How Stripe's card fingerprint can catch affiliate self-referral fraud
Affiliate self-referral fraud occurs when someone uses their own referral link to sign up under a second account and collect commissions on their own payments. Common detection methods like email, IP address, and device fingerprints are easily bypassed using disposable emails, VPNs, and anti-detect browsers. Stripe offers a more reliable signal through a card fingerprint — an opaque string derived from the underlying card number that remains consistent across different customer accounts within the same Stripe account. This means two accounts with different emails, IPs, and browsers will share the same fingerprint if they use the same physical card, making self-referrals detectable. Developers can retrieve this fingerprint via Stripe's PaymentMethod or Charge API and store it safely in a database without entering additional PCI compliance scope.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in