Check the Development | Production toggle in the page header before you start. Keys and gates belong to one environment, and a gate’s environment is fixed when you place it. Start in Development: it is not billed and has no business requirements.
Create a site key
The widget authenticates with a site key. It is public, so it is locked to the origins you list.1
Open Site Keys
Go to Settings → Developer Tools and select the Site Keys tab. Select New Site Key.
2
Name the key and pick an environment
Enter a Name, for example “Production checkout”. Under Environment, choose test for Development gates or live for Production gates. A test key starts with
pk_test_ and a live key starts with pk_live_.3
Add allowed origins
Under Allowed Origins, add each origin that will host the widget, for example
https://www.meridianairlines.com. Origins are matched exactly. Use https://*.meridianairlines.com to allow every subdomain.4
Create
Select Create Site Key. The key appears in the list with its origins. You can edit the origins or revoke the key later from the same list.
organization_id claim of every verification token, so keep it in your server configuration. See Keys and environments.
Place the gate
1
Open BotShield Gate
Select BotShield Gate in the sidebar. The Deployments tab lists your gates for the environment selected in the header. Select Place a gate.
2
Fill in the modal
The modal reads “Name it and pick a verification mode. You’ll configure the rest and activate on the next screen.”
3
Confirm with your passkey (Production only)
In Production the modal shows a Passkey badge: “Placing a gate is sealed with your passkey — only a proven human places a gate.” Select Place gate and confirm with your Console passkey when prompted. In Development there is no passkey step.
4
Check the key
The gate opens in a detail panel as a Draft. Its key is shown under the name. If the key you asked for was already taken, BotShield adds a suffix such as
-2, so copy the key from this panel, not from memory.pk_test_ and bs_dev_ keys reach Development gates, pk_live_ and bs_production_ keys reach Production gates.
Draft, Active, Archived
To activate, open the Draft and select Activate in the header, or Activate → in the Next steps list. To archive an active gate, select Deactivate, then Confirm when the panel asks “Stop answering verifications?”.
Production requirements
A Development gate activates with no checks. A Production gate activates only when all three of these are true, checked in this order:- Your business is verified. Select Verify Business on the BotShield Gate page and use a company email address on your company’s domain. Verification is automatic. Personal email domains such as Gmail or Outlook are declined.
- You have an active plan. Choose one on the Plan tab.
- You confirmed with your Console passkey in the last 5 minutes. Add a passkey under Settings → Profile → Passkeys if you do not have one. The Console prompts you when a fresh confirmation is needed.
Placing a Production gate can also return the two passkey codes.
The embed snippet
The gate’s Integration card shows the site key for the gate’s environment, a link to its allowed origins, and a snippet with a Copy button. The snippet is ready to paste: it carries the site key, the gate key asscope, and scan-mode="modal", which names the widget’s QR code and mobile hand-off flow.
pk_live_… or pk_test_… as a placeholder, you have no site key in that environment yet. Create one first. See Web component for every attribute and event.
The gate detail panel
Select a gate in the Deployments list to open its panel. A Draft shows only Overview. Active and Archived gates show three tabs.- Overview
- Verification Logs
- Activity Logs
- A date range (Last 7 days, Last 30 days, Last 90 days) and Export CSV for the summary.
- Metric tiles: Total attestations, Human Verified, BotShield ID Active (verifications that passed on Recent Presence without a phone step) and Human Unavailable. An Age Gate shows Over N Verified and Age Unavailable as well.
- Configuration: gate type, age threshold (Age Gate) and verification mode. Changes save automatically.
- Health: last attestation, last webhook sent, error rate, BotShield ID adoption and Unavailable rate.
- Integration: site key, allowed origins and the embed snippet.
- Next steps: place, activate, then test in the Sandbox.
Next steps
Web component
Put the widget on your page.
Verify on your server
Check the result before you trust it.
Testing
Try the gate in the Console Sandbox.
Keys and environments
Site keys, API keys and how the two environments differ.
