Shield features
Verification your visitors never notice
Invisible checks, a score your server can act on, and privacy guaranteed by how the system is built rather than by a policy. None of it involves a puzzle.
Every feature on this page is free, on every widget.
Widget modes
Three modes, and none of them is a puzzle
Choose how visible verification is, per widget. Switch between them to see what a visitor gets.
The default. People verify invisibly. Traffic that scores low gets one “I am human” click, backed by a proof-of-work about 16 times harder.
data-mode="managed"Create your account
maya@studio.coSign up
- Mode set per widget from the console, CLI or API
- Tokens refresh automatically before they expire
- JavaScript API for single-page apps: render, execute, reset
- Hidden form field added for you, with Turnstile compatibility
Proof-of-work
Proof of work, not proof of patience
Shield issues a signed challenge that the browser solves in a background Web Worker: tens of milliseconds on a phone, invisible to the visitor, and off the main thread. Difficulty follows risk. A clean browser gets trivial work; automation gets exponentially more expensive work.
- SHA-256 proof-of-work solved in a Web Worker
- Stateless, HMAC-signed challenges with anti-replay
- Headless browser and automation-framework detection
- Motor-noise analysis computed in the browser; raw input never leaves the device
- The tarpit: repeat offenders pay 16× more per step
The humanity score
A confidence level, not a coin toss
Turnstile tells you pass or fail. Shield tells you how sure it is. Every successful siteverify call carries a score from 1 (confirmed automation) to 100 (confirmed human), refined once the visitor has actually interacted. Thresholds and outcomes are yours to tune.
- Returned on every successful siteverify call
- Re-minted with a behaviour-informed score before your server sees it
- Allow, step up, redirect to your API, review or block
- Versioned scoring: detection improves without integration changes
Privacy by architecture
It can't leak what it never kept
Signals are scored in memory during the request and then discarded. The only thing that touches a disk is an hourly counter. No cookie banner triggered by your bot protection, and no visitor data for anyone to breach.
No cookies or local storage
Nothing is set in the visitor's browser, so there's nothing to consent to.No fingerprint database
No per-visitor records of any kind. Only hourly aggregate counters are persisted.GDPR and CCPA friendly by default
Not by configuration. There's no visitor data processing to document.
Integration and migration
Leaving your current CAPTCHA takes three lines
The siteverify response matches Turnstile's field for field, and compatibility mode also fills the cf-turnstile-response input. Existing server code keeps working; it just gains a score.
One snippet, any stack
A script tag and a div. The widget renders itself and adds a hidden form field. Plain HTML, React, Vue or any SPA.Sitekey and secret model
The key model you know from Turnstile and reCAPTCHA. Secrets are hashed at rest and shown once.Hostname allowlists
Lock each widget to specific hostnames. Tokens minted anywhere else fail validation.Offline verification (JWKS)
Tokens are Ed25519-signed JWTs with a public key endpoint. Verify them locally with no network call.Test sitekeys for CI
Fixed keys that always pass, always fail or always escalate. Deterministic and invisible to your analytics.Shadow mode
Report-only on live traffic: nothing is blocked, and analytics show what enforcement would have done.WCAG 2.2 AA
The rare confirmation is a real button with full ARIA support and keyboard navigation.Isolated infrastructure
Shield runs on dedicated infrastructure at shield.edge.network, separate from everything else.Verified agents API
Check Web Bot Auth signatures server-side with agentverify, no widget required.
Analytics
Know your traffic without knowing your visitors
Hour-by-hour challenge, solve and score metrics per widget. A sudden drop in the average score is your early warning of a bot campaign. There's no per-visitor drill-down, because there's no per-visitor data.
- Issued, solved and escalated challenges per hour
- Average humanity score over time
- Failed and replayed verifications
- Shadow mode: would-fail and would-escalate counts
- The Examiner: an AI review of the last 30 days
Specification
The details, in one table
| Shield | |
|---|---|
| Widget | Under 15KB, no dependencies, open-source client |
| Modes | Managed (default), non-interactive, invisible |
| Challenge | SHA-256 proof-of-work in a Web Worker, adaptive difficulty |
| Token | Ed25519-signed JWT, single-use, 5-minute expiry, auto-refresh |
| Server verification | POST https://shield.edge.network/siteverify |
| Offline verification | https://shield.edge.network/.well-known/jwks.json |
| Response fields | success, score (1–100), challenge_ts, hostname, error-codes; agent and shadow when relevant |
| Verified agents | Web Bot Auth signatures, reverse-DNS crawler checks, per-widget policy |
| Test keys | es_test_pass, es_test_block, es_test_interactive |
| Data stored | Hourly aggregate counters only. No cookies, IPs or fingerprints |
| Accessibility | WCAG 2.2 AA |
| Price | Free, unlimited widgets and verifications |
Protection your users will never notice
Add Shield to a form in about five minutes. Free forever, with every feature on this page.
No card, no caps, no puzzles.