Skip to main content
ShieldLabs bills per identification, not per monthly active user. An identification is one check by the JavaScript snippet, the event underneath each account. Each plan includes a volume of identifications for your whole account, shared by every domain on it, and covers everything ShieldLabs does with them: your users, devices, visitors and IP addresses, each identified and scored; High-Risk Events detected on your users; and, on every identification, the Risk Score with each named risk signal behind it. You manage your plan and usage on Usage in the analytics dashboard, and your payment method and invoices under Settings > Billing. Usage and plan walks through both screens.

What counts toward your plan

Counted: identifications

Each identification counts once against your account’s included volume. Its Risk Score, signals and webhook come with it.

Free: API reads

History API reads on account.shieldlabs.ai and the Management API GET /v1/profile never count toward your plan.

Free: webhooks

Webhook delivery never counts toward your plan.

Free: analytics dashboard

The analytics dashboard, every breakdown, CSV export, and your plan and usage.
The simple rule: each new identification counts toward your plan. Reading results through the History API, everything in the analytics dashboard and every webhook ShieldLabs sends you are free.

Plans

The Free plan is a one-time allowance of 5,000 identifications, no credit card required. Starter, Growth and Scale include a volume of identifications each billing month, shared by every domain on your account. For traffic above Scale, Custom volume is a committed-volume quote: contact us.

Billing frequency

Pick monthly or yearly billing. Yearly billing costs 20% less: Included identifications renew every month on monthly and yearly billing alike. On yearly billing, each month starts on the day of the month your subscription started, and that month is the billing cycle: the included volume, its reset date and the 402 described below all follow it. You can change your plan or billing frequency any time on Usage in the analytics dashboard: pick Monthly or Yearly, choose a plan, and confirm it in the dialog. The dialog shows a Stripe preview of the amount and warns you when the new plan is smaller than your current usage. A downgrade starts at the next renewal, when usage resets.
The plan change dialog in the analytics dashboard, Downgrade to a lower plan from Growth to Starter: Due today $0.00, Next charge $99.00 monthly from Oct 12, 2026, the Secure checkout note, and the warning that this plan is smaller than current usage.The plan change dialog in the analytics dashboard in the dark theme, Downgrade to a lower plan from Growth to Starter: Due today $0.00, Next charge $99.00 monthly from Oct 12, 2026, the Secure checkout note, and the warning that this plan is smaller than current usage.

Changing plan in the analytics dashboard, with a Stripe preview of the amount.

What every plan includes

Every plan (Free, Starter, Growth and Scale) ships the full feature set. The tiers differ on included identifications, how many domains you can keep active and the per-domain ingest rate on the gateway. Scale adds priority support and a 99.9% uptime SLA.
  • Users, devices, visitors and IPs: users (the hashed User HID you pass), devices, visitors, public IPs and local IPs, identified and scored. The Device ID holds through cleared cookies, incognito mode and IP changes. Identifiers lists every ID.
  • High-Risk Events: Multi-accounting, Account sharing, Impossible travel and Account takeover, detected on your users out of the box, each at Medium or High confidence. High-Risk Events are available in the analytics dashboard, the API and webhooks.
  • Risk signals: network and device intelligence (VPN, proxy, Tor, Privacy Relay, datacenter IP, anti-detect browser detection) and bot detection, drawn from 300+ device and network signals collected on each identification.
  • Risk scoring: the explainable 0-100 Risk Score of each identification, with every risk signal named and weighted.
  • Traffic analytics: the analytics dashboard with traffic quality by source, channel and campaign, every breakdown, and CSV export.
  • API: read one identification by request ID, or every identification of one user, device, visitor or IP address, from your backend.
  • Webhooks: the Risk Score and every named risk signal of each identification, pushed to your endpoints about 300 ms after the check.
  • Support: chat and email on every plan, including Free; Scale adds priority support.

Compare all features

Every plan, Free included, ships the same capabilities; plans differ on included identifications, active domains, ingest rate, support and the uptime SLA. Volume and limits Identification Risk Signals Bots and automation Risk Scoring High-Risk Events Analytics API & Delivery Platform & Support

Estimating your monthly identifications

Usage follows how many identifications your pages run:
1

Count your identifications

On signed-in pages, call checkAuthenticatedUser(hashedUserId); that steady coverage is what builds each user’s risk, linked devices and High-Risk Events. Within one visit (while a page of your site stays open in the browser), it runs at most one identification every five minutes for the same user, shared across open tabs, and a call inside that window counts nothing. On a multi-page site, a full page load in the only open tab can start a new visit with its own identification. Each forceCheckAuthenticatedUser or forceCheckAnonymous call, at sign-up, login, checkout or another sensitive action, adds one identification. Logged-out pages you score with checkAnonymous follow the same five-minute rule.
2

Prefer webhooks for live decisions

Acting on the webhook you already received is free, and so are reads through the History API on account.shieldlabs.ai.
3

Read the rest in the analytics dashboard

Analytics, breakdowns and exports are free, so reporting and review work never adds to your bill.
A login flow that identifies the attempt with forceCheckAnonymous on the form’s first focus, then the signed-in session with forceCheckAuthenticatedUser on the first signed-in page, uses two identifications per login. Reading that account’s earlier identifications through the History API by user_hid adds nothing, since reads are free. Optimize usage and cost maps each touchpoint to its call.

When you reach your included volume

When your account reaches its included volume, identification pauses: the identification request returns HTTP 402 until the billing cycle resets or you change plan. History API and profile reads never return 402. On Free, the 5,000 identifications are one time, so identification resumes when you move to a paid plan. On Usage, the Identifications card shows how much of your included volume you used this billing cycle, what remains and the date usage resets. It follows the billing cycle, not the period you pick on other screens. Reads through the History API never use included identifications.
The Identifications card on Usage in the analytics dashboard: billing cycle Sep 12 to Oct 12, 2026, 41% used, Used 61,240, Remaining 88,760, Included volume 150,000 / month, Usage resets on Oct 12, 2026.The Identifications card on Usage in the analytics dashboard in the dark theme: billing cycle Sep 12 to Oct 12, 2026, 41% used, Used 61,240, Remaining 88,760, Included volume 150,000 / month, Usage resets on Oct 12, 2026.

Included identifications for the billing cycle, in the analytics dashboard's Usage screen.

402 means your included volume is used up. It is separate from 429 rate limiting on the gateway: per IP, per domain, or a temporary domain freeze. A frozen domain pauses processing, is not billed and resumes on its own. The Errors page carries the full status-code list.

Next steps

Compare plans and change yours on Usage in the analytics dashboard, described on Usage and plan. To put results to work, read Acting on results. Delivery and programmatic reads are on the webhooks setup and the Server API pages; neither counts toward your plan.