CAPABILITIES

Verify

Trust the action.
Verify the browser.

Browser verification for sign-in, account creation, checkout, and the other actions your application needs to protect. Invisible to the person using it.

REQUEST PATHIllustrative

POST /api/login

  1. Browser action
  2. Opaque browser proof
  3. Hosted verification
  4. Application decision

Browser evidence. Application authority.

01 — IN YOUR CODE

What Verify adds to a route

Wrap a browser route handler in Next.js or Express.
Connect it from the terminal in a few commands.
Start in Observe from Policy Studio, without a redeploy.

Verify on your server

Wrap the handler that commits the action. Browser proof is checked per request, and your code still owns authentication, validation and business logic.

app/api/checkout/route.ts
import { withMandateManaged } from "@mandate-security/node/next"; export const POST = withMandateManaged(async (request, context) => {  // Keep your authentication, validation, and business logic here.  // context.mandate separates policy outcome from browser verification.  return Response.json({ ok: true });});

Any browser route

Express gets the same managed guard as middleware. Keep machine clients, webhooks and auth callbacks outside browser verification.

server/routes.js
import {  mandateManagedMiddleware as mandate,} from "@mandate-security/node/express"; // Protect the browser action; leave machine APIs unguarded.app.post("/app/signup",  mandate({ verify: true, reroute: false }),  signupHandler);app.post("/webhooks/payments", paymentsWebhook);

Set up from the terminal

Log in once, preview the managed setup for one route, then check it. A new connection starts paused; you choose when to observe.

Terminal
# connect this app$ npx --no-install mandate login # preview, then apply with --write$ npx --no-install mandate setup --managed --route /api/signup --method POST $ npx --no-install mandate verify

Managed SDK preview. The @mandate-security packages are not yet published to their registries; your dashboard supplies the matching install command.

02 — POSITION

The edge sees traffic. Verify sees the action.

Anything in front of your application sees requests. It does not see whether the browser behind this sign-in or checkout produced fresh proof for it.

Proof travels with the request

A short-lived, opaque credential rides along with the protected request. It is not a JWT or a readable summary of the browser.

Checked against live state

Hosted verification cross-references server-side state, including replay and session continuity, before your handler decides.

Nothing for the customer to solve

The core flow has no checkbox, puzzle or branded interstitial. Your application keeps its own success and error states.

CDNSEES PACKETSWAFSEES REQUESTSRATE LIMITSEES COUNTSMANDATE VERIFYSEES THE BROWSER ACTION
Browser evidence. Application authority.Your server still makes the call.

03 — SPECS

Tech specs

See what is inside the box.

Integrations

Managed SDK preview for Next.js App Router and Express (@mandate-security/node), set up with @mandate-security/cli. Packages are not yet published to their registries.

Proof

Short-lived and opaque, carried with the protected request. Not a JWT, and not a customer-readable summary of browser characteristics.

Verification

Hosted and server-side. Each covered request makes one managed-decision call that cross-references live state, including replay and session continuity.

Modes

Native Verify workflows currently observe. More restrictive workflow settings are not a promise of released enforcement.

Visitor experience

No CAPTCHA, checkbox, puzzle or branded challenge in the core flow. Plan explicitly for unavailable verification and for a customer who needs to retry.

Reporting

Grouped evidence. Customer reporting does not expose raw browser fingerprints, behavior traces or private detection internals.

Out of scope

Webhooks, OAuth callbacks, machine APIs and scheduled jobs. Browser verification does not establish that a person is human.