> ## Documentation Index
> Fetch the complete documentation index at: https://docs.shieldlabs.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Fraud detection and prevention docs

> Detect risky users, devices and IPs under any masking, and stop multi-accounting, account sharing and takeovers.

<div className="sl-home">
  <section className="sl-hero">
    <div>
      <h1 className="sl-hero-title">Detect risky users<br /><span className="sl-brand">under any masking</span></h1>
      <p className="sl-hero-sub">Stop multi-accounting, account sharing and takeovers. ShieldLabs scores every user, device, visitor and IP address, with <a href="/features/accuracy">99.9% identification accuracy and 99.9% risk signal detection accuracy</a>. Integration takes five minutes.</p>

      <div className="sl-cta">
        <a className="sl-btn sl-btn-primary" href="/quickstart">Get started</a>
        <a className="sl-btn sl-btn-ghost" href="/api/overview">Explore the API</a>
      </div>

      <p className="sl-strip">Five-minute integration · API and webhooks</p>
    </div>

    <div className="sl-hero-visual">
      <div className="sl-score-card">
        <div className="sl-score-section">User</div>
        <div className="sl-score-row"><span className="sl-score-key">User HID</span><span className="sl-score-val">e3b0…b924</span></div>
        <div className="sl-score-row"><span className="sl-score-key">Risk</span><span className="sl-score-val"><span className="sl-badge-high">DANGEROUS</span></span></div>
        <div className="sl-score-row"><span className="sl-score-key">Linked devices</span><span className="sl-score-val">2</span></div>
        <div className="sl-score-row"><span className="sl-score-key">Linked public IPs</span><span className="sl-score-val">4</span></div>
        <div className="sl-score-section">High-Risk Event</div>
        <div className="sl-score-row"><span className="sl-score-key">Multi-accounting</span><span className="sl-score-val"><span className="sl-badge-confidence">HIGH CONFIDENCE</span></span></div>
        <div className="sl-score-section">Latest identification</div>
        <div className="sl-score-row"><span className="sl-score-key">Device ID</span><span className="sl-score-val">d290…0851</span></div>
        <div className="sl-score-row"><span className="sl-score-key">VPN</span><span className="sl-score-pts">+15</span></div>
        <div className="sl-score-row"><span className="sl-score-key">Anti-detect Browser</span><span className="sl-score-pts">+60</span></div>
        <div className="sl-score-row sl-score-total"><span className="sl-score-key">Risk Score</span><span className="sl-score-val sl-score-big">75<span className="sl-badge-high">DANGEROUS</span></span></div>
      </div>
    </div>
  </section>

  <section className="sl-section">
    <h2 className="sl-h2">Detect risky users. Stop abuse of your product.</h2>
    <p className="sl-lead">One integration gives you your users, devices, visitors and IPs with their risk, the four High-Risk Events, every risk signal and your traffic quality.</p>

    <CardGroup cols={3}>
      <Card title="High-Risk Events" icon="diagram-project" href="/features/high-risk-events">
        Multi-accounting, Account sharing, Impossible travel and Account takeover, detected on your users out of the box, each at Medium or High confidence.
        <div className="sl-pills"><span className="sl-pill">Multi-accounting</span><span className="sl-pill">Account sharing</span><span className="sl-pill">Impossible travel</span><span className="sl-pill">Account takeover</span></div>
      </Card>

      <Card title="Users, devices, visitors and IPs" icon="fingerprint" href="/concepts/entities">
        Link every user to the devices, visitors and IP addresses they use, each with its own risk band. The Device ID holds through cleared cookies, incognito mode and IP changes.
        <div className="sl-pills"><span className="sl-pill">User HID</span><span className="sl-pill">Device ID</span><span className="sl-pill">Visitor ID</span><span className="sl-pill">Public IP</span><span className="sl-pill">Local IP</span></div>
      </Card>

      <Card title="Risk Signals" icon="mask" href="/features/risk-signals">
        Catch the masking and automation behind risky users, well beyond IP blocklists: VPNs, proxies, Tor, datacenter IPs, anti-detect browsers, bots and browser automation.
        <div className="sl-pills"><span className="sl-pill">VPN</span><span className="sl-pill">Proxy</span><span className="sl-pill">Tor</span><span className="sl-pill">Anti-detect</span><span className="sl-pill">Bots</span><span className="sl-pill">+ more</span></div>
      </Card>

      <Card title="Risk Scoring" icon="gauge" href="/features/risk-scoring">
        Every identification gets a Risk Score from 0 to 100 with each risk signal named and weighted. Users, devices, visitors and IPs carry the worst band of their identifications.
        <div className="sl-pills"><span className="sl-pill">0-100</span><span className="sl-pill">Trusted</span><span className="sl-pill">Suspicious</span><span className="sl-pill">Dangerous</span></div>
      </Card>

