Don't set a tracking cookie, use of IP addresses is allowed for legitimate purposes (Art 6(1)(f)) as long as they're not stored.

At least for GDPR...

The only ways to actually track without a consent pop-up are:

(1) stay off the device entirely and process server-transmitted data under legitimate interests with a privacy notice, or

(2) confine any device storage to what's strictly necessary for the service the user requested

This goes to show that the assertion that cookie banners are just "malicious compliance" isn't quite correct. These are significant trade-offs here.

you don’t need to track users by giving them an ID they send with every request.

in fact. you probably don’t need to track users.