Visitors, users & identity
"How many people" depends on which layer you count: all three can exist at once, and on an anonymous project they come out equal. How reports count the layers is in Counting modes; the calls are in Identify users.
People and the mapping log are on ConsoleAll-platform analyticsUsersIdentity map. Consent and tier are on ConsoleConfigurationPrivacy center, which also shows whether the project is anonymous or identified. Identified mode needs Pro or above; the console has no switch yet, so contact support to turn it on.
The three layers
The collector hashes a site salt with address and browser data into a visitor id. The website script does not write a cookie by default. Strict privacy rotates that salt each project day, so the same browser is not the same visitor tomorrow. Balanced privacy keeps a site salt longer, which is what makes new and returning visitors possible.
A device id is written only in identified mode, at collection tier 3, and with analytics consent. Identified mode needs a plan that includes it and pins the collection tier at 3.
A user appears in the People list after login binds a login id to that device. Visitors who never log in stay in aggregates and do not get a profile.
What login does
The first time a device binds to a login id, that session and the device's earlier anonymous events receive the user id. If the same device later logs in as someone else, rows that already have a user stay as they are, the device mapping moves, and a new analytics session starts. See Sessions.
One user keeps a single id of the login type. Email, mobile, and UnionID allow five each. Devices default to 50; the oldest is unbound past that. Values such as 0, -1, null, and guest are rejected.
Identify users in code
The website script loads the identity file only after identified mode is on, so the methods below exist only then; the People list shows only successful binds. The model is in Visitors, users & identity.
Parameters
login(id, props, opts) requires id, at most 200 characters. opts.type defaults to the login id and may be email, mobile, OpenID, or UnionID. Email is lowercased and hashed. Mobile strips spaces and dashes. Name, email, and phone inside props go to the profile.
bind adds other ids. logout clears the login and rotates the session marker. setProps overwrites profile fields. setPropsOnce writes a field only when it is empty.
Defaults & limits
login returns immediately when identified mode is off, the tier is below 3, or the id is blocked. The first login on a device backfills that device's anonymous history. A later account switch leaves rows that already have a user untouched, points the device at the new user, and opens a new analytics session. One user keeps one id of the login type. Email, mobile, and UnionID allow five each. Devices default to 50.
Compliance config can also point at a page variable, element, or cookie as the login id source. The script reads it a few more times after load and after route changes; empty and blocked values are not retried again.
Example
<script>
webcount.login('u_123', { $name: 'Ada' });
webcount.bind({ unionid: 'UNION' });
</script>Sign out:
<script>
webcount.logout();
</script>A mini program calls the same login after it has an OpenID, with the OpenID type.
Errors
anonymous, guest, null, all zeros, and -1 are rejected and show up as warnings on the identity map. Calling before the identity script loads fails; queue the call on window.__wcq. After logout, new pageviews in the same browser are no longer attached to that user until the next login.
Manage identity mapping
In anonymous mode there is no table: visits are still counted, and nobody is profiled. After you turn on identified mode, one person on a phone and a laptop is merged, and every bind and split is logged here so you can see how much duplication identity removed.
ConsoleAll-platform analyticsUsersIdentity mapIf the site is still anonymous, a notice points at project settings. Cards show people, bound devices, people identified in 7 days (login, zero-code, server), and people under a processing restriction.
Metrics & definitions
The difference card compares visitor, device, and person counts for the selected dates: how many extras identity removed, and how many of those came from one person on several devices. Quality warnings for 7 days include device-limit hits, rejected login ids, invalid device ids, clock skew, dropped profile fields, and personal data stripped from properties.
| Log action | Who does it | Result |
|---|---|---|
| Bind / backfill | Automatic at collect | The first login on a device writes the person onto that session |
| Account switch | Automatic at collect | History already stored on the old person stays; the new session belongs to the new person |
| Unbind / split | Owner or admin | Splitting a device reverts that session’s backfill. Later visits are a new anonymous device |
| Reject / limit | Automatic at collect | Blocked login values are dropped. Past the device cap, the oldest device is unbound |
Built-in blocked login values include empty or over-long ids, plus null, undefined, anonymous, guest, all zeros, -1, NaN, true, and false. The default cap is 50 devices per person. Beyond that, the oldest device is unbound and the log records a limit.
How to use it
- On the Users tab, search by name or login id. Email and phone must be complete.
- Open a person for profile, identifiers, sessions, and consent. Split a device, or unbind another identifier.
- Open Mapping log and filter by bind, unbind, split, reject, or backfill to see who changed what and when.
Identification sources are login, zero-code, and server. See Visitors, users & identity.
Access & limits
Owners, admins, and analysts can read the list and the log. Only owners and admins can split or unbind. The Free plan cannot enable identified mode. People under a processing restriction have later events dropped, and they are counted on their own card.
FAQ
Why is “identified in 7 days” zero? The site is still anonymous, or login was never called. The empty state names webcount.login() and zero-code sources.
Why did counts move after a split? A split reverts only the same-session backfill. Older events that already have a person id stay. That device is anonymous again until the next login.