Skip to content

Shield features

Verification your visitors never notice

Invisible checks, a score your server can act on, and privacy guaranteed by how the system is built rather than by a policy. None of it involves a puzzle.

Every feature on this page is free, on every widget.

Widget modes

Three modes, and none of them is a puzzle

Choose how visible verification is, per widget. Switch between them to see what a visitor gets.
Read the widget modes guide

The default. People verify invisibly. Traffic that scores low gets one “I am human” click, backed by a proof-of-work about 16 times harder.

data-mode="managed"

Create your account

maya@studio.coSign up
  • Mode set per widget from the console, CLI or API
  • Tokens refresh automatically before they expire
  • JavaScript API for single-page apps: render, execute, reset
  • Hidden form field added for you, with Turnstile compatibility

Proof-of-work

Proof of work, not proof of patience

Shield issues a signed challenge that the browser solves in a background Web Worker: tens of milliseconds on a phone, invisible to the visitor, and off the main thread. Difficulty follows risk. A clean browser gets trivial work; automation gets exponentially more expensive work.
  • SHA-256 proof-of-work solved in a Web Worker
  • Stateless, HMAC-signed challenges with anti-replay
  • Headless browser and automation-framework detection
  • Motor-noise analysis computed in the browser; raw input never leaves the device
  • The tarpit: repeat offenders pay 16× more per step

The humanity score

A confidence level, not a coin toss

Turnstile tells you pass or fail. Shield tells you how sure it is. Every successful siteverify call carries a score from 1 (confirmed automation) to 100 (confirmed human), refined once the visitor has actually interacted. Thresholds and outcomes are yours to tune.
  • Returned on every successful siteverify call
  • Re-minted with a behaviour-informed score before your server sees it
  • Allow, step up, redirect to your API, review or block
  • Versioned scoring: detection improves without integration changes

Privacy by architecture

It can't leak what it never kept

Signals are scored in memory during the request and then discarded. The only thing that touches a disk is an hourly counter. No cookie banner triggered by your bot protection, and no visitor data for anyone to breach.
  • No cookies or local storage

    Nothing is set in the visitor's browser, so there's nothing to consent to.
  • No fingerprint database

    No per-visitor records of any kind. Only hourly aggregate counters are persisted.
  • GDPR and CCPA friendly by default

    Not by configuration. There's no visitor data processing to document.

Integration and migration

Leaving your current CAPTCHA takes three lines

The siteverify response matches Turnstile's field for field, and compatibility mode also fills the cf-turnstile-response input. Existing server code keeps working; it just gains a score.
  • One snippet, any stack

    A script tag and a div. The widget renders itself and adds a hidden form field. Plain HTML, React, Vue or any SPA.
  • Sitekey and secret model

    The key model you know from Turnstile and reCAPTCHA. Secrets are hashed at rest and shown once.
  • Hostname allowlists

    Lock each widget to specific hostnames. Tokens minted anywhere else fail validation.
  • Offline verification (JWKS)

    Tokens are Ed25519-signed JWTs with a public key endpoint. Verify them locally with no network call.
  • Test sitekeys for CI

    Fixed keys that always pass, always fail or always escalate. Deterministic and invisible to your analytics.
  • Shadow mode

    Report-only on live traffic: nothing is blocked, and analytics show what enforcement would have done.
  • WCAG 2.2 AA

    The rare confirmation is a real button with full ARIA support and keyboard navigation.
  • Isolated infrastructure

    Shield runs on dedicated infrastructure at shield.edge.network, separate from everything else.
  • Verified agents API

    Check Web Bot Auth signatures server-side with agentverify, no widget required.

Analytics

Know your traffic without knowing your visitors

Hour-by-hour challenge, solve and score metrics per widget. A sudden drop in the average score is your early warning of a bot campaign. There's no per-visitor drill-down, because there's no per-visitor data.
  • Issued, solved and escalated challenges per hour
  • Average humanity score over time
  • Failed and replayed verifications
  • Shadow mode: would-fail and would-escalate counts
  • The Examiner: an AI review of the last 30 days

Specification

The details, in one table

Shield
WidgetUnder 15KB, no dependencies, open-source client
ModesManaged (default), non-interactive, invisible
ChallengeSHA-256 proof-of-work in a Web Worker, adaptive difficulty
TokenEd25519-signed JWT, single-use, 5-minute expiry, auto-refresh
Server verificationPOST https://shield.edge.network/siteverify
Offline verificationhttps://shield.edge.network/.well-known/jwks.json
Response fieldssuccess, score (1–100), challenge_ts, hostname, error-codes; agent and shadow when relevant
Verified agentsWeb Bot Auth signatures, reverse-DNS crawler checks, per-widget policy
Test keyses_test_pass, es_test_block, es_test_interactive
Data storedHourly aggregate counters only. No cookies, IPs or fingerprints
AccessibilityWCAG 2.2 AA
PriceFree, unlimited widgets and verifications

Protection your users will never notice

Add Shield to a form in about five minutes. Free forever, with every feature on this page.

No card, no caps, no puzzles.