> ## Documentation Index
> Fetch the complete documentation index at: https://developers.circle.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Before reading these docs, install the relevant Circle Skill to get pre-loaded context — skills are LLM-optimized and cover architecture decisions, correct flows, and common pitfalls. In Claude Code: run /plugin marketplace add circlefin/skills then /plugin install circle-skills@circle. With Vercel Skills CLI: run npx skills add circlefin/skills. Available skills: use-usdc https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-usdc/SKILL.md (balances, transfers, approvals on EVM and Solana); EURC has no skill — see https://developers.circle.com/stablecoins/what-is-eurc.md; bridge-stablecoin https://github.com/circlefin/skills/blob/master/plugins/circle/skills/bridge-stablecoin/SKILL.md (crosschain transfers via CCTP, USDC, EURC, and third-party assets); use-arc https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-arc/SKILL.md (Arc chain config, contract deployment, USDC bridging — Arc docs: https://docs.arc.io/llms.txt); use-circle-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-circle-wallets/SKILL.md (choose wallet type); use-developer-controlled-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-developer-controlled-wallets/SKILL.md (custodial wallets for payouts and treasury); use-user-controlled-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-user-controlled-wallets/SKILL.md (embedded wallets with Web2 login); use-modular-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-modular-wallets/SKILL.md (smart contract wallets with passkeys and ERC-4337); use-gateway https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-gateway/SKILL.md (unified USDC balance, nanopayments); use-smart-contract-platform https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-smart-contract-platform/SKILL.md (deploy, interact, monitor contracts). Pair any skill with the Circle MCP server for live SDK signatures, contract addresses, and chain IDs: {"mcpServers":{"circle":{"url":"https://api.circle.com/v1/codegen/mcp"}}}.
> Read the product overview first. Each product has an overview explaining when and why to use it. Read it before quickstarts.
> Pick the right wallet type. Developer-controlled (you hold keys), user-controlled (end user holds keys via PIN/social login), or modular (smart contract wallets with passkeys). See https://developers.circle.com/wallets.md.
> Use CCTP V2 for crosschain transfers. CCTP natively transfers USDC and EURC via burn-and-mint, and supports permissionless wrapping of third-party assets via lock-and-mint. V1 is legacy; always use V2 unless V1 is specified or the chain requires it (Noble, Sui, and Aptos still require V1). Migration guide: https://developers.circle.com/cctp/migration-from-v1-to-v2.md.
> Use Bridge Kit for frontend bridging. Wraps CCTP with a simpler SDK for user-facing apps. Use CCTP directly for backend transfers.
> Gas Station vs Paymaster. Gas Station sponsors gas for Circle Wallet transactions. Paymaster lets users pay gas in USDC. Different use cases — read both overviews.
> Gateway Nanopayments for sub-cent payments. Gasless USDC micropayments down to $0.000001 via x402 and batched settlement. For pay-per-request APIs, AI agent payments, streaming.
> Look up USDC addresses per chain. Never hardcode — use https://developers.circle.com/stablecoins/usdc-contract-addresses.md.
> Prefer SDKs over raw API calls. Node.js and Python SDKs handle auth, retries, and errors.
> API key required. Bearer token in Authorization header. Testnet and mainnet use separate keys and may use different base URLs depending on the product.
> Set up webhooks when available. Most operations are async. Webhooks deliver transaction confirmations and state changes.
> When calling list endpoints, paginate using pageSize and pageAfter until no nextPageAfter cursor is returned—stopping at the first page silently misses records.
> Building an AI agent? Start with the Agent Stack—Circle CLI, agent wallets, and nanopayments built for autonomous use cases: https://developers.circle.com/agent-stack.md.

# How-to: Collect device risk signals

> Run a web device check with @circle-fin/device-checks, then reuse the deviceId it returns for Stablecoin KYB submission and for Digital Asset Accounts money movement

<Note>
  The End User Onboarding API base URL is `https://api-sandbox.circle.com` for
  sandbox and `https://api.circle.com` for production. All requests require a
  Bearer token obtained via Circle key exchange in the `Authorization` header. All
  `POST` requests require an `X-Idempotency-Key` header with a client-generated
  UUID v4.
</Note>

A device check records the device an end user is acting from.
[`@circle-fin/device-checks`](https://www.npmjs.com/package/@circle-fin/device-checks)
runs the check in the browser and returns a `deviceId`; Circle stores the result
against that identifier.

