Developer Documentation

Invisible bot protection. No CAPTCHAs. API-first.

Quickstart

1

Install & Embed

Add the script and get a token

2

Verify on Server

Validate the token on your backend

Quick Test with cURL

Verify nonce from command line

# Verify Nonce
curl -X POST https://api.silentshield.io/v1/verify \
  -H "api-key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"nonce": "256ea6c63c3ccdd317e05cbc9ef0c659"}'

Frontend Integration

Add the client script with SRI and defer attributes

<!-- Add to <head> with SRI for security -->
(function () {
  var KEY = "YOUR_API_KEY";
  var SITE = location.hostname;
  var V = "2025.09.1";
  var s = document.createElement('script');
  s.src = "https://api.silentshield.io/client.js?k=" + encodeURIComponent(KEY)
    + "&v=" + encodeURIComponent(V)
    + "&site=" + encodeURIComponent(SITE);
  s.async = true;
  s.crossOrigin = "anonymous";
  document.head.appendChild(s);
})();

Security & Privacy

  • No cookies – fully cookieless operation
  • No PII collection – GDPR & CCPA compliant
  • EU hosting – all data stays in Europe
  • WCAG compliant – accessible to all users
  • CSP compatible – use with Content Security Policy:
Content-Security-Policy: script-src 'self' https://api.silentshield.io;

API Reference

API Version: 2025-10-01 · Base URL: https://api.silentshield.io

POST/v1/verify

Verify SilentShield Nonce

Request Headers:

AuthorizationBearer YOUR_API_KEY
Content-Typeapplication/json

Request Body:

tokenstringThe nonce to verify

Response:

Success (200):

{
  "ok": true,
  "verdict": "human",
  "confidence": 0.95,
  "request_nonce": "req_abc123"
}

Error:

{
  "ok": false,
  "verdict": "error",
  "confidence": 0,
  "request_nonce": "req_abc123",
  "error": "Invalid nonce"
}

Status Codes:

200Nonce successfully verified
400Invalid request (missing or incorrect nonce)
401Invalid API Key
429Rate limit exceeded (100 requests/min.)
500Internal Server Error

SDKs & Libraries

The package runs on your server (Node.js 18 or newer). In the browser you need no package at all — the client.js snippet from the quick start does the job.

Node.js / Express

v1.2.0
npm i @forge12interactive/silentshield-sdk-js
import { createClient } from "@forge12interactive/silentshield-sdk-js";

const shield = createClient({ apiKey: process.env.SILENTSHIELD_API_KEY });

app.post("/signup", async (req, res) => {
  const { human } = await shield.verify(req.body.behavior_nonce);
  if (!human) return res.status(403).send("Verification failed");
  res.send("ok");
});

AI agents (Node.js)

v1.2.0
npm i @forge12interactive/silentshield-sdk-js
import { createClient, enforce } from "@forge12interactive/silentshield-sdk-js";

const shield = createClient({ apiKey: process.env.SILENTSHIELD_API_KEY });

// Reports bot candidates only — never blocks, never sees human traffic.
app.use(shield.observe);

// Applies your policy locally from a signed bundle. Fail-open.
app.use(enforce({ apiKey: process.env.SILENTSHIELD_API_KEY }));

Resources

Help Center

Comprehensive documentation with getting started guides, integration tutorials, configuration references, and troubleshooting.

Changelog

Stay up to date with the latest features, improvements, and fixes.

Ready to start?

Create a free account and get your site key in seconds.