Skip to main content
Use a browser SDK to identify a visitor and obtain a Request ID. Send that ID with the action your application is protecting. Your backend uses a server SDK to read the identification and its Risk Score, risk signals and detection flags, or verifies a signed webhook.
Only the Public Key belongs in browser code. Keep Private API Keys and webhook signing secrets on your server. Never put them in a public environment variable, browser bundle or GTM container.

Browser packages

See each package README for framework versions, provider setup, consent-aware loading and required peer dependencies. Follow the identification flow when passing a Request ID to a protected server action. A Request ID alone is not a risk verdict.

Server packages

Server SDKs provide identifier-based History reads, wait-for-verdict helpers, Management profile reads and raw-body webhook signature verification. They preserve unknown fields and compatible historical values while exposing a normalized identification model. See Server API for authentication and pagination, and webhooks for signature handling.

OpenAPI and SDK updates

The normative HTTP description is maintained in shieldlabs-openapi. Download this site’s YAML bundle or JSON bundle. The docs copy records its immutable source commit and checksums. Changes to the schema arrive as reviewable updates. The SDK generation pipelines check their pinned descriptions and supported client integration. A schema change does not install a new SDK version in your application: upgrade the package explicitly after reviewing its changelog. Generated wire types describe API fields. The supported clients retain their own transport, timeouts, polling, tolerant normalization and webhook verification. A standalone reference client in generated/ is not a replacement for the documented package entrypoint. Request ID, IP, User HID, Device ID, Visitor ID, Session ID and Cookie ID are exact lookup types. total counts matches for that lookup, not all identifications of a domain. A summary computed from a bounded history window is not a complete domain-wide traffic report.