Integrations
Segment and Amplitude integration
Keep the reports your team already uses. DataCops sends every session into Segment and Amplitude marked clean or bot, with the reason, so any chart, funnel or audience can show real visitors only.
What it is
DataCops checks every session on your own domain for bots, VPNs, proxies, Tor and data-center traffic. This integration sends that verdict into Segment and Amplitude as one event per session, so your existing analytics can separate real people from bots.Nothing in your current Segment tracking plan or Amplitude project changes. DataCops only adds one event, next to the events you already send.
There are two ways in, and you can use both:
- Verdict on every page (dataLayer). The DataCops script puts the verdict on the page, and your own Segment or Tag Manager adds it to the events you already send. It lands on your own IDs, anonymous visitors included. You set it up yourself, below.
- Server feed. One
DataCops Session Scoredevent per session, sent from our servers into Segment and Amplitude. You connect it yourself in the dashboard, see Server feed setup.
Verdict on every page (dataLayer)
Turn it on, add a few lines to your Segment setup, and every event you already send carries datacops_verdict and datacops_clean. No keys, nothing from us.Turn it on
In DataCops, open Settings, Script Setup and switch on Bot verdict in your dataLayer. It reaches your pages within 5 minutes. Owners and team members can switch it.
Check it on a page
Open your site (staging is fine, as long as it runs the DataCops script), open the browser console and type
window.datacopsVerdict. You see the verdict for your own visit.window.dataLayershows thedatacops_verdictevents.Add it to your events
Pick Segment or Tag Manager below.
What the event looks like
window.dataLayer.push({
event: "datacops_verdict",
datacops_verdict: "human", // "human", "bot" or "pending"
datacops_clean: true, // false for bots and for VPN, proxy, Tor or data-center visits
datacops_reasons: "", // why, for example "headless browser detected, data center"
datacops_verdict_source: "server", // "browser" first, then "server" once our checks finish
datacops_session_id: "session_...", // only when the visitor allowed analytics
datacops_version: 1
}); The same values are kept on window.datacopsVerdict (fields verdict, clean, reasons, source, session_id), and a datacops:verdict browser event fires when the verdict is first known and when it changes during the visit (not on every page).
When it fires:
- First page of a visit: straight away, with the browser's own check (
source: "browser"). - A few seconds later: once more, with our server checks added (IP, VPN, proxy, Tor, data center),
source: "server". - Every later page: straight away, with the final verdict. No extra request.
- Needs the full DataCops snippet (it includes the small
stubfile that carries this switch). A custom install that loads only the main script gets no verdict.
pending means neither the browser check nor our server had a verdict yet (rare); the next page asks again.
Segment
Add this once, after your Segment snippet. It puts the latest verdict on every track and page call, so Amplitude and every other Segment destination get it on your own IDs.
analytics.addSourceMiddleware(({ payload, next }) => {
const v = window.datacopsVerdict;
const type = payload.obj.type;
if (v && (type === "track" || type === "page")) {
payload.obj.properties = Object.assign({}, payload.obj.properties, {
datacops_verdict: v.verdict,
datacops_clean: v.clean,
datacops_reasons: v.reasons,
datacops_verdict_source: v.source
});
}
next(payload);
}); On the first page of a visit, events sent in the first few seconds can go out before the verdict exists (our checks need a moment). From the second page on, every event carries it, and usually the page call too (the verdict is restored early, but your page call can still win the race). To have a record for every visit, also send one event when the verdict arrives or changes (at most two per visit):
window.addEventListener("datacops:verdict", (e) => {
analytics.track("DataCops Verdict", {
datacops_verdict: e.detail.verdict,
datacops_clean: e.detail.clean,
datacops_reasons: e.detail.reasons,
datacops_verdict_source: e.detail.source
});
}); Google Tag Manager
- Variables, New, Data Layer Variable: one each for
datacops_verdict,datacops_cleananddatacops_reasons. - Triggers, New, Custom Event, event name
datacops_verdict. - Add the variables as parameters on the tags you want to carry them (for example a GA4 event or your Segment tag), or fire a tag on the trigger.
In Amplitude
Filter any chart, funnel or cohort on datacops_clean = true for real visitors only, or group by datacops_verdict and datacops_reasons to see where bots come from.
Privacy
The verdict describes the visit (a bot check), not the person, and is on the page for every visit. The DataCops session ID is added only when the visitor allowed analytics. Your own consent setup still decides what Segment or Tag Manager sends on.
How it works, step by step
A visitor lands on your site
The DataCops script runs on your own subdomain and opens a session. It records the landing page, the referrer and where the visit came from.
The session gets a verdict
DataCops runs its bot checks in the browser and its IP checks on the server. The result is stored on the session: bot or not, the reasons, and one true/false for VPN, proxy, Tor and data center.
Every two minutes, new sessions are collected
A background job looks for sessions that started since the last successful run for your site. It takes up to 500 sessions per run, oldest first, so a busy site catches up over the next runs instead of skipping anything.
Each session is sent as one event
Each session becomes one
DataCops Session Scoredevent. Segment gets it through its HTTP tracking API. Amplitude gets it through its HTTP API, in the region your project lives in.Every send is logged
Each send is written to the DataCops audit log as sent, failed or skipped. If one session fails, the rest of the batch still goes out.
