MIRA FIVE

Identify users

Tie events to a browser, a session and a signed-in person, reset them on logout, and link browser and server events.

Identifying users ties events to the same browser, the same visit and your own user id, so MIRA FIVE can count people instead of pageviews. It needs full mode and the visitor's consent. In the default consentless mode there are no ids at all, and none of this applies.

The three ids

IdWhat it isWho sets itWhere it lives
Anonymous idA UUID for one browserThe browser SDK, on the first event after consentlocalStorage, 365 days since last seen
Session idA UUID for one visitThe browser SDKlocalStorage, ends after 30 minutes without an event
User idYour own id for the signed-in personYou, with identify()Memory of the page; sent on every later event

Sessions live in localStorage, not sessionStorage, so a link opened in a new tab stays in the same session.

The user id is pseudonymous: pass your internal id (u_42, a UUID, a database key), never an email address. It has 1 to 256 characters. In development, the browser SDK warns when an id contains @.

Turn on full mode

Full mode needs the identity code in the page and a consent answer:

<script>window.mirafive=window.mirafive||function(){(mirafive.q=mirafive.q||[]).push(arguments)}</script>
<script defer src="https://cdn.mirafive.io/mira.js" data-key="mf_…" data-mode="full"></script>

The identity chunk downloads on the first consent grant.

Before a consent answer, full mode stores nothing and sends nothing. Pass the answer from your consent manager with consent(), as described in Consent. Events are sent once statistics consent is granted.

Identify after login

Call identify(userId, traits) once the person is signed in. It sends $identify with the traits as properties, and every later event on the page carries the user id:

<script>
  mirafive('identify', 'u_42', { plan: 'pro' })
</script>

Rules:

  • The user id is kept in memory only. Call identify() on every page load while the person is signed in, not only right after the login form.
  • $identify needs statistics consent. Called before the grant, the user id is kept and stamped on later events, but the $identify event itself is dropped. Call identify() again after the grant to send the traits.
  • Traits follow the property limits and hold no personal data you do not need: a plan or a role, not a name or an email address.
  • When a different user signs in on the same browser, the SDK starts fresh anonymous and session ids first, so two people never share one.

Reset on logout

Call reset() when the person signs out. It forgets the user, the anonymous id and the session, so the next event starts new ones:

<script>
  document.querySelector('#logout').addEventListener('click', () => mirafive('reset'))
</script>

A consent decline (consent(false)) does the same and also clears the queue.

A server does not know the browser's anonymous id unless the page sends it. Read it with anonymousId() and pass it with your own request, under any header or field name you choose. It is undefined without statistics consent.

<script>
  mirafive('anonymousId', (anonymousId) => {
    document.querySelector('input[name=mirafive_anonymous_id]').value = anonymousId ?? ''
  })
</script>

On the server, pass it with the event. identify() with an anonymous id links that browser to the user:

const anonymousId = request.headers.get('X-Anonymous-Id') || undefined

mira.identify(user.id, { plan: user.plan }, { anonymousId })
mira.track('order completed', { userId: user.id, anonymousId, properties: { revenue: 49.9, currency: 'EUR' } })

Server events are sent in full mode by default, and you hold the consent for the ids you pass. Only pass an anonymous id the page gave you, which exists only after statistics consent. Server flag reads take the same id to keep a visitor's variants: see Feature flags.

What is stored where

WhereWhatLifetime
localStorage mirafive:{ns}:aid{anonymousId}.{lastSeenMs}365 days since last seen
localStorage mirafive:{ns}:sid{sessionId}.{lastSeenMs}30 minutes idle
localStorage mirafive:{ns}:uidA hash of the user id, only to notice a different user signing in365 days
Page memoryThe user id and traits from identify()Until the page unloads or reset()

{ns} is the key's namespace: the website key without its last _… part, for example mf_ab12cd34, so the key's tail is never stored. The SDKs set no cookies, in any mode. Nothing is stored before a consent scope is granted, and consent(false) or reset() removes all three entries.

Server SDKs store nothing on the visitor's device.

Troubleshooting

SymptomCause and fix
Events have no user ididentify() did not run on this page load. Call it on every load while signed in.
No $identify eventIt ran before statistics consent. Call identify() again after the grant.
anonymousId() is undefinedNo statistics consent yet, the page is in consentless mode, or Do Not Track or Global Privacy Control is on.
identify() does nothingThe client has no identity() plugin or runs in consentless mode. A development warning says identify() needs its plugin.
Server throws on userIdThe server client is in consentless mode. Use full mode where you hold consent.

On this page