FOR DEVELOPERS How Verify works

From browser action
to server decision.

Collection in the browser. Verification on the server. Application rules at the point where the action happens.

REQUEST PATHIllustrative

The verification lifecycle

  1. Collect browser evidence
  2. Issue opaque proof
  3. Validate with live state
  4. Apply application rules

Browser evidence. Application authority.

1. Connect the browser

A supported integration loads browser collection for your application. The core flow runs invisibly, without a checkbox or puzzle. Choose browser-originated routes whose callers can participate in that flow.

2. Carry short-lived proof

The integration carries an opaque credential with the protected request. It is not a JWT or a customer-readable summary of browser characteristics. Keep credentials out of logs and do not treat their presence as a successful verification.

3. Ask the hosted service

Your server submits proof through its server-side integration. Hosted verification cross-references live state for the decision, including replay and session continuity. Keep server credentials on the server.

4. Complete the application decision

Apply your authentication, authorization, business rules, and supported verification policy. Observe-only integrations record evidence without claiming enforcement. Handle retries and verification errors explicitly, then review the business outcome separately.