Documentation
Understand the integration.
On-site signals. An explainable score. A decision that stays on your server.
How it fits together. A small reviewed collector runs on your pages, your backend relays scored evidence through the Volance API with a secret key, and the portal keeps the workspace, keys, sessions, and usage.
How an integration works
Choose where collection belongs.
The scopes are a whole site, selected pages, or a server-side API endpoint. Browser-based integrations collect on-site behavioral and client signals only where the script is installed. An API-only integration uses request-level evidence without inventing browser activity.
- Collection is your decision. Your pages load the reviewed collector with a public
pk_key and obtain a signed session manifest, which also carries your workspace's collection settings. Nothing is collected from a page until you deploy the collector there, and fingerprint signals stay off until you turn them on. Read the privacy page before you plan collection. - Score from your backend. Your server submits session evidence to
POST /api/trace/scorewith its secretsk_key, sent as a bearer header and never exposed to a browser. - Inspect before enforcing. Your application reads the score, classification, and evidence, then applies its own allow, flag, or block policy. A browser display is not an enforcement boundary.
- Verify when using a token.
POST /api/trace/verify-tokenchecks a returned trust token server-side, and each token verifies once.
Read the result without conflating the fields.
score- A human-likeness estimate on a 0–100 scale, not a probability or proof of identity.
classification.label- An estimate of the traffic class:
human,agent, orbot. It does not by itself authorize access. verdict- The policy-facing assessment, such as
likely_humanorsuspicious_agent. It is distinct from the classification label. actionand policy- The proposed response: allow, flag, or block. Your server controls enforcement; authorized automation can be allowed.
signalsand cascade- Signals explain the evidence. A cascade means additional checks for an uncertain result, not proof that a visitor is human.
Volance measures automation. It is not a CAPTCHA and does not prove a human was present.
Continue with the API reference or check the status page.