Three parties, three verbs
The binding exists only because the person confirmed it. Nothing creates a Trusted Account in the background, and passing a gate never does.
What you learn and what you never learn
The handle is different on every platform. Two platforms cannot compare handles to find the same person.
One human, one account
On your platform, one BotShield ID secures one account, and one account is secured by one BotShield ID. BotShield refuses anything else:
This is what makes a second account cost a second human.
How it relates to BotShield Gate
A gate and a Trusted Account answer different questions.
Three rules connect them:
- The Console switch decides where the offer appears. Each Human Gate has a switch in the Console, Notarize account with BotShield. Widgets placed with that gate show the offer only while the switch is on. The widget’s
notarize="false"attribute can turn the offer off for one placement. Nothing in your page markup can turn the offer on. - The binding belongs to your platform, not to one gate. The switch chooses which gates carry the offer. After an account is secured, every gate on your platform that receives the same
platform-user-refreportstrusted: truefor it.platform-user-refis your stable ID for the account on your platform. BotShield uses it to recognise a Trusted Account. - A gate pass never creates or changes a binding. Passing a gate proves a human is present. Only the person’s confirmation on the offer secures an account.
How it works
1
You show the offer
With the gate’s switch on, your page renders the widget after your own sign-in, with your stable ID for the account in
platform-user-ref, and optionally account-hint. The person sees Secure your account with BotShield.2
The person taps Link BotShield ID
On a phone the tap opens BotShield. On a desktop it opens BotShield in a new tab, or shows a QR code and a 6-character code to use from a phone. The code lasts 5 minutes and works once.
3
The person confirms with a passkey
BotShield asks Secure your account? and names your platform. The person confirms with their device biometric, or cancels.
4
You receive the result
Your page gets
botshield:success with trusted: true. Your server verifies the token, and your webhook endpoint receives gate.human_verified with trusted: true and first_time: true.Next steps
Quickstart
Turn on the offer, add the widget and verify the result.
Widget reference
Attributes, events, card states and failure reasons.
Token and webhooks
The trust claims and the events your server receives.
Managing accounts
The registry, Revoke, and what the person can do.
