---
title: "Edge Shield"
description: "Free, privacy-first bot protection without puzzles. Verify humans, route agents, and stop abuse with a 1–100 humanity score on every check."
url: "https://edge.network/docs/shield"
section: "Shield"
---

# Edge Shield

A lightweight CAPTCHA alternative. Shield verifies visitors invisibly, with no puzzles, cookies or tracking, and returns a 1–100 humanity score your application can act on. Free forever, with unlimited verifications.

## Key features

- **Invisible verification:** a proof-of-work challenge is solved in a background thread. Real visitors almost never see anything, and never have to label traffic lights.
- **Humanity score:** every verification carries a 1–100 score, where 1 is confirmed automation and 100 a confirmed human. Allow, step up, redirect or block on your own thresholds.
- **Privacy by architecture:** no cookies, no fingerprint database and no per-visitor storage. Only hourly aggregate counters are kept, so Shield is GDPR and CCPA friendly by default.
- **Turnstile-compatible:** the siteverify response matches Cloudflare Turnstile's exactly, plus the score. Migrating is a URL and key swap.
- **Shadow mode and test keys:** trial Shield in report-only mode on live traffic (nothing is ever blocked), and run CI against fixed test keys that never touch real state.
- **Offline verification:** tokens are Ed25519-signed JWTs with a public JWKS endpoint. Verify them locally with zero network calls when latency matters.

## How it works

1. **The widget requests a challenge.** A cryptographically signed challenge is issued by the Shield service. Difficulty adapts to risk signals, so clean browsers get trivial work.
2. **The browser solves it invisibly.** A SHA-256 proof-of-work runs in a Web Worker. It takes tens of milliseconds on a phone and has no impact on your Core Web Vitals.
3. **A response token is minted.** The solution plus coarse environment signals produce a signed, single-use token containing the humanity score. It's added to your form automatically.
4. **The score refines as the visitor interacts.** Verification runs at page load, before any real interaction. As the visitor types or moves the pointer, the widget sends a one-off summary of that interaction (aggregate statistics only, computed in the browser) and the token is re-minted with a behaviour-informed score. Human motor noise raises it; machine-perfect input lowers it.
5. **Your server validates the token.** One POST to siteverify with your secret key returns the verdict, hostname and score. Tokens expire after 5 minutes and can be used exactly once.

## Pricing

Shield's core protection is **free forever**. It includes unlimited widgets, unlimited verifications, all three widget modes and the humanity score. There are no monthly assessment caps and no credit card required.

## In this section

- [Getting started](/docs/shield/getting-started) — Create a Shield widget, add two lines to your page and validate tokens on your server. Privacy-first bot protection in five minutes.
- [Widget modes](/docs/shield/widget-modes) — Managed, non-interactive and invisible modes: choose how visible Shield verification is, and configure the widget with data attributes.
- [JavaScript API](/docs/shield/js-api) — Explicit rendering, programmatic execution and single-page application integration for the Edge Shield widget, using its small global JavaScript API.
- [Server-side validation](/docs/shield/siteverify) — Validate Shield tokens with the siteverify API: Turnstile-compatible responses, error codes, and how to use the 1–100 humanity score.
- [Offline token verification](/docs/shield/offline-verification) — Verify Shield tokens locally with zero network calls. Tokens are Ed25519-signed JWTs, and the public key is published at a standard JWKS endpoint.
- [Testing & CI](/docs/shield/testing) — Fixed test sitekeys and secrets that behave deterministically. Run your test suite against Shield with no real keys, network state or analytics noise.
- [Shield on a static site](/docs/shield/static-sites) — Using Shield on a static site with no backend: test the siteverify check from your laptop, see what Shield can protect, and add the smallest server-side step.
- [Verified agents](/docs/shield/verified-agents) — Identify legitimate AI agents and crawlers with Web Bot Auth (RFC 9421), set per-widget agent policies, and verify agents server-side with agentverify.
- [Migrating from Turnstile](/docs/shield/turnstile-migration) — Move from Cloudflare Turnstile to Edge Shield. It uses the same siteverify response shape and sitekey/secret model, so most migrations are a URL swap.
- [Analytics](/docs/shield/analytics) — Per-widget Shield verification metrics, humanity score trends and failure counts, plus what Shield stores and what it deliberately doesn't.
- [Shield Examiner](/docs/shield/examiner) — AI review of your Shield widget's traffic: bot pressure, escalation calibration, abuse signals and recommended siteverify thresholds, from aggregate data only.
