> ## Documentation Index
> Fetch the complete documentation index at: https://docs.shieldlabs.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# SDKs

> Install the browser and server SDKs and understand their public API contract.

Use a browser SDK to identify a visitor and obtain a Request ID. Send that ID with the action
your application is protecting. Your backend uses a server SDK to read the identification and
its Risk Score, risk signals and detection flags, or verifies a signed webhook.

<Warning>
  Only the Public Key belongs in browser code. Keep Private API Keys and webhook signing secrets
  on your server. Never put them in a public environment variable, browser bundle or GTM container.
</Warning>

## Browser packages

| Stack | Package | Installation |
| - | - | - |
| JavaScript / TypeScript | [shieldlabs-js](/sdks/javascript) | `npm install @shieldlabs-ai/js` |
| React | [shieldlabs-react](/sdks/react) | `npm install @shieldlabs-ai/react` |
| Vue | [shieldlabs-vue](/sdks/vue) | `npm install @shieldlabs-ai/vue` |
| Angular | [shieldlabs-angular](/sdks/angular) | `npm install @shieldlabs-ai/angular` |
| Svelte / SvelteKit | [shieldlabs-svelte](/sdks/svelte) | `npm install @shieldlabs-ai/svelte` |
| Next.js | [shieldlabs-next](/sdks/nextjs) | `npm install @shieldlabs-ai/next` |

See each package README for framework versions, provider setup, consent-aware loading and
required peer dependencies. Follow the [identification flow](/api/identification-flow) when
passing a Request ID to a protected server action. A Request ID alone is not a risk verdict.

## Server packages

| Language | Package | Installation |
| - | - | - |
| Node.js / TypeScript | [shieldlabs-node](/sdks/node) | `npm install @shieldlabs-ai/node` |
| Python | [shieldlabs-python](/sdks/python) | `pip install shieldlabs` |
| Go | [shieldlabs-go](/sdks/go) | `go get github.com/ShieldLabs-ai/shieldlabs-go` |
| PHP | [shieldlabs-php](/sdks/php) | `composer require shieldlabs/shieldlabs-php` |
| Java | [shieldlabs-java](/sdks/java) | Maven coordinate `ai.shieldlabs:shieldlabs-java` |
| .NET | [shieldlabs-dotnet](/sdks/dotnet) | `dotnet add package ShieldLabs` |

Server SDKs provide identifier-based History reads, wait-for-verdict helpers, Management profile
reads and raw-body webhook signature verification. They preserve unknown fields and compatible
historical values while exposing a normalized identification model. See [Server API](/api/server-api)
for authentication and pagination, and [webhooks](/api/webhooks) for signature handling.

## OpenAPI and SDK updates

The normative HTTP description is maintained in
[shieldlabs-openapi](https://github.com/ShieldLabs-ai/shieldlabs-openapi). Download this site's
[YAML bundle](/references/openapi.yaml) or [JSON bundle](/references/openapi.json).

The docs copy records its immutable source commit and checksums. Changes to the schema arrive as
reviewable updates. The SDK generation pipelines check their pinned descriptions and supported
client integration. A schema change does not install a new SDK version in your application:
upgrade the package explicitly after reviewing its changelog.

Generated wire types describe API fields. The supported clients retain their own transport,
timeouts, polling, tolerant normalization and webhook verification. A standalone reference
client in `generated/` is not a replacement for the documented package entrypoint.

Request ID, IP, User HID, Device ID, Visitor ID, Session ID and Cookie ID are exact lookup types.
`total` counts matches for that lookup, not all identifications of a domain. A summary computed
from a bounded history window is not a complete domain-wide traffic report.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.