Browser verification for sign-in, account creation, checkout, and the other actions your application needs to protect. Invisible to the person using it.
Wrap a browser route handler in Next.js or Express. Connect it from the terminal in a few commands. Start in Observe from Policy Studio, without a redeploy.
Verify on your server
Wrap the handler that commits the action. Browser proof is checked per request, and your code still owns authentication, validation and business logic.
app/api/checkout/route.ts
import { withMandateManaged } from"@mandate-security/node/next";exportconst POST = withMandateManaged(async (request, context) => {// Keep your authentication, validation, and business logic here.// context.mandate separates policy outcome from browser verification.return Response.json({ ok: true });});
Any browser route
Express gets the same managed guard as middleware. Keep machine clients, webhooks and auth callbacks outside browser verification.
Log in once, preview the managed setup for one route, then check it. A new connection starts paused; you choose when to observe.
Terminal
# connect this app$ npx --no-install mandate login# preview, then apply with --write$ npx --no-install mandate setup --managed --route /api/signup --method POST$ npx --no-install mandate verify
Managed SDK preview. The @mandate-security packages are not yet published to their registries; your dashboard supplies the matching install command.
02 — POSITION
The edge sees traffic. Verify sees the action.
Anything in front of your application sees requests. It does not see whether the browser behind this sign-in or checkout produced fresh proof for it.
Proof travels with the request
A short-lived, opaque credential rides along with the protected request. It is not a JWT or a readable summary of the browser.
Checked against live state
Hosted verification cross-references server-side state, including replay and session continuity, before your handler decides.
Nothing for the customer to solve
The core flow has no checkbox, puzzle or branded interstitial. Your application keeps its own success and error states.
Browser evidence. Application authority.Your server still makes the call.
03 — SPECS
Tech specs
See what is inside the box.
Integrations
Managed SDK preview for Next.js App Router and Express (@mandate-security/node), set up with @mandate-security/cli. Packages are not yet published to their registries.
Proof
Short-lived and opaque, carried with the protected request. Not a JWT, and not a customer-readable summary of browser characteristics.
Verification
Hosted and server-side. Each covered request makes one managed-decision call that cross-references live state, including replay and session continuity.
Modes
Native Verify workflows currently observe. More restrictive workflow settings are not a promise of released enforcement.
Visitor experience
No CAPTCHA, checkbox, puzzle or branded challenge in the core flow. Plan explicitly for unavailable verification and for a customer who needs to retry.
Reporting
Grouped evidence. Customer reporting does not expose raw browser fingerprints, behavior traces or private detection internals.
Out of scope
Webhooks, OAuth callbacks, machine APIs and scheduled jobs. Browser verification does not establish that a person is human.