What it is
Canvas fingerprinting asks your browser to draw a hidden image — some text, a few shapes, an emoji — and reads the pixels back. Two machines never draw it exactly the same way, so the pixels become an ID. It is one of the most stable signals a site can get without asking for any permission.
How websites read it
const ctx = canvas.getContext('2d');
ctx.fillText('Cwm fjordbank gly 😃', 2, 15);
const id = hash(canvas.toDataURL());The whole thing takes a few milliseconds and leaves no trace on the page.
Why it identifies you
The final pixels depend on your GPU, graphics driver, operating system, installed fonts, anti-aliasing and colour-management settings. Change any of those and the image changes; keep them and the image stays identical for months.
How risk-control systems use it
They rarely care about the hash itself. They check whether it behaves like a real canvas: does the same drawing give the same result twice? Does an OffscreenCanvas agree with the on-screen one? Is toDataURL still the browser's own function? Random per-call noise — the naive way to “protect” canvas — fails all three and reads as a modified browser.
Common mistakes
Browser extensions that add random noise; “canvas blocker” flags that return blank images; sharing one canvas value across profiles that claim different hardware.
Mango is accepting waitlist registrations. These capabilities describe its first release; client access opens with invitations.
How Mango Browser handles it
NoiseSeeded noise: each profile has its own stable seed, so its canvas is unique across profiles yet identical on every draw, on-screen or off-screen. Mode: Noise (default) or Real.
Check yours
Jump to this signal in your scan results.