Skip to main content
A Trusted Account is an account on your platform that one real human has bound to their BotShield ID. The person does it once, with a passkey, from an offer you show after they sign in. From then on, every verification on that account tells you that a human is behind it and since when. BotShield tells you that a human runs the account, never who. You receive no name, no email address and no device information. Trusted Accounts is part of a paid plan. See pricing.

Three parties, three verbs

The binding exists only because the person confirmed it. Nothing creates a Trusted Account in the background, and passing a gate never does.

What you learn and what you never learn

The handle is different on every platform. Two platforms cannot compare handles to find the same person.

One human, one account

On your platform, one BotShield ID secures one account, and one account is secured by one BotShield ID. BotShield refuses anything else: This is what makes a second account cost a second human.

How it relates to BotShield Gate

A gate and a Trusted Account answer different questions. Three rules connect them:
  • The Console switch decides where the offer appears. Each Human Gate has a switch in the Console, Notarize account with BotShield. Widgets placed with that gate show the offer only while the switch is on. The widget’s notarize="false" attribute can turn the offer off for one placement. Nothing in your page markup can turn the offer on.
  • The binding belongs to your platform, not to one gate. The switch chooses which gates carry the offer. After an account is secured, every gate on your platform that receives the same platform-user-ref reports trusted: true for it. platform-user-ref is your stable ID for the account on your platform. BotShield uses it to recognise a Trusted Account.
  • A gate pass never creates or changes a binding. Passing a gate proves a human is present. Only the person’s confirmation on the offer secures an account.
You can place gates and never turn the offer on. An Age Gate never shows the offer.

How it works

1

You show the offer

With the gate’s switch on, your page renders the widget after your own sign-in, with your stable ID for the account in platform-user-ref, and optionally account-hint. The person sees Secure your account with BotShield.
2

The person taps Link BotShield ID

On a phone the tap opens BotShield. On a desktop it opens BotShield in a new tab, or shows a QR code and a 6-character code to use from a phone. The code lasts 5 minutes and works once.
3

The person confirms with a passkey

BotShield asks Secure your account? and names your platform. The person confirms with their device biometric, or cancels.
4

You receive the result

Your page gets botshield:success with trusted: true. Your server verifies the token, and your webhook endpoint receives gate.human_verified with trusted: true and first_time: true.
The BotShield Demos run BotShield Gate and Agents Ask on production keys. To run the Trusted Accounts confirmation yourself, use Trusted Accounts, then Try it in the BotShield Console.

Next steps

Quickstart

Turn on the offer, add the widget and verify the result.

Widget reference

Attributes, events, card states and failure reasons.

Token and webhooks

The trust claims and the events your server receives.

Managing accounts

The registry, Revoke, and what the person can do.