# Octet Browser

Octet Browser returns a country verdict for each web session: the country the session is operating from, a confidence score, and an alarm level. Your backend receives the verdict, and your policy decides what happens next.

The current version is **v1.3.0**. See [Release Notes](/docs/browser/reference/release-notes/).

## What the verdict tells you

| Field | Meaning |
|---|---|
| `country` | The ISO 3166-1 alpha-2 code of the country the session is operating from, for example `"DE"`. Absent when Octet could not determine a country. |
| `confidence` | A number from `0` to `1`. Higher means Octet is more certain of `country`. |
| `alarm` | `none`, `low`, `medium` or `high`. How strongly the session's signals contradict `country`, or suggest the connection is masked. |

See [Verdicts](/docs/browser/concepts/verdicts/) for how to read each field, and [Verdict Reference](/docs/browser/reference/verdict/) for the exact shape.

## Using the verdict

- **Read the three fields together.** `confidence` and `alarm` tell you how much to rely on `country`. When `alarm` is `medium` or above, act on `alarm` rather than `country`.
- **Your backend makes the decision.** Octet does not allow or block sessions. Your backend decides whether to allow, challenge or log each one.
- **The verdict has a fourth field, `token`.** It is a signed copy of `country`, `confidence` and `alarm`, which you can verify and keep as a record. An auditor can check that record later against Octet's public key. See [Integrity and Audit](/docs/browser/concepts/integrity/).

## No prompts for your users

Octet Browser shows your users nothing. It never asks for permission to use location, camera, microphone or notifications, in any collection mode.

## The three parts of an integration

```mermaid
flowchart LR
    A[Browser<br/>collector] -->|HTTPS + WebSocket| B[Your edge<br/>octet-edge]
    B -->|mutual TLS| C[Octet API]
    D[Your backend] -->|GET /v1/verdict/:ref| C
```

1. **The collector** is a JavaScript file you serve from your own site. It runs in the user's browser and sends what it collects to your edge.
2. **The edge** is a small Linux binary you run on your own infrastructure. It receives the browser's connection directly and forwards the data to Octet over mutual TLS with your license token.
3. **Your backend** fetches the verdict directly from Octet with a read token, then applies your policy.

The browser never receives the verdict. Your backend is the only place it arrives. See [How It Works](/docs/browser/concepts/how-it-works/).

## Start here

- **Integrating for the first time:** [Quickstart](/docs/browser/getting-started/quickstart/)
- **Getting credentials:** [Credentials](/docs/browser/integration/credentials/)
- **Checking your CSP and firewall:** [Network and CSP](/docs/browser/reference/network/)
- **Something is failing:** [Errors](/docs/browser/reference/errors/) and [Troubleshooting](/docs/browser/troubleshooting/faq/)

## Access and support

- **Request access:** apply at [browser.octetproof.com/signup](https://browser.octetproof.com/signup). Octet reviews each application and emails your license token when it is approved.
- **Terms:** [Octet Browser terms](https://octetproof.com/terms/browser/).
- **Pricing:** [octetproof.com/pricing](https://octetproof.com/pricing/).
- **Integration support:** [developer@octetproof.com](mailto:developer@octetproof.com). Include the `sessionRef` and the time of the request. Never send a license token, read token or private key.
