# Octet Browser

Octet Browser estimates which country a web session is operating from, and tells you how much to doubt that estimate. Your backend receives a verdict for each session: a country, a confidence score, and an alarm level. Your own policy decides what happens next.

The current version is **v1.2.0**. See [Release Notes](/docs/browser/reference/release-notes/).

## What the verdict tells you

| Field | Meaning |
|---|---|
| `country` | The ISO 3166-1 alpha-2 code of the country Octet estimates the session is operating from, for example `"DE"`. |
| `confidence` | A number from `0` to `1`. Higher means Octet is more certain of `country`. |
| `alarm` | `none`, `low`, `medium` or `high`. How strongly the session's signals contradict `country`, or suggest the connection is masked. |

See [Verdicts](/docs/browser/concepts/verdicts/) for how to read each field, and [Verdict Reference](/docs/browser/reference/verdict/) for the exact shape.

## Using the verdict

- **Read it as an estimate.** `country` is Octet's best estimate, and `confidence` and `alarm` tell you how much to rely on it. When `alarm` is `medium` or above, act on `alarm` rather than `country`.
- **Your policy makes the call.** Octet reports each session, and you decide whether to allow it, challenge it or log it.
- **These three fields are the whole verdict.** Your backend also receives a signed copy of them, which you can verify and keep as a record.

## No prompts for your users

Octet Browser shows your users nothing. It never asks for permission to use location, camera, microphone or notifications, in any collection mode.

## The three parts

```mermaid
flowchart LR
    A[Browser<br/>collector] -->|HTTPS + WebSocket| B[Your edge<br/>octet-edge]
    B -->|HTTPS| C[Octet API]
    D[Your backend] -->|GET /v1/verdict/:ref| C
```

1. **The collector** is a JavaScript file you serve from your own site. It runs in the user's browser and sends what it collects to your edge.
2. **The edge** is a small Linux binary you run on your own infrastructure. It receives the browser's connection directly and forwards the data to Octet with your license token.
3. **Your backend** fetches the verdict from Octet server to server, using a read token, and applies your policy.

The browser never receives the verdict. Your backend is the only place it arrives. See [How It Works](/docs/browser/concepts/how-it-works/).

## Start here

- **Integrating for the first time:** [Quickstart](/docs/browser/getting-started/quickstart/)
- **Getting credentials:** [Credentials](/docs/browser/integration/credentials/)
- **Checking your CSP and firewall:** [Network and CSP](/docs/browser/reference/network/)
- **Something is failing:** [Errors](/docs/browser/reference/errors/) and [Troubleshooting](/docs/browser/troubleshooting/faq/)

## Access and support

- **Request access:** apply at [browser.octetproof.com/signup](https://browser.octetproof.com/signup). Octet reviews each application and emails your license token when it is approved.
- **Terms:** [Octet Browser terms](https://octetproof.com/terms/browser/).
- **Pricing:** [octetproof.com/pricing](https://octetproof.com/pricing/).
- **Integration support:** [developer@octetproof.com](mailto:developer@octetproof.com). Include the `sessionRef` and the time of the request. Never send a license token, read token or private key.