The data is the same session data you can pull yourself from the export API. This integration simply pushes it to you, so nobody has to run a script.
What arrives
Every session arrives as one event named DataCops Session Scored. Clean and flagged sessions are both sent, so your totals always add up. The event carries these properties:
| Property | What it means |
|---|---|
is_clean | true when the session is not a bot, VPN, proxy, Tor or data-center visit. The one field to filter on. |
is_bot | true when the session was flagged as automated. |
bot_reasons | The signals that fired, for example headless browser detected. |
is_vpn, is_proxy, is_tor, is_datacenter | The network checks, one true/false each. |
country, city | Where the visit came from. |
referrer, landing_url | Where the visitor arrived from and the first page they saw. |
session_id | The DataCops session. Also used as the anonymous ID when there is no user ID. |
source | Always datacops, so you can tell these events apart. |
Sessions are sent every two minutes through the official Segment and Amplitude APIs. For Amplitude, DataCops sends to the EU or US data center, matching your project.
One small difference between the two tools: in Segment, country and city sit inside the event properties. In Amplitude they go into Amplitude's own country and city fields, so they work with its built-in location filters.
Example events
This is the shape of one session as Segment receives it. The values are an example.
{
"anonymousId": "<session id>",
"event": "DataCops Session Scored",
"timestamp": "2026-10-01T09:14:02.000Z",
"properties": {
"session_id": "<session id>",
"is_clean": false,
"is_bot": true,
"is_vpn": false,
"is_proxy": false,
"is_tor": false,
"is_datacenter": true,
"bot_reasons": "headless browser detected",
"country": "US",
"city": "Ashburn",
"referrer": "https://example-referrer.com/",
"landing_url": "https://yourshop.com/landing",
"source": "datacops"
},
"context": { "library": { "name": "datacops", "version": "1.0.0" } }
} The same session in Amplitude looks like this:
{
"device_id": "<session id>",
"event_type": "DataCops Session Scored",
"time": 1790846042000,
"event_properties": {
"session_id": "<session id>",
"is_clean": false,
"is_bot": true,
"is_datacenter": true,
"bot_reasons": "headless browser detected",
"source": "datacops"
},
"country": "US",
"city": "Ashburn"
} The Amplitude example is shortened. It carries the same VPN, proxy, Tor, referrer and landing page properties as the Segment event.
Using it in your reports
- Real visitors only: filter any chart or audience on
is_clean = true. - How much traffic is fake: compare
is_clean = trueandfalseby channel, country or landing page. - Which sources send bots: group flagged sessions by
referrerand readbot_reasons. - Clean funnels: join the verdict to your existing events through the same user ID, and exclude flagged users from funnel and retention charts.
Identity and consent
When a visitor has consented and has a user ID, the event is sent with that user ID, so it lines up with your other events for the same person. Otherwise it is sent with the DataCops session ID as the anonymous ID.
| Tool | With a user ID | Without a user ID |
|---|---|---|
| Segment | userId | anonymousId = DataCops session ID |
| Amplitude | user_id (5 characters or more) | device_id = DataCops session ID |
Amplitude rejects IDs shorter than 5 characters, so a very short user ID is sent as a device ID instead. The session_id property is always included, so you can still join on it.
DataCops follows your consent setup. A visitor who declines is only counted as an anonymous session, with no user ID and no device fingerprint.
Server feed setup
Connect it yourself from the DataCops dashboard. Owners and team members can do this. (The dataLayer verdict above needs no keys at all.)
Install DataCops
Add the DataCops script on your own subdomain, as in getting started, so sessions are being scored.
Open Analytics tools
In DataCops, open Configuration, Integrations and scroll to Analytics tools.
Connect Segment
Paste the write key of the Segment source you want the events in, pick US or EU (EU if your Segment workspace is hosted in the EU), and click Connect. Segment accepts any key, so DataCops sends one
DataCops Connectedevent: check that it shows in that source's debugger. If it does not, the key or region is wrong.Connect Amplitude
Paste the project API key, pick the project's region (US or EU), and click Connect. DataCops sends a
DataCops Connectedevent to check the key and region first, so a saved Amplitude connection is a working one.Watch it run
The card shows when the last session was sent, how many were sent and failed in the last 24 hours, and the last error if there is one. Disconnect removes the key and stops sending.
How it fits with DataCops
This integration is for reporting. It does not send conversions to ad platforms. If you also want clean conversions in your ad accounts, that is a separate switch:
- Conversion delivery sends purchases and leads to Meta, Google Ads, TikTok, LinkedIn, Microsoft Ads, Reddit, Pinterest and X.
- Real people only stops bot conversions from reaching an ad platform. It is set per platform and is off by default.
- IP intelligence explains the VPN, proxy, Tor and data-center checks behind each true/false field.
You can run all of these at once. Segment and Amplitude get the verdict for every session, while your ad platforms get only the conversions you choose to send.
Good to know
- Sending starts with sessions from the last 15 minutes before the first run. Older sessions can be pulled through the export API.
- Segment accepts events even if a write key is wrong, so after connecting, check that
DataCops Connectedshows in your Segment source debugger before relying on the feed. - Every send is logged on our side, so a missing event can be traced.