Skip to main content
BotShield Gate checks for a real human at the moment it matters: a sign-up, a checkout, a post, an age-restricted page. The user confirms with their device biometric (a passkey) in the BotShield app, and you receive a result. BotShield tells you that the user is human, never who they are. You receive no personal data.

Two gate types

Human Gate

“Is a real human here?” The result is Verified or Unavailable.

Age Gate (Beta)

“Is this human over 13, 18 or 21?” The result is Over N Verified or Unavailable. It never returns a date of birth, an age, or an “underage” answer. See Age Gate.
Both types use the same integration. There are only two result states, and your code should branch on exactly those two. See Result states.
See it before you build it. The BotShield Demos run both gate types on production keys: Ticketz puts a Human Gate on a checkout (with the inline passkey beta), and Vapez puts an Age Gate on a storefront door. Open one on your laptop and confirm on your phone.
Unavailable is not an accusation. It means BotShield could not confirm a human this time: the request expired, the user declined, or the check could not run.

What a gate is

A gate is one placement of BotShield Gate in your product. You place gates in the BotShield Console, and each gate has:

Verification mode

An Age Gate always runs Live, because the age signal is read on the phone during the confirmation.
Recent Presence only applies when you tell BotShield which of your users is asking, with platform-user-ref on the widget or partner_user_ref in the API. BotShield stores that reference only as a one-way hash. Without it, every request runs the live check.

Where to use a gate

Use a gate anywhere you would put a CAPTCHA, and anywhere a CAPTCHA has stopped being enough:
  • Sign-up and sign-in, to stop scripted account creation.
  • Checkout, for limited drops, tickets and high-demand inventory.
  • Posting, voting and reviews, to keep automated content out.
  • Age-restricted access, with an Age Gate.
  • Sensitive account changes, such as payout details or recovery.
A gate covers one action. Place separate gates for separate actions so you can choose the mode, read the logs and archive each one independently.

Two ways to integrate

Web component

Add a script tag and a <botshield-verify> element to your page. The widget draws the Verify Human button, shows the QR code or opens the app, and hands your page the result. Then you verify it on your server.

Server-to-server

Your server creates the verification request with your API key, you show the link in your own UI, and you learn the result by webhook or by polling. Use this for native apps, custom UI and back-office flows.

How the widget flow works

The event on your page is a convenience for your UI. The decision belongs on your server: always check the result server-side before you let the action through.

Next steps

Place a gate

Create a site key, place a gate and activate it in the Console.

Web component

The full <botshield-verify> reference.

Verify on your server

Check tokens, or run the whole flow server-to-server.

Testing

Development keys, the Console Sandbox and a launch checklist.

Live demos

Ticketz (Human Gate at checkout) and Vapez (Age Gate at the door), running on production.