How integration works
- 01
Add the script
One script tag on the pages you want protected. It loads asynchronously, never blocks rendering and can run from your own first-party domain.
- 02
Send the token with the action
When a visitor signs up, logs in, claims a bonus or checks out, your page sends the short-lived Kavra token along with the request.
- 03
Verify on your server
One server-side call with your project key returns the assessment: classification, findings and a recommendation.
- 04
Act with your own rules
Allow, verify or block. Start in observe-only mode and switch to enforcement when you trust the results.
Supported platforms
| Platform | How it connects | Typical use |
|---|---|---|
| Websites and web apps | JavaScript script plus one server-side verification call | Signup, login, checkout, forms, promotions |
| iOS apps | Native iOS SDK plus the same server-side call | Account creation, login, payments in the app |
| Android apps | Native Android SDK plus the same server-side call | Referral and bonus flows, emulator and device farm traffic |
| Backend and APIs | Server-side request API, no browser needed | Public APIs, partner endpoints, layer-7 floods |
| Your systems | Signed webhooks with retries | Stream assessments into your data warehouse, SIEM or case tools |
Where to place checks
Protect the actions where value changes hands. Each token is bound to the action it was issued for, so a token from one page cannot be replayed on another.
| Action | What Kavra catches there |
|---|---|
| Signup | Fake accounts, multi-accounting, SMS pumping |
| Login | Credential stuffing, account takeover |
| Bonus, promo or trial | Bonus abuse, free-trial abuse |
| Checkout | Payment fraud, card testing, scalping |
| Content and APIs | Web scraping, API abuse |
What your team needs
A few lines in your frontend
Add the script and pass the token with the protected request.
One backend call
Redeem the token with your project key and read the recommendation.
A policy
Choose a preset (cautious, balanced or strict) and decide what verify means for each action.
A contact on our side
Integration guides and support are provided to your team during onboarding.
Security and privacy of the integration
Tokens are signed, single-use and short-lived, and bound to the action they were issued for; replays are refused and reported. Browser evidence travels in an encrypted envelope on top of TLS. Each project has its own keys, and data is never shared across customers. The integration is consent-aware: pass your consent manager's answer at load time and Kavra applies the right legal basis per visitor region. More on the security page.