The token
The attestation token is the same signed JWT that BotShield Gate issues. See Verify on your server for the format, the issuer, the 120-second lifetime and the published keys. Trusted Accounts adds three claims.
A token without
trusted_since is never trusted. Do not read a missing date as “trusted since the beginning”.
Verify with the API
POST /sdk/verify-token needs no API key.
Verify locally
This example usesjose.
What to check
- The token is valid and not expired.
organization_idis your organization.request_idis the one your page sent with the token.trustedistrue.
When there is no token
GET /verification/status reports the same result by request_id. After the request completes, the response carries trusted and first_time. For a refused or failed request, reason is already_trusted, rebind_requires_prior_id or unavailable.
Webhook events
Set up delivery and signature verification first. See the Webhooks overview.gate.human_verified
The event gains two fields. Both are always present.
The other fields are described in Webhook events. (
census is the API’s name for BotShield Gate.)
account.unlinked
Sent when a binding ends. The next confirmation on that account is a first-time confirmation again.
The event identifies the account by
handle, not by your platform-user-ref. BotShield does not keep your reference in a readable form, so it cannot send it back. To find the handle for one of your users, search the Console registry by your user reference. The matching row shows the handle.gate.unavailable
A request to secure an account that does not complete ends with this event.
failure_code is present only for the two binding conflicts. A request produces one terminal event. Use request_id as your idempotency key.
Keep your records current
Do not rely on webhooks alone. A later gate pass on the account reports the current
trusted value in its token.