Documentation

Understand the integration.

On-site signals. An explainable score. A decision that stays on your server.

How it fits together. A small reviewed collector runs on your pages, your backend relays scored evidence through the Volance API with a secret key, and the portal keeps the workspace, keys, sessions, and usage.

Choose where collection belongs.

The scopes are a whole site, selected pages, or a server-side API endpoint. Browser-based integrations collect on-site behavioral and client signals only where the script is installed. An API-only integration uses request-level evidence without inventing browser activity.

  1. Collection is your decision. Your pages load the reviewed collector with a public pk_ key and obtain a signed session manifest, which also carries your workspace's collection settings. Nothing is collected from a page until you deploy the collector there, and fingerprint signals stay off until you turn them on. Read the privacy page before you plan collection.
  2. Score from your backend. Your server submits session evidence to POST /api/trace/score with its secret sk_ key, sent as a bearer header and never exposed to a browser.
  3. Inspect before enforcing. Your application reads the score, classification, and evidence, then applies its own allow, flag, or block policy. A browser display is not an enforcement boundary.
  4. Verify when using a token. POST /api/trace/verify-token checks a returned trust token server-side, and each token verifies once.

Read the result without conflating the fields.

score
A human-likeness estimate on a 0–100 scale, not a probability or proof of identity.
classification.label
An estimate of the traffic class: human, agent, or bot. It does not by itself authorize access.
verdict
The policy-facing assessment, such as likely_human or suspicious_agent. It is distinct from the classification label.
action and policy
The proposed response: allow, flag, or block. Your server controls enforcement; authorized automation can be allowed.
signals and cascade
Signals explain the evidence. A cascade means additional checks for an uncertain result, not proof that a visitor is human.

Volance measures automation. It is not a CAPTCHA and does not prove a human was present.

Continue with the API reference or check the status page.