What counts toward your plan
Counted: identifications
Each identification counts once against your account’s included volume. Its Risk Score,
signals and webhook come with it.Free: API reads
History API reads on
account.shieldlabs.ai and the Management API GET /v1/profile never count toward your plan.Free: webhooks
Webhook delivery never counts toward your plan.
Free: analytics dashboard
The analytics dashboard, every breakdown, CSV export, and your plan and usage.
The simple rule: each new identification counts toward your plan. Reading results through the History API, everything in the analytics dashboard and every webhook ShieldLabs sends you are free.
Plans
The Free plan is a one-time allowance of 5,000 identifications, no credit card required. Starter, Growth and Scale include a volume of identifications each billing month, shared by every domain on your account. For traffic above Scale, Custom volume is a committed-volume quote: contact us.
Billing frequency
Pick monthly or yearly billing. Yearly billing costs 20% less:
Included identifications renew every month on monthly and yearly billing alike. On yearly billing, each month starts on the day of the month your subscription started, and that month is the billing cycle: the included volume, its reset date and the
402 described below all follow it.
You can change your plan or billing frequency any time on Usage in the analytics dashboard: pick Monthly or Yearly, choose a plan, and confirm it in the dialog. The dialog shows a Stripe preview of the amount and warns you when the new plan is smaller than your current usage. A downgrade starts at the next renewal, when usage resets.


Changing plan in the analytics dashboard, with a Stripe preview of the amount.
What every plan includes
Every plan (Free, Starter, Growth and Scale) ships the full feature set. The tiers differ on included identifications, how many domains you can keep active and the per-domain ingest rate on the gateway. Scale adds priority support and a 99.9% uptime SLA.- Users, devices, visitors and IPs: users (the hashed User HID you pass), devices, visitors, public IPs and local IPs, identified and scored. The Device ID holds through cleared cookies, incognito mode and IP changes. Identifiers lists every ID.
- High-Risk Events: Multi-accounting, Account sharing, Impossible travel and Account takeover, detected on your users out of the box, each at Medium or High confidence. High-Risk Events are available in the analytics dashboard, the API and webhooks.
- Risk signals: network and device intelligence (VPN, proxy, Tor, Privacy Relay, datacenter IP, anti-detect browser detection) and bot detection, drawn from 300+ device and network signals collected on each identification.
- Risk scoring: the explainable 0-100 Risk Score of each identification, with every risk signal named and weighted.
- Traffic analytics: the analytics dashboard with traffic quality by source, channel and campaign, every breakdown, and CSV export.
- API: read one identification by request ID, or every identification of one user, device, visitor or IP address, from your backend.
- Webhooks: the Risk Score and every named risk signal of each identification, pushed to your endpoints about 300 ms after the check.
- Support: chat and email on every plan, including Free; Scale adds priority support.
Compare all features
Every plan, Free included, ships the same capabilities; plans differ on included identifications, active domains, ingest rate, support and the uptime SLA. Volume and limits
Identification
Risk Signals
Bots and automation
Risk Scoring
High-Risk Events
Analytics
API & Delivery
Platform & Support
Estimating your monthly identifications
Usage follows how many identifications your pages run:1
Count your identifications
On signed-in pages, call
checkAuthenticatedUser(hashedUserId); that steady coverage is what builds each user’s risk, linked devices and High-Risk Events. Within one visit (while a page of your site stays open in the browser), it runs at most one identification every five minutes for the same user, shared across open tabs, and a call inside that window counts nothing. On a multi-page site, a full page load in the only open tab can start a new visit with its own identification. Each forceCheckAuthenticatedUser or forceCheckAnonymous call, at sign-up, login, checkout or another sensitive action, adds one identification. Logged-out pages you score with checkAnonymous follow the same five-minute rule.2
Prefer webhooks for live decisions
Acting on the webhook you already received is free, and so are reads through the History API on
account.shieldlabs.ai.3
Read the rest in the analytics dashboard
Analytics, breakdowns and exports are free, so reporting and review work never adds to your bill.
When you reach your included volume
When your account reaches its included volume, identification pauses: the identification request returns HTTP 402 until the billing cycle resets or you change plan. History API and profile reads never return402. On Free, the 5,000 identifications are one time, so identification resumes when you move to a paid plan.
On Usage, the Identifications card shows how much of your included volume you used this billing cycle, what remains and the date usage resets. It follows the billing cycle, not the period you pick on other screens. Reads through the History API never use included identifications.


Included identifications for the billing cycle, in the analytics dashboard's Usage screen.