Developer Documentation
Invisible bot protection. No CAPTCHAs. API-first.
Quickstart
1
Install & Embed
Add the script and get a token
2
Verify on Server
Validate the token on your backend
Quick Test with cURL
Verify nonce from command line
# Verify Nonce
curl -X POST https://api.silentshield.io/v1/verify \
-H "api-key: YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"nonce": "256ea6c63c3ccdd317e05cbc9ef0c659"}'Frontend Integration
Add the client script with SRI and defer attributes
<!-- Add to <head> with SRI for security -->
(function () {
var KEY = "YOUR_API_KEY";
var SITE = location.hostname;
var V = "2025.09.1";
var s = document.createElement('script');
s.src = "https://api.silentshield.io/client.js?k=" + encodeURIComponent(KEY)
+ "&v=" + encodeURIComponent(V)
+ "&site=" + encodeURIComponent(SITE);
s.async = true;
s.crossOrigin = "anonymous";
document.head.appendChild(s);
})();Security & Privacy
- No cookies – fully cookieless operation
- No PII collection – GDPR & CCPA compliant
- EU hosting – all data stays in Europe
- WCAG compliant – accessible to all users
- CSP compatible – use with Content Security Policy:
Content-Security-Policy: script-src 'self' https://api.silentshield.io;API Reference
API Version: 2025-10-01 · Base URL: https://api.silentshield.io
POST
/v1/verifyVerify SilentShield Nonce
Request Headers:
AuthorizationBearer YOUR_API_KEYContent-Typeapplication/jsonRequest Body:
tokenstringThe nonce to verifyResponse:
Success (200):
{
"ok": true,
"verdict": "human",
"confidence": 0.95,
"request_nonce": "req_abc123"
}Error:
{
"ok": false,
"verdict": "error",
"confidence": 0,
"request_nonce": "req_abc123",
"error": "Invalid nonce"
}Status Codes:
200Nonce successfully verified400Invalid request (missing or incorrect nonce)401Invalid API Key429Rate limit exceeded (100 requests/min.)500Internal Server ErrorSDKs & Libraries
The package runs on your server (Node.js 18 or newer). In the browser you need no package at all — the client.js snippet from the quick start does the job.
Node.js / Express
v1.2.0npm i @forge12interactive/silentshield-sdk-jsimport { createClient } from "@forge12interactive/silentshield-sdk-js";
const shield = createClient({ apiKey: process.env.SILENTSHIELD_API_KEY });
app.post("/signup", async (req, res) => {
const { human } = await shield.verify(req.body.behavior_nonce);
if (!human) return res.status(403).send("Verification failed");
res.send("ok");
});AI agents (Node.js)
v1.2.0npm i @forge12interactive/silentshield-sdk-jsimport { createClient, enforce } from "@forge12interactive/silentshield-sdk-js";
const shield = createClient({ apiKey: process.env.SILENTSHIELD_API_KEY });
// Reports bot candidates only — never blocks, never sees human traffic.
app.use(shield.observe);
// Applies your policy locally from a signed bundle. Fail-open.
app.use(enforce({ apiKey: process.env.SILENTSHIELD_API_KEY }));Resources
Help Center
Comprehensive documentation with getting started guides, integration tutorials, configuration references, and troubleshooting.
Changelog
Stay up to date with the latest features, improvements, and fixes.