      <Card title="Traffic Analytics" icon="chart-line" href="/features/traffic-analytics">
        Score your traffic quality by channel, referrer and UTM campaign.
        <div className="sl-pills"><span className="sl-pill">Channels</span><span className="sl-pill">Referrers</span><span className="sl-pill">UTM</span><span className="sl-pill">Traffic quality</span></div>
      </Card>
    </CardGroup>

    <Frame caption="The Overview screen of the analytics dashboard: traffic quality, users, High-Risk Events and risk signals for the selected period.">
      <img className="block dark:hidden" src="https://mintcdn.com/shieldlabs-725d18f1/JyleDzUFYU3SXP4Q/images/dashboard/overview-hero.png?fit=max&auto=format&n=JyleDzUFYU3SXP4Q&q=85&s=60cb66f3d0ce88b6db66cfe1c4b4ae9b" alt="The Overview screen of the analytics dashboard for the last 7 days: traffic quality at 14.36, Trusted, over 12,480 identifications; 1,240 users with 104 risky users and 46 High-Risk Event users; the four High-Risk Events with their Medium and High confidence counts; 3,910 unique visitors, 3,490 Trusted and 420 risky; the top risk signals VPN, Timezone Mismatch, Datacenter IP and Proxy; and the riskiest identifications." width="2880" height="1800" data-path="images/dashboard/overview-hero.png" />

      <img className="hidden dark:block" src="https://mintcdn.com/shieldlabs-725d18f1/JyleDzUFYU3SXP4Q/images/dashboard/overview-hero-dark.png?fit=max&auto=format&n=JyleDzUFYU3SXP4Q&q=85&s=5e4f1a680dcf02dde5499ef029af8103" alt="The Overview screen of the analytics dashboard in the dark theme for the last 7 days: traffic quality at 14.36, Trusted, over 12,480 identifications; 1,240 users with 104 risky users and 46 High-Risk Event users; the four High-Risk Events with their Medium and High confidence counts; 3,910 unique visitors, 3,490 Trusted and 420 risky; the top risk signals VPN, Timezone Mismatch, Datacenter IP and Proxy; and the riskiest identifications." width="2880" height="1800" data-path="images/dashboard/overview-hero-dark.png" />
    </Frame>

    <p className="sl-lead"><a href="/dashboard/overview">Tour the analytics dashboard</a></p>
  </section>

  <section className="sl-section">
    <h2 className="sl-h2">Start by use case</h2>
    <p className="sl-lead">Each recipe is a worked, copy-pasteable flow built on your users, their devices and IPs, and the Risk Score of each identification.<br /><a href="/use-case">View all use cases</a></p>

    <div className="sl-uc-theme">Protect your users</div>

    <CardGroup cols={3}>
      <Card title="Account Takeover" icon="user-shield" href="/use-case/account-takeover">
        Account takeover is detected on the user at Medium or High confidence. Step up before a sensitive action.
      </Card>

      <Card title="Credential Stuffing" icon="key" href="/use-case/credential-stuffing">
        Tell a spray of scripted logins apart from your real returning users.
      </Card>

      <Card title="Login and 2FA" icon="lock" href="/use-case/step-up-authentication">
        Skip friction for known devices, step up only when a login looks risky.
      </Card>
    </CardGroup>

    <div className="sl-uc-theme">Grow your revenue</div>

    <CardGroup cols={3}>
      <Card title="New Account Fraud" icon="user-plus" href="/use-case/new-account-fraud">
        Catch one device or local IP opening many fresh accounts at signup.
      </Card>

      <Card title="Promo Abuse" icon="ticket" href="/use-case/promo-abuse">
        Stop multi-accounting from draining coupons and signup bonuses.
      </Card>

      <Card title="Account Sharing" icon="users" href="/use-case/account-sharing">
        Detect one account used from several distinct devices, at Medium or High confidence.
      </Card>

      <Card title="Paywall Enforcement" icon="newspaper" href="/use-case/paywall">
        Recognize the same device through cleared cookies and incognito mode.
      </Card>

      <Card title="Regional Pricing" icon="globe" href="/use-case/regional-pricing">
        Catch VPNs and proxies used to reach a cheaper region's price.
      </Card>

      <Card title="Returning Visitor" icon="user-check" href="/use-case/returning-visitor">
        Recognize a trusted device on return and spare it repeated checks.
      </Card>
    </CardGroup>

    <div className="sl-uc-theme">Protect your platform</div>

    <CardGroup cols={3}>
      <Card title="Ban Enforcement" icon="ban" href="/use-case/ban-evasion">
        Keep a banned user's device out, even when they come back with a fresh account.
      </Card>

      <Card title="Chargeback Dispute" icon="file-invoice-dollar" href="/use-case/chargeback-fraud">
        Attach the account's device and identification evidence to a disputed order.
      </Card>

