Opaque browser tokens
The browser receives a cryptographically random token. Risk score and decision metadata stay server-side.
Novera scores bot risk silently, returns one opaque token to the browser, and keeps the real decision inside an authenticated server-to-server verification.
A layered, explainable risk engine looks for weak signals across behavior, velocity, network, and browser integrity—never one brittle check.
The browser receives a cryptographically random token. Risk score and decision metadata stay server-side.
See useful factors like unusual velocity or short interaction time without exposing proprietary rule weights.
Tune login, signup, checkout, and custom actions independently with managed or custom thresholds.
No typed values, form contents, passwords, or session replay. Only bounded, summarized interaction counters.
Short-lived tokens are atomically consumed. A concurrent second verification is rejected every time.
A small async SDK, predictable test keys, typed server SDKs, and copy-paste integrations for every major stack.
An attacker can intercept JavaScript, change variables, or forge frontend responses. None of it changes the score stored by Novera or the result your backend receives.