Skip to main content
A binding has two sides. Your organization sees it in the registry in the BotShield Console. The person sees it in the Trusted Accounts list in the BotShield app. Either side can end it.

The registry

In the BotShield Console, open Trusted Accounts. The Registry tab lists every binding for your organization. Use the Development and Production switch to choose the environment. A binding appears under the environment of the gate it came through. The registry is a list of accounts, not of people. A row never shows an email address, a name, a device or another platform.

Columns

Totals

The period is Last 30 days, 90 days or All time. The filters All, Notarized and Unlinked choose which rows the table shows.

Search by your user reference

Type one of your own account IDs, the value you pass as platform-user-ref, into Search by your user ref. The match is exact. BotShield hashes what you type and compares it with the stored hash, then shows the row with its handle. Your reference is never stored in a readable form and never shown back to you. This is how you find the handle for one of your users.

Export CSV

Export CSV downloads the rows that are loaded in the table, with these columns: Handle, Trusted since, Last pass, Via gate, Status, Unlinked at, Unlinked by.

Revoke

Select Revoke on an active row to end the binding. The Console asks Stop trusting this account? before it continues. After a revoke: Revoke an account when:
  • The user deleted or closed the account on your side.
  • The account changed hands.
  • A sign-in detail changed, such as a password reset you did not expect, and you want the human to confirm again.
A revoke that finds no active binding succeeds and changes nothing.

What the person controls

The person manages their side in the BotShield app, under Trusted Accounts. A person cannot secure an account again from the app alone. The request always starts on your page, where your sign-in shows which account it is. The app confirms the human. Your page identifies the account. The person can type or scan a code in the app under Link account, but the code comes from your page. An unlinked account is an ordinary account again:
  • A gate pass on it reports trusted: false.
  • The widget shows the offer on the next visit, when the offer is on.
  • Securing it again produces gate.human_verified with first_time: true.
Keep your own record in step by handling account.unlinked. See Token and webhooks.