Bot Protection with Edge Shield
Stop form spam, credential stuffing, and fake signups without ever showing a human a puzzle. Two lines on the page, one HTTP call on the server — free forever.
Why not just use a CAPTCHA?
Traditional CAPTCHAs make humans do work that AI now does better — image puzzles cost you real conversions while modern bots solve them for fractions of a cent. And most "invisible" alternatives pay for their invisibility with tracking.
Edge Shield takes a different approach: a lightweight proof-of-work runs in a background thread while the page loads, corroborated by server-side signals — solve timing, header coherence, network reputation, TLS characteristics. The result is a humanity score from 1 to 100 attached to every verification, with no cookies, no fingerprint database, and no per-visitor data stored.
1. Add the widget to your form
Create a widget in the control panel (verified email is all you need — no card), then drop the script tag and a placeholder div into any form:
<script src="https://shield.edge.network/api.js" defer></script>
<form action="/signup" method="POST">
<input type="email" name="email" required />
<div class="edge-shield" data-sitekey="es_your_sitekey"></div>
<button type="submit">Sign up</button>
</form>
Verification runs while the visitor fills in the form, and the token lands in a hidden
edge-shield-response
input automatically. In the default managed mode, real visitors see a
small "Verified" badge; only suspicious traffic gets a single-click confirmation backed
by a harder challenge.
2. Validate the token server-side
Client-side checks alone protect nothing — always validate the token from your server. Tokens are single-use and expire after five minutes, so replayed or scripted submissions fail even if they captured a real token. The response shape is compatible with Cloudflare Turnstile, so migrating is a URL swap.
// On your server, before processing the form
const res = await fetch('https://shield.edge.network/siteverify', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({
secret: process.env.SHIELD_SECRET,
response: req.body['edge-shield-response'],
}),
})
const { success, score, agent } = await res.json()
if (!success) return reject() // invalid, expired, or replayed
if (agent?.verified) return route() // declared automation — your call
if (score < 40) return stepUp() // suspicious — require confirmation 3. Act on the score, not just the verdict
The score turns bot protection from a binary gate into a policy you control. Sensible starting bands:
| Score | Meaning | Suggested action |
|---|---|---|
| 70–100 | Confident human | Let them straight through. |
| 40–69 | Uncertain | Step up: email confirmation, or rely on managed mode’s one-click check. |
| 1–39 | Automation | Block — or route verified agents to your API instead. |
Note the third row: "automation" doesn't have to mean "blocked". AI agents acting for real customers score low honestly — and if they sign their requests with Web Bot Auth, the siteverify response tells you exactly who they are, so you can send them to your API instead of a dead end.
Where it earns its keep
- Signup and login forms — stop credential stuffing and fake account waves without adding friction for real users.
- Contact and comment forms — kill form spam at the source instead of moderating it afterwards.
- Checkouts — card-testing bots hammer payment forms; a score floor before the payment call cuts fraud and processor fees.
- Newsletter subscriptions — protect your sender reputation from bot-filled lists.
Every form on this site — including the newsletter box in the footer — runs Shield in invisible mode. You've been verified several times just browsing, and never noticed.