Python-integration

Python kan skyddas fullt ut — utan paket och utan beroenden. Kontrollen är ett enda HTTPS-anrop.

Vi levererar inget Python-SDK. Det säger något om vår distribution, inte om ert skydd: det SDK:erna gör klarar anropet nedan med standardbiblioteket.

1. Lägg in widgeten

Skriptet mäter beteendet i webbläsaren och lägger ett dolt fält i varje formulär. Lägg in det en gång i sidhuvudet.

HTMLhtml
<!-- Add to <head> with SRI for security -->
(function () {
  var KEY = "YOUR_API_KEY";
  var SITE = location.hostname;
  var V = "2025.09.1";
  var s = document.createElement('script');
  s.src = "https://api.silentshield.io/client.js?k=" + encodeURIComponent(KEY)
    + "&v=" + encodeURIComponent(V)
    + "&site=" + encodeURIComponent(SITE);
  s.async = true;
  s.crossOrigin = "anonymous";
  document.head.appendChild(s);
})();

2. Verifiera på servern

Läs det dolda fältet vid inskick och fråga oss innan ni tar emot inskicket. Utan detta steg avgör bara webbläsaren — och en bot utan JavaScript går rakt förbi.

Pythonpython
# No package required — the check is one HTTPS POST.
# Standard library only: nothing to install, nothing to keep updated.
import json
import os
import urllib.error
import urllib.request

VERIFY_URL = "https://api.silentshield.io/api/v1/captcha/verify-nonce"
API_KEY = os.environ["SILENTSHIELD_KEY"]  # never hard-code it


def is_human(nonce: str) -> bool:
    """Ask SilentShield about one submission.

    The hidden field `behavior_nonce` is injected by client.js;
    read it from the posted form and hand it over unchanged.
    """
    if not nonce:
        return False

    request = urllib.request.Request(
        VERIFY_URL,
        data=json.dumps({"nonce": nonce}).encode(),
        headers={
            "Content-Type": "application/json",
            "X-Api-Key": API_KEY,
            # Tells us which integration is in use, exactly like the SDKs do.
            "X-SS-SDK": "python-inline/1",
        },
        method="POST",
    )

    try:
        with urllib.request.urlopen(request, timeout=5) as response:
            data = json.loads(response.read())
    except (urllib.error.URLError, TimeoutError, ValueError):
        # We are unreachable. Let the visitor through: a real customer turned
        # away costs more than a bot let in. Flip this to False only if you
        # would rather lose submissions than accept one unchecked.
        return True

    return (
        data.get("ok") is True
        and data.get("verdict") == "human"
        and data.get("confidence", 0) >= 0.7
    )


# --- Flask ---------------------------------------------------------------
# @app.post("/contact")
# def contact():
#     if not is_human(request.form.get("behavior_nonce", "")):
#         abort(400, "Please submit the form again.")
#     ...

# --- Django --------------------------------------------------------------
# def contact(request):
#     if not is_human(request.POST.get("behavior_nonce", "")):
#         return HttpResponseBadRequest("Please submit the form again.")
#     ...

# --- FastAPI -------------------------------------------------------------
# @app.post("/contact")
# async def contact(behavior_nonce: str = Form("")):
#     if not is_human(behavior_nonce):
#         raise HTTPException(status_code=400, detail="Please submit the form again.")
#     ...

Flask, Django och FastAPI

Funktionen ovan är ramverksoberoende. De tre anropsställena står som kommentarer sist i utdraget: Flask läser formulärordboken, Django POST-datan, FastAPI en formulärparameter.

Om vi inte går att nå

Utdraget släpper då igenom besökaren. En kund som felaktigt avvisas kostar mer än en bot som släpps in. Vill ni tvärtom, returnera falskt i felgrenen — då kostar ett avbrott er inskick.

AI-agenter

Rapportera agentobservationer med samma mönster till telemetripunkten: ett POST och samma huvud.

Att tillämpa reglerna lokalt går inte från Python — det kräver verifiering av en Ed25519-signatur över ett regelpaket. Ställ enforcern framför applikationen som sidecar eller använd Cloudflare Worker.