Edge Shield
Stop the bots. Never test the people.
Free bot protection with no puzzles and no tracking. Shield scores every visitor from 1 to 100 in the background, so your forms can welcome people, route verified AI agents and turn away abuse.
Free forever. Unlimited widgets and verifications, no card.
- Widget, no dependencies
- <15KB
- Score on every check
- 1–100
- Cookies or trackers
- 0
- At any volume
- $0
How it works
Two snippets and one API call
About five minutes from script tag to verified traffic. If you've used Turnstile or reCAPTCHA, the model is the one you know.
- 01
Add the widget to your form
One script tag and one div with your sitekey. Plain HTML, React, Vue or any single-page app. - 02
Visitors verify in the background
A small proof-of-work runs in a Web Worker while risk signals are scored. The score sharpens once the visitor moves or types. People almost never see a challenge. - 03
Check the token on your server
Post the token to siteverify and get a verdict plus a 1–100 humanity score. Tokens are single-use and expire after five minutes.
One score, three outcomes
Pick a visitor and follow the token
A pass/fail CAPTCHA treats a shopping agent like an attack. Shield tells your server who it's dealing with, so each visitor gets the right door.
Maya, signing up on her phone
- Clean browser
- Natural motor noise while typing
- Trivial proof-of-work, solved in 21ms
POST /siteverify
{
"success": true,
"score": 94,
"hostname": "shop.example"
}Create the account. She never saw a challenge.
Built for the agentic web
Automation is a signal, not a verdict
More of your legitimate traffic is software acting for a person. Agents that sign their requests with Web Bot Auth, the IETF draft backed by OpenAI, Google and Amazon, are identified cryptographically and handed to your server by name. Automation that won't identify itself gets the hard treatment.
- Web Bot Auth signatures checked on every challenge
- Crawlers such as Googlebot confirmed by reverse DNS
- Per-widget agent policy: allow, challenge or block
- Server-side agentverify API, no widget required
Privacy
Nothing to consent to, because nothing is kept
Most verification products promise not to misuse the data they hold. Shield doesn't hold it. Signals are scored in memory during the request and then discarded. The only thing written to disk is an hourly counter, so there's no cookie banner and no visitor data to breach.
- No cookies or local storage
- No behavioural profiling or ad tracking
- Open-source client widget
- WCAG 2.2 AA, because there's no puzzle to fail
Included on every widget
Everything Turnstile does, plus a score
No paid tier holds back the useful parts.
Invisible verification
Managed mode shows a single “I am human” click to genuinely suspicious traffic, and nothing to anyone else.Drop-in Turnstile migration
The siteverify response matches Turnstile's field for field. Swap a URL and two keys.Shadow mode and test keys
Trial Shield on live traffic without blocking anyone, and run CI against keys that always pass, fail or escalate.Offline verification
Tokens are Ed25519-signed JWTs with a public key set. Verify them on your own server with no network call.The tarpit
Repeat offenders get exponentially harder proof-of-work. Bots can keep trying and keep paying for the electricity.The Examiner
An AI review of 30 days of your widget's traffic, written in plain English with specific fixes.
The whole integration
This is all the code there is
A script tag and a div on the page, one HTTP call on your server. Coming from Turnstile? The response format is identical, so migrating is a find and replace.
- Sitekey and secret, like Turnstile and reCAPTCHA
- Any framework, any backend language
- Signed, single-use tokens that expire in five minutes
- Your traffic never routes through our network
signup.html
<script src="https://shield.edge.network/api.js" defer></script>
<form method="post" action="/signup">
<input type="email" name="email" />
<div class="edge-shield" data-sitekey="es_your_sitekey"></div>
<button>Sign up</button>
</form>server
POST https://shield.edge.network/siteverify
secret=es_secret_…&response=<edge-shield-response>
→ { "success": true, "score": 96, "hostname": "example.com" }Compare
What “free” means at each provider
| Turnstile | reCAPTCHA | hCaptcha | ||
|---|---|---|---|---|
| Price | Free, unlimited | Free | Free to 10k/mo | Free tier |
| Confidence score | 1–100, every call | 0.0–1.0 (v3) | Enterprise only | |
| Visual puzzles | Never | Never | v2 fallback | Yes |
| No per-visitor data stored | ||||
| Offline token verification | ||||
| Report-only (shadow) mode | ||||
| Open-source widget |
Competitor details from publicly listed plans and documentation. They may change.
FAQ
Why add Shield before bots arrive
Something else on your mind? Talk to the Shield team.
We don't have a bot problem. Why add Shield now?
“No bot problem” is usually an assumption rather than a measurement. Automated traffic shows up as inflated visitor counts, odd conversion rates and mailing lists that decay too fast. In invisible mode Shield measures first: every visitor gets a score, and your dashboard shows the real mix of people, declared agents and undeclared automation, without a single challenge shown.
Isn't a CAPTCHA something you add once abuse starts?
CAPTCHAs get added late because they cost conversions. Shield is invisible and free, so that trade-off goes away. Running it early gives you clean signup data from day one and an agent policy already in place. If abuse arrives, you change a setting instead of retrofitting a CAPTCHA under pressure.
What does running it early protect?
Your data quality, which is far cheaper to keep than to recover. Fake signups skew funnels and the spending decisions built on them. Bot addresses damage your sender reputation for months.
How do you treat AI agents?
Agents that sign their requests with Web Bot Auth are identified cryptographically, and their identity arrives in the siteverify response. Route them to an API instead of a puzzle. You set the policy per widget: allow, challenge or block.
What does it cost?
Nothing. Core protection is free forever, with no verification cap and no card.
Guides
Set it up properly
Your users aren't robots. Stop testing them.
Private verification that welcomes people, routes good agents and stops abuse. Free forever and live in five minutes.
No card, no caps, no puzzles.