to be done | Best free OSS fit |
|---|---|
| Per-browser hash, widest signal set, large community | FingerprintJS OSS |
| Per-browser hash, MIT license, actively maintained | ThumbmarkJS |
| Per-browser hash, minimal footprint, Apache license | ClientJS |
| Spoofing analysis, entropy auditing, anti-detect research | CreepJS |
| Minimal dependency, early-stage project | ImprintJS |
| Cross-browser hardware identity, free but closed-source | Benny the Doorman |
| Cross-browser ID, mobile SDKs, enterprise SLA | FingerprintJS Pro (commercial) |
Frequently asked questions
What is the best free open-source fingerprinting library?
It depends on what you need. FingerprintJS OSS has the widest signal set and the largest community. ThumbmarkJS is the most actively maintained MIT-licensed option and the simplest modern drop-in. ClientJS is lighter but has not had a release since 2021. CreepJS is best for spoofing research rather than production identification. If you need cross-browser device identity and an OSS license is not a hard requirement, Benny the Doorman provides it for free.
Is FingerprintJS still open source?
FingerprintJS has an open-source client-side library available on GitHub, but its license has changed across major versions (MIT, then Business Source License, then MIT again), so confirm the license of the specific version you are adopting. The advanced features - cross-browser persistent visitor IDs, IP intelligence, and anti-spoof detection - are part of FingerprintJS Pro, which is a commercial SaaS platform and not open source.
Can I self-host browser fingerprinting for free?
Yes. All the OSS libraries in this guide - FingerprintJS OSS, ThumbmarkJS, ClientJS, CreepJS, and ImprintJS - run entirely client-side in your JavaScript bundle with no external API call and no usage limits. Benny the Doorman is also free and self-hosted but is closed-source. The only options that require a vendor server are commercial platforms such as FingerprintJS Pro, SEON, and DataDome.
What is the difference between FingerprintJS free and FingerprintJS Pro?
The free open-source FingerprintJS library returns a single per-browser hash computed client-side. FingerprintJS Pro is a separate commercial SaaS platform that adds server-side resolution for a persistent visitor ID that survives cookie clears and browser reinstalls, cross-browser identity, IP intelligence, ML-based bot and spoof detection, and native mobile SDKs. The Pro platform is priced per identification above a monthly free allowance.
Which open-source fingerprinting library works across Chrome, Safari, and Firefox?
None of the OSS libraries in this guide produce a stable cross-browser hardware identity by default: they all return a per-browser hash that differs between Chrome and Safari on the same device. Cross-browser device identity requires either a commercial platform (FingerprintJS Pro, SEON) or Benny the Doorman, which resolves a hardware fingerprint client-side for free but is closed-source.
Does CreepJS work as a production fingerprinting library?
CreepJS is a research and demonstration project, not a production identification library. Its output is a detailed trust report oriented toward detecting browser lies and anti-detect tooling, not a stable hash you would store as a visitor ID. For production use, FingerprintJS OSS, ThumbmarkJS, or Benny the Doorman are more appropriate choices.
Get started
Need cross-browser identity on top of a free library?
Benny the Doorman returns both a per-browser fingerprint and a deterministic cross-browser hardware ID in a single client-side call, with free anti-spoof scoring. No server roundtrip, no account, no usage-based billing.
Last reviewed July 12, 2026

