Integrazione Python
Python può essere protetto completamente, senza pacchetto e senza dipendenze. La verifica è una sola chiamata HTTPS.
Non pubblichiamo un SDK Python. Riguarda la nostra distribuzione, non la sua protezione: ciò che fanno gli SDK lo fa la chiamata qui sotto con la libreria standard.
1. Inserire il widget
Lo script misura il comportamento nel browser e inserisce un campo nascosto in ogni modulo. Lo aggiunga una volta nell'intestazione delle sue pagine.
<!-- Add to <head> with SRI for security -->
(function () {
var KEY = "YOUR_API_KEY";
var SITE = location.hostname;
var V = "2025.09.1";
var s = document.createElement('script');
s.src = "https://api.silentshield.io/client.js?k=" + encodeURIComponent(KEY)
+ "&v=" + encodeURIComponent(V)
+ "&site=" + encodeURIComponent(SITE);
s.async = true;
s.crossOrigin = "anonymous";
document.head.appendChild(s);
})();2. Verificare sul server
All'invio legga il campo nascosto e ci interroghi prima di accettare la trasmissione. Senza questo passaggio decide solo il browser, e un bot senza JavaScript lo aggira.
# No package required — the check is one HTTPS POST.
# Standard library only: nothing to install, nothing to keep updated.
import json
import os
import urllib.error
import urllib.request
VERIFY_URL = "https://api.silentshield.io/api/v1/captcha/verify-nonce"
API_KEY = os.environ["SILENTSHIELD_KEY"] # never hard-code it
def is_human(nonce: str) -> bool:
"""Ask SilentShield about one submission.
The hidden field `behavior_nonce` is injected by client.js;
read it from the posted form and hand it over unchanged.
"""
if not nonce:
return False
request = urllib.request.Request(
VERIFY_URL,
data=json.dumps({"nonce": nonce}).encode(),
headers={
"Content-Type": "application/json",
"X-Api-Key": API_KEY,
# Tells us which integration is in use, exactly like the SDKs do.
"X-SS-SDK": "python-inline/1",
},
method="POST",
)
try:
with urllib.request.urlopen(request, timeout=5) as response:
data = json.loads(response.read())
except (urllib.error.URLError, TimeoutError, ValueError):
# We are unreachable. Let the visitor through: a real customer turned
# away costs more than a bot let in. Flip this to False only if you
# would rather lose submissions than accept one unchecked.
return True
return (
data.get("ok") is True
and data.get("verdict") == "human"
and data.get("confidence", 0) >= 0.7
)
# --- Flask ---------------------------------------------------------------
# @app.post("/contact")
# def contact():
# if not is_human(request.form.get("behavior_nonce", "")):
# abort(400, "Please submit the form again.")
# ...
# --- Django --------------------------------------------------------------
# def contact(request):
# if not is_human(request.POST.get("behavior_nonce", "")):
# return HttpResponseBadRequest("Please submit the form again.")
# ...
# --- FastAPI -------------------------------------------------------------
# @app.post("/contact")
# async def contact(behavior_nonce: str = Form("")):
# if not is_human(behavior_nonce):
# raise HTTPException(status_code=400, detail="Please submit the form again.")
# ...Flask, Django e FastAPI
La funzione sopra è indipendente dal framework. I tre punti di chiamata sono commentati alla fine del frammento: Flask legge il dizionario del modulo, Django i dati POST, FastAPI un parametro di modulo.
Se non siamo raggiungibili
Il frammento lascia passare il visitatore. Un cliente respinto per errore costa più di un bot ammesso. Per il comportamento opposto restituisca falso nel ramo di errore: un disservizio le costerà invii.
Agenti IA
Segnali gli avvistamenti di agenti con lo stesso schema all'endpoint di telemetria: un POST e la stessa intestazione.
Applicare le regole localmente non è possibile da Python: richiede la verifica di una firma Ed25519 su un pacchetto di regole. Metta l'enforcer davanti alla sua applicazione come sidecar oppure usi il Worker di Cloudflare.