import ai.shieldlabs.EvaluateOptions;
import ai.shieldlabs.Evaluation;
import ai.shieldlabs.Identification;
import ai.shieldlabs.IdentificationScoredEvent;
import ai.shieldlabs.Risk;
import ai.shieldlabs.ShieldLabsClient;
import ai.shieldlabs.WebhookEvent;
import ai.shieldlabs.Webhooks;
import java.util.Optional;
import java.util.Set;
import java.util.concurrent.ConcurrentHashMap;
public final class QuickStart {
// Reads SHIELDLABS_API_KEY: the Private API Key of your domain (sec_...).
private final ShieldLabsClient shieldlabs = ShieldLabsClient.fromEnvironment();
// One identification authorizes one action. This in-memory set keeps the example short;
// in production, claim request IDs atomically in your database or cache.
private final Set<String> usedRequestIds = ConcurrentHashMap.newKeySet();
// 1. Call this with the requestId the browser sent together with the signup form.
public boolean allowSignup(String requestId) {
// Scoring is asynchronous: this waits (up to 10 seconds by default) until the verdict is stored.
Optional<Identification> identification = shieldlabs.identifications().get(requestId);
// 2. Missing, reused, stale, rate limited, no device signals, browser automation
// or the dangerous band: refuse, or route to review or a step-up check.
Evaluation evaluation = Risk.evaluate(
identification.orElse(null),
EvaluateOptions.builder().replayCheck(id -> !usedRequestIds.add(id)).build());
evaluation.getReason().ifPresent(reason -> System.out.println("refused: " + reason.getValue()));
return evaluation.isOk();
}
// 3. Call this with the raw body and the X-Shield-Signature header of a webhook delivery.
public void handleWebhook(byte[] rawBody, String signatureHeader) {
WebhookEvent event = Webhooks.constructEvent(
rawBody, signatureHeader, System.getenv("SHIELDLABS_WEBHOOK_SECRET")); // whsec_...
if (event instanceof IdentificationScoredEvent) {
Identification scored = ((IdentificationScoredEvent) event).getIdentification();
System.out.println(scored.getRequestId() + " " + scored.getRiskScore());
}
}
public static void main(String[] args) {
String requestId = args[0]; // a request ID your page received from the browser SDK
System.out.println(new QuickStart().allowSignup(requestId) ? "allowed" : "refused");
}
}