Visitors & identity

Every score belongs to a visitor. This page explains how Aurora recognizes the same person across sessions and devices, when an anonymous visitor becomes a named contact, and how visitors roll up into company accounts.

4 min read Updated Aug 12, 2026
On this page
  1. Anonymous and identified visitors
  2. Identifying visitors
  3. Other identification sources
  4. Sessions
  5. Merging profiles across devices
  6. Company accounts
  7. Visitor profile reference

Anonymous and identified visitors#

When someone first lands on your site, Aurora creates an anonymous visitor and stores a random identifier in the first-party aur_vid cookie. Every page view and event from that browser is attached to the same profile, and the score builds up even though you don't yet know who the person is.

A visitor becomes identified when Aurora can link the profile to an email address. From that moment, alerts show the person's name and company, CRM sync can match them to an existing record, and all earlier anonymous activity stays attached — nothing is lost when a visitor identifies.

StateHow it happensWhat you see
AnonymousFirst visit from a browser without an aur_vid cookieLocation, referrer, company (if resolved from IP), full session history
IdentifiedAn identify call, a connected form, a tracked email link or a CRM matchEverything above, plus name, email and any traits you send
MergedTwo profiles are found to belong to the same emailOne profile with the combined history and a recalculated score

Identifying visitors#

The most reliable way to identify a visitor is to call identify when they sign up or log in. Pass a stable user ID from your own database and whatever traits are useful to your team:

JavaScript
aurora("identify", "usr_8f2a91", {
  email: "dana@northwind.example",
  name: "Dana Whitfield",
  company: "Northwind Supply",
  plan: "trial"
});

The user ID should never change for the same person. Email addresses can change, so Aurora treats the user ID as the primary key and updates the email when it differs. Full parameter details are in the JavaScript API reference.

Other identification sources#

  • Connected forms. Under Settings → Forms, choose which forms on your site count as identification (for example, demo requests and newsletter signups). Aurora reads only the email and name fields you map — never passwords or free-text fields.
  • Tracked email links. When your CRM or email tool appends ?aur_e= with a hashed contact ID to links, a click identifies the visitor on arrival.
  • CRM matching. With CRM sync enabled, Aurora matches identified visitors to existing contacts and leads by email.
  • REST API. Server-side systems can identify a visitor with POST /v1/visitors/identify by passing the aur_vid value and an email.

Only call identify with information the visitor gave you knowingly. Don't identify visitors from enrichment guesses or purchased lists; that breaks both user trust and most privacy laws.

Sessions#

A session groups the activity from one visit. Aurora starts a new session when a visitor returns after 30 minutes of inactivity, at midnight in the workspace time zone, or when they arrive from a new campaign (a different utm_campaign value). Session count is itself a signal: a third session in a week usually means more than three page views in one sitting.

You can change the inactivity timeout between 10 and 120 minutes under Settings → Tracking → Sessions. Changing it only affects new sessions; history is not recalculated.

Merging profiles across devices#

People research on a laptop at work and come back on a phone in the evening. Each device gets its own anonymous profile until the visitor identifies on both. When two profiles share the same user ID or email, Aurora merges them automatically:

  1. All sessions and events are combined in chronological order.
  2. The score is recalculated from the combined history, so recency and repeat-visit multipliers apply correctly.
  3. If either profile had already been routed, the existing owner is kept and no duplicate alert is sent.

Merges can't be undone automatically. If two different people were merged by mistake — usually because a shared login was identified — contact support and we'll split the history for you.

Company accounts#

For B2B teams, a single interested person is often part of a larger buying group. Aurora groups visitors into accounts by the domain of their email address, and resolves anonymous visitors to companies from their IP address where a confident match exists (typically 30–45% of business traffic).

The account view shows every known and anonymous visitor from the same company, plus an account score — the highest individual score plus a bonus for each additional engaged visitor. You can route on account score instead of individual score in routing conditions.

Free email domains (such as Gmail and Outlook) and ISP addresses never create accounts. You can add your own exclusions in Settings → Accounts.

Visitor profile reference#

These fields are available in the dashboard, in exports, in webhook payloads and through the REST API.

FieldTypeDescription
idstringAurora's visitor ID, prefixed vis_.
user_idstring | nullYour own user ID, set by identify.
email, namestring | nullContact details once identified.
accountobject | nullCompany name, domain, size band and industry.
scoreintegerCurrent score, 0–100.
statusstringnew, warm, ready, assigned, contacted or archived.
first_seen_at, last_seen_attimestampISO 8601, UTC.
sessions_countintegerTotal sessions across all merged devices.
top_signalsarrayThe three rules contributing most to the current score.
traitsobjectAny custom properties sent with identify.
Last updated Aug 12, 2026 Report an issue with this page

Ready to try it on your own site?

Install the snippet in five minutes and see your first scored visitors today. Starter is free forever for one seat.

No credit card required · Setup help from real engineers