BotShield_Gate__c record, and your page or automation acts only on that verified row.
How it works
1
The guest verifies
The widget shows a lightweight human check (scan a code or an inline passkey — no login, no PII). Behind the scenes it calls your BotShield deployment on the CDN.
2
The verification is pushed to your org
On success, your BotShield Console pushes a
BotShield_Gate__c record into this org (keyed on the request ID), Change Data Capture enabled so Flows and LWCs can react the moment it lands.3
You act on the verified row
Your checkout or form completes only against that verified row — the booking, order, or record is created only when a real human is present.
Add the widget
1
Open Experience Builder
Edit your community page and drag the BotShield Verify component onto the cart, checkout, or form page.
2
Set the site key
In the component properties, paste the site key for this deployment (from your BotShield Console → the deployment’s settings). The site key is publishable — it’s safe in the page.
3
Allow the origin
Add your Experience Cloud site’s origin to the deployment’s allowed domains in the Console. If the origin isn’t allow-listed, verification requests are rejected.
The package ships the required CSP Trusted Sites for the BotShield CDN and QR endpoints, so the widget loads in both LWR and Aura communities without extra configuration.
Read the result
Each verification lands as aBotShield_Gate__c record with the outcome (never PII):
Watch verifications in the BotShield → Verifications tab, filtered by deployment and status.
Commerce Cloud checkout
The same gate on a Composable Storefront / Storefront Next checkout using the BotShield SDK.
