Octet Browser
Octet Browser returns a country verdict for each web session: the country the session is operating from, a confidence score, and an alarm level. Your backend receives the verdict, and your policy decides what happens next.
The current version is v1.3.0. See Release Notes.
What the verdict tells you
| Field | Meaning |
|---|---|
country |
The ISO 3166-1 alpha-2 code of the country the session is operating from, for example "DE". Absent when Octet could not determine a country. |
confidence |
A number from 0 to 1. Higher means Octet is more certain of country. |
alarm |
none, low, medium or high. How strongly the session's signals contradict country, or suggest the connection is masked. |
See Verdicts for how to read each field, and Verdict Reference for the exact shape.
Using the verdict
- Read the three fields together.
confidenceandalarmtell you how much to rely oncountry. Whenalarmismediumor above, act onalarmrather thancountry. - Your backend makes the decision. Octet does not allow or block sessions. Your backend decides whether to allow, challenge or log each one.
- The verdict has a fourth field,
token. It is a signed copy ofcountry,confidenceandalarm, which you can verify and keep as a record. An auditor can check that record later against Octet's public key. See Integrity and Audit.
No prompts for your users
Octet Browser shows your users nothing. It never asks for permission to use location, camera, microphone or notifications, in any collection mode.
The three parts of an integration
flowchart LR
A[Browser<br/>collector] -->|HTTPS + WebSocket| B[Your edge<br/>octet-edge]
B -->|mutual TLS| C[Octet API]
D[Your backend] -->|GET /v1/verdict/:ref| C
- The collector is a JavaScript file you serve from your own site. It runs in the user's browser and sends what it collects to your edge.
- The edge is a small Linux binary you run on your own infrastructure. It receives the browser's connection directly and forwards the data to Octet over mutual TLS with your license token.
- Your backend fetches the verdict directly from Octet with a read token, then applies your policy.
The browser never receives the verdict. Your backend is the only place it arrives. See How It Works.
Start here
- Integrating for the first time: Quickstart
- Getting credentials: Credentials
- Checking your CSP and firewall: Network and CSP
- Something is failing: Errors and Troubleshooting
Access and support
- Request access: apply at browser.octetproof.com/signup. Octet reviews each application and emails your license token when it is approved.
- Terms: Octet Browser terms.
- Pricing: octetproof.com/pricing.
- Integration support: developer@octetproof.com. Include the
sessionRefand the time of the request. Never send a license token, read token or private key.