      <Card title="Affiliate Fraud" icon="link" href="/use-case/affiliate-fraud">
        Rank affiliate partners by the risky accounts and self-referred traffic they bring.
      </Card>

      <Card title="Traffic Quality" icon="chart-line" href="/use-case/traffic-quality">
        Grade each channel by the users and devices it brings and its traffic quality.
      </Card>

      <Card title="Checkout" icon="cart-shopping" href="/use-case/payment-fraud">
        Add friction at payment only when the buyer's account or identification looks risky.
      </Card>
    </CardGroup>
  </section>

  <section className="sl-api">
    <input type="radio" name="sl-api-tab" id="sl-t1" className="sl-api-tab-in" defaultChecked />

    <input type="radio" name="sl-api-tab" id="sl-t2" className="sl-api-tab-in" />

    <input type="radio" name="sl-api-tab" id="sl-t3" className="sl-api-tab-in" />

    <div className="sl-api-left">
      <h2 className="sl-api-title">Built for easy integration</h2>
      <p className="sl-api-text">The JavaScript snippet, the Server API and webhooks. ShieldLabs returns a Risk Score with every named risk signal on each identification. You choose the action for each case and act on it in your backend.</p>

      <div className="sl-tablist">
        <label htmlFor="sl-t1" className="sl-tab">JavaScript snippet</label>
        <label htmlFor="sl-t2" className="sl-tab">Server API</label>
        <label htmlFor="sl-t3" className="sl-tab">Webhooks</label>
      </div>

      <div className="sl-cta">
        <a className="sl-btn sl-btn-primary" href="/api/overview">See the full API</a>
      </div>
    </div>

    <div className="sl-api-right">
      <div className="sl-panel sl-p1">
        <pre className="sl-code">
          {`const mod = await import(
                    'https://cdn.shieldlabs.ai/snippet.js?publicKey=YOUR_PUBLIC_KEY'
                    );
                    // Signed-in user: pass a hashed account id
                    mod.checkAuthenticatedUser('HASHED_USER_ID');
                    // Page without a signed-in user:
                    // mod.checkAnonymous();`}
        </pre>

        <ul className="sl-check">
          <li>Identify users and devices with 99.9% identification accuracy</li>
          <li>Works with React, Vue, Svelte, Angular, and plain JS</li>
          <li>One ES module from cdn.shieldlabs.ai, loaded with a dynamic import</li>
        </ul>

        <a className="sl-tab-link" href="/setup/snippet">Read the snippet docs ›</a>
      </div>

      <div className="sl-panel sl-p2">
        <pre className="sl-code">
          {`curl "https://account.shieldlabs.ai/api/v1/history/user_hid/HASHED_USER_ID?limit=20" \\
                    -H "Authorization: Bearer sec_your_private_api_key"`}
        </pre>

        <ul className="sl-check">
          <li>Read every identification of one user, device, visitor or IP</li>
          <li>Authenticate with the Private API Key from Integration > API keys in the analytics dashboard</li>
          <li>Guaranteed read by request ID when a webhook is missed</li>
        </ul>

        <a className="sl-tab-link" href="/api/server-api">Read the Server API docs ›</a>
      </div>

      <div className="sl-panel sl-p3">
        <pre className="sl-code">
          {`POST /your/webhook
                    X-Shield-Signature: sha256=<hmac>

                    {
                    "event_type": "identification.scored",
                    "schema_version": "2026-06-01",
                    "created_at": "2026-06-16T18:00:21Z",
                    "data": {
                      "request_id": "550e8400-e29b-41d4-a716-446655440000",
                      "user_hid": "e3b0c442f8a1b924",
                      "risk_score": 70,
                      "signals": [
                        { "name": "antidetect_browser", "weight": 60 },
                        { "name": "proxy", "weight": 10 }
                      ]
                    }
                    }`}
        </pre>

        <ul className="sl-check">
          <li>Pushed to your backend about 300 milliseconds after the check</li>
          <li>Verify X-Shield-Signature on the raw body</li>
          <li>At-most-once, so make your handler idempotent on request\_id</li>
        </ul>

        <a className="sl-tab-link" href="/setup/webhooks">Read the webhook docs ›</a>
      </div>
    </div>
  </section>

  <section className="sl-section">
    <h2 className="sl-h2">Keep going</h2>

    <CardGroup cols={3}>
      <Card title="Quickstart" icon="rocket" href="/quickstart">
        Install the snippet, identify your first user and read a Risk Score in five minutes.
      </Card>

      <Card title="Troubleshooting" icon="wrench" href="/troubleshooting">
        No webhook, no risk signals, or a Risk Score you did not expect? Start here.
      </Card>

      <Card title="Changelog" icon="clock-rotate-left" href="/changelog">
        What shipped recently across the snippet, the Risk Score and the analytics dashboard.
      </Card>
    </CardGroup>
  </section>
</div>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.