Docs/Octet Browser/Octet Browser

Octet Browser

Octet Browser returns a country verdict for each web session: the country the session is operating from, a confidence score, and an alarm level. Your backend receives the verdict, and your policy decides what happens next.

The current version is v1.3.0. See Release Notes.

What the verdict tells you

Field Meaning
country The ISO 3166-1 alpha-2 code of the country the session is operating from, for example "DE". Absent when Octet could not determine a country.
confidence A number from 0 to 1. Higher means Octet is more certain of country.
alarm none, low, medium or high. How strongly the session's signals contradict country, or suggest the connection is masked.

See Verdicts for how to read each field, and Verdict Reference for the exact shape.

Using the verdict

  • Read the three fields together. confidence and alarm tell you how much to rely on country. When alarm is medium or above, act on alarm rather than country.
  • Your backend makes the decision. Octet does not allow or block sessions. Your backend decides whether to allow, challenge or log each one.
  • The verdict has a fourth field, token. It is a signed copy of country, confidence and alarm, which you can verify and keep as a record. An auditor can check that record later against Octet's public key. See Integrity and Audit.

No prompts for your users

Octet Browser shows your users nothing. It never asks for permission to use location, camera, microphone or notifications, in any collection mode.

The three parts of an integration

flowchart LR
    A[Browser<br/>collector] -->|HTTPS + WebSocket| B[Your edge<br/>octet-edge]
    B -->|mutual TLS| C[Octet API]
    D[Your backend] -->|GET /v1/verdict/:ref| C
  1. The collector is a JavaScript file you serve from your own site. It runs in the user's browser and sends what it collects to your edge.
  2. The edge is a small Linux binary you run on your own infrastructure. It receives the browser's connection directly and forwards the data to Octet over mutual TLS with your license token.
  3. Your backend fetches the verdict directly from Octet with a read token, then applies your policy.

The browser never receives the verdict. Your backend is the only place it arrives. See How It Works.

Start here

Access and support