FOR DEVELOPERS / FAQ

A few useful answers.

What browser verification does, where it fits, and what to check before you connect it.

The product

What does MANDATE protect?

MANDATE is designed for high-value browser actions such as sign-in, account creation, and checkout. It adds browser and request-integrity evidence to the server’s decision. It is not a general WAF, CDN, DDoS service, or payment-fraud scoring system.

Will visitors see a CAPTCHA?

The core browser-verification flow has no CAPTCHA, checkbox, puzzle, or branded challenge. Your application remains responsible for communicating errors and providing a recovery path.

Does a verified browser mean a human is using it?

No. Real browsers can be automated. Browser verification adds evidence about an environment and its requests; it does not establish human identity or guarantee that every automated request is detected.

Which capabilities are available?

Verify is the core browser-verification capability. Limit is implemented in the Node managed candidate with Observe and explicit budget enforcement. Reroute is in development and default-off. EdgeD has provider-specific preview limitations, and Managed ingress is planned. Policy Studio and managed SDK workflows remain Beta / preview; native Verify workflows currently observe. See each capability page for its scope.

Does Limit need browser verification?

A verified-browser budget requires Verify. Limit can also run independently with a trusted server identity resolved from application authentication; that mode needs no browser collector. It counts admission attempts using capacity and continuous refill, not successful transactions.

Integration and rollout

Where should I start?

Choose one browser-originated action with a clear completion signal. Inventory its callers, connect the browser and server sides, then Observe and review legitimate completion before considering enforcement.

Can I install the managed SDK from npm?

The new managed packages are not yet published to their registries. Use the matching package-manager command supplied by your dashboard preview. The legacy npm release does not provide the managed setup workflow.

Can I protect webhooks and machine APIs?

Those callers do not participate in a browser verification flow. Keep them outside browser-only coverage and authenticate them with a method appropriate to the integration.

Does MANDATE replace authentication?

No. Your application must still authenticate the account, check permissions and tenant membership, and apply business rules. Browser proof does not grant an account or permission.

What happens if verification is unavailable?

The answer depends on your integration and policy. Design and test that behavior explicitly. Do not silently treat an error as a verified result. The managed preview requires valid active configuration; its quickstart explains the current failure behavior.

Data and decisions

Are proof credentials JWTs?

No. MANDATE uses short-lived, opaque credentials. Hosted verification cross-references server-side state; applications should not parse a credential to decide whether to trust it.

What appears in customer reporting?

Customer-facing reporting presents grouped evidence. It is not intended to expose raw browser fingerprints, behavior traces, or private detection internals.

Does a verification decision prove an order succeeded?

No. Verification and business completion are separate. Your application must record the order or other operation outcome, and handle duplicate requests and lost responses consistently.

Where can I read about privacy?

The Privacy page describes the current draft scope, service information, and privacy contact. It remains a review draft; deployment-specific processing terms and notices need to match the actual integration.