IP fingerprinting is the practice of using a visitor's IP address, or attributes derived from it, to identify or categorise a network connection. Because many devices share a single IP and addresses change frequently, IP fingerprinting is a weak standalone identifier. It is most useful when combined with device or browser fingerprinting to build a richer, more stable visitor profile.
An IP address identifies where a request originates on the network, not which specific device or browser sent it. In a home network, all devices behind a router share one public IP. In a mobile network, carrier-grade NAT (CGNAT) pools thousands of subscribers behind a handful of addresses. A user switching from Wi-Fi to mobile data gets a different IP entirely. These realities mean IP alone produces many false matches and frequent misses.
Beyond NAT and CGNAT, VPNs and proxy services let users deliberately rotate or mask their IP. A user connecting through a commercial VPN appears to come from whichever exit node they choose, which is unrelated to their actual location or device. This makes IP a signal that is both noisy and easily spoofed.
Despite its limits, IP fingerprinting has legitimate uses. Geo-routing uses IP to route requests to the nearest data centre. Fraud and abuse teams flag IPs associated with known data-centre ranges or Tor exit nodes as elevated-risk connections. Rate limiters and DDoS mitigations act on IP because it is available at the network layer before any JavaScript runs.
Device and browser fingerprinting are a natural complement to IP: they identify the specific device rather than its current network address, and they remain stable across IP changes. A combined signal, the IP for real-time network-level risk plus a device fingerprint for cross-session continuity, captures what neither approach achieves alone.
In doorman-benny
doorman-benny is a client-side library and does not collect or expose the visitor's IP address. IP remains a server-side signal that the calling application reads from the HTTP request. The `fingerprint` and `hardwareFingerprint` values Benny returns are complementary to IP: they identify the specific device regardless of which IP it currently uses, so the two signals can be combined server-side for a fuller picture of each visit.
Fingerprint vs cookies vs IPFrequently asked questions
Is an IP address a fingerprint?
Not in the precise sense. A fingerprint is derived from multiple observable characteristics of a device or browser and is specific to that device. An IP address identifies a network connection, which may be shared by many devices at once and changes whenever the connection changes. Calling an IP address a fingerprint overstates its specificity.
What is the difference between IP fingerprinting and device fingerprinting?
IP fingerprinting looks at the network address a request arrives from, which reflects the user's current connection, not their device. Device fingerprinting measures characteristics of the hardware and software itself, such as screen properties, rendering output, and installed capabilities. Device fingerprinting is more specific and far more stable across network and IP changes.
Can you reliably identify a user by IP address alone?
Rarely. Shared Wi-Fi, corporate networks, mobile carriers, and VPNs mean one IP may represent hundreds of different users, and a single user may appear under many IPs over time. IP is a useful supporting signal for risk and geo-routing decisions, but it cannot substitute for device or browser fingerprinting when per-device identification is needed.
How does CGNAT affect IP-based identification?
Carrier-grade NAT (CGNAT) allows mobile and broadband providers to assign a single public IP to a large pool of subscribers. Users behind CGNAT are indistinguishable from one another at the IP level, which makes IP a poor identifier for those networks and underscores the value of pairing it with a device-level signal.