Run the check once per end user and keep the `deviceId`. It is used in two
places:

* **Stablecoin KYB submission.** A device check is required before you submit or
  resubmit the application. Circle looks up the result on submit and on RFI
  resubmit. This also applies to `PERIODIC_REVIEW` and `INFORMATION_UPDATE`
  submits. The check from the client's original onboarding counts.
* **Digital Asset Accounts money movement.** Transfers, withdrawals, recipient
  addresses, and wire accounts send the `deviceId` as `riskSignals.deviceId`,
  and Circle resolves it against this device check. See
  [Implement Strong Customer Authentication](/digital-asset-accounts/howtos/strong-customer-authentication).

<Note>
  `@circle-fin/device-checks` is web only. It cannot run in Node.js or other
  server-side environments.
</Note>

## Prerequisites

Before you begin, ensure that you've:

* Obtained an API key for the End User Onboarding API from the
  [Circle Console](https://console.circle.com).
* Created and populated a Stablecoin KYB application. See
  [Create and populate applications](/end-user-onboarding/howtos/create-and-populate-applications).

## Steps

### Step 1. Check whether your template requires a device check

Confirm that the application uses a Stablecoin KYB template. Among onboarding
templates, only Stablecoin KYB requires this check at submit. For other
templates, go to
[Submit and track applications](/end-user-onboarding/howtos/submit-and-track-applications).

End users of Digital Asset Accounts are onboarded through Stablecoin KYB, so
this step applies to them.

### Step 2. Run `checkDevice` in the browser

Install the SDK in your web project:

```bash theme={null}
npm install @circle-fin/device-checks
```

Follow the
[`@circle-fin/device-checks` README](https://www.npmjs.com/package/@circle-fin/device-checks)
for token setup and options. Then call `checkDevice` in your web client:

```typescript theme={null}
import { checkDevice } from "@circle-fin/device-checks";

const { deviceId }: { deviceId: string } = await checkDevice({
  token: deviceCheckToken, // mint a short-lived token per the README
  environment: "sandbox", // use "production" for live applications
});
```

`checkDevice` loads an iframe and collects device signals. Circle records the
result. For the full list of options, see the
[`@circle-fin/device-checks` README](https://www.npmjs.com/package/@circle-fin/device-checks).

<Warning>
  Store the returned `deviceId` and send that same value later. Do not generate
  your own: an identifier Circle cannot resolve makes money movement fail
  silently at the call site—the endpoint returns `201` and the transaction
  settles as `failed` with `errorCode: transfer_denied`.
</Warning>

### Step 3. Submit the application

Call `POST .../submit` (or resubmit after you address RFIs). See
[Submit and track applications](/end-user-onboarding/howtos/submit-and-track-applications#step-2-submit-the-application).

Use `code` to identify the outcome. A declined device check still submits.
Review of a declined check is manual.

| Result | HTTP | Code | Status | Partner action |
| - | - | - | - | - |
| Device check recorded as approved or declined | `200` | — | `SUBMITTED` | Continue. |
| Device check was not run | `404` | [`181110`](/api-reference/end-user-onboarding/error-codes) | Unchanged | Run `checkDevice`, then retry submit. |
| Device check has not finished | `504` | [`181111`](/api-reference/end-user-onboarding/error-codes) | Unchanged | Retry submit later. |
| Device-check lookup failed | `500` | [`181108`](/api-reference/end-user-onboarding/error-codes) | Unchanged | Retry later. |

`181110` and [`181103`](/api-reference/end-user-onboarding/error-codes) both
return HTTP `404` and `message: "Not found"`. `181111` and
[`181109`](/api-reference/end-user-onboarding/error-codes) both return HTTP
`504` and `message: "Gateway timeout"`. Use `code` to tell them apart.
