Welcome to BotShield
BotShield is a deployable, usage-based human presence verification layer for modern platforms. It is a clean CAPTCHA replacement that verifies human presence at the moment of action — without surveillance or continuous monitoring.What is BotShield?
BotShield attests one truth: whether a human is present for a specific action. Unlike traditional verification methods, BotShield:- Confirms presence at the moment of action — Verification happens only when required
- Is scoped to the action at hand — No broad surveillance or tracking
- Is invoked only when it matters — No unnecessary friction for real users
- Produces time-bound attestations — Each verification is consumed by the action itself
- Enforces hardware-backed security — Device passcode is required to ensure attestations are cryptographically valid
Current Availability
BotShield is currently available as SDK A (Signal-Only) — momentary human presence verification with no persistence. Access is granted through a developer application process.BotShield is not a self-service download. To integrate, request developer access and our team will provision your API credentials.
Key Features
Single-Action Verification
Verify human presence for specific actions like checkout, ticketing, or signup
Action-Scoped Enforcement
Enforcement is limited to the specific action being verified
Hardware-Backed Security
Requires device passcode for cryptographically valid attestations
No Persistence
No data persistence across actions — each verification is independent
How It Works
BotShield integrates into your platform’s critical actions via a REST API:- Your server creates a session using your API key
- Your server creates a verification link for the user’s action
- The user opens BotShield via deep link, web URL, or QR code
- BotShield verifies presence using device biometrics (Face ID / Touch ID)
- A Human Presence Signal (HPS) is returned to your server via webhook or polling
- Your server validates the HPS and proceeds with the action
Use Cases
BotShield fits in any stack and is ideal for:- Limited-access drops — Ensure fair access for real customers
- Ticket purchasing — Prevent bot scalping
- High-value checkout — Protect critical transactions
- Account recovery — Verify presence during sensitive operations
- Digital agreement execution — Confirm human presence for consent
- Public posting actions — Reduce spam and abuse