Docs/Octet Browser/Octet Browser

Octet Browser

Octet Browser estimates which country a web session is operating from, and tells you how much to doubt that estimate. Your backend receives a verdict for each session: a country, a confidence score, and an alarm level. Your own policy decides what happens next.

The current version is v1.2.0. See Release Notes.

What the verdict tells you

Field Meaning
country The ISO 3166-1 alpha-2 code of the country Octet estimates the session is operating from, for example "DE".
confidence A number from 0 to 1. Higher means Octet is more certain of country.
alarm none, low, medium or high. How strongly the session's signals contradict country, or suggest the connection is masked.

See Verdicts for how to read each field, and Verdict Reference for the exact shape.

Using the verdict

  • Read it as an estimate. country is Octet's best estimate, and confidence and alarm tell you how much to rely on it. When alarm is medium or above, act on alarm rather than country.
  • Your policy makes the call. Octet reports each session, and you decide whether to allow it, challenge it or log it.
  • These three fields are the whole verdict. Your backend also receives a signed copy of them, which you can verify and keep as a record.

No prompts for your users

Octet Browser shows your users nothing. It never asks for permission to use location, camera, microphone or notifications, in any collection mode.

The three parts

flowchart LR
    A[Browser<br/>collector] -->|HTTPS + WebSocket| B[Your edge<br/>octet-edge]
    B -->|HTTPS| C[Octet API]
    D[Your backend] -->|GET /v1/verdict/:ref| C
  1. The collector is a JavaScript file you serve from your own site. It runs in the user's browser and sends what it collects to your edge.
  2. The edge is a small Linux binary you run on your own infrastructure. It receives the browser's connection directly and forwards the data to Octet with your license token.
  3. Your backend fetches the verdict from Octet server to server, using a read token, and applies your policy.

The browser never receives the verdict. Your backend is the only place it arrives. See How It Works.

Start here

Access and support