Skip to main content
Trusted Accounts looks familiar if you have built an OAuth integration: a button, a short code, a confirmation on another device, a token. It is a different protocol with a different purpose. This page says what to expect, so you do not look for parts that are not there.

The direction is reversed

OAuth is delegated authorization. A user lets your application call another service on their behalf. Your application ends up holding a token that it uses against that service. Trusted Accounts is an attestation. A person vouches that they are the human behind an account on your platform. Your server ends up holding a signed statement that it verifies. The statement gives your platform no access to BotShield and no ability to act as the person. Trusted Accounts is also not a sign-in. BotShield does not authenticate the user to your platform and does not issue a session. Your own sign-in comes first, and the offer appears after it.

What it borrows

The hand-off between your page and the person’s phone has the same shape as the OAuth device authorization flow: your page shows a short code and a QR code, the person opens a link on another device, and your page waits for the result. Only the shape is shared. No access token is issued at the end.

What your integration needs

Start with the Quickstart.