Integrations

Live in minutes with one script and one API call

Kavra integrates with one script on your pages and one call from your backend. There is no DNS change and no traffic routing: your site stays where it is. Native iOS and Android SDKs cover mobile apps, a server-side API covers backend traffic, and webhooks stream every assessment into your own systems.

How integration works

  1. 01

    Add the script

    One script tag on the pages you want protected. It loads asynchronously, never blocks rendering and can run from your own first-party domain.

  2. 02

    Send the token with the action

    When a visitor signs up, logs in, claims a bonus or checks out, your page sends the short-lived Kavra token along with the request.

  3. 03

    Verify on your server

    One server-side call with your project key returns the assessment: classification, findings and a recommendation.

  4. 04

    Act with your own rules

    Allow, verify or block. Start in observe-only mode and switch to enforcement when you trust the results.

Supported platforms

PlatformHow it connectsTypical use
Websites and web appsJavaScript script plus one server-side verification callSignup, login, checkout, forms, promotions
iOS appsNative iOS SDK plus the same server-side callAccount creation, login, payments in the app
Android appsNative Android SDK plus the same server-side callReferral and bonus flows, emulator and device farm traffic
Backend and APIsServer-side request API, no browser neededPublic APIs, partner endpoints, layer-7 floods
Your systemsSigned webhooks with retriesStream assessments into your data warehouse, SIEM or case tools

Where to place checks

Protect the actions where value changes hands. Each token is bound to the action it was issued for, so a token from one page cannot be replayed on another.

What your team needs

  • A few lines in your frontend

    Add the script and pass the token with the protected request.

  • One backend call

    Redeem the token with your project key and read the recommendation.

  • A policy

    Choose a preset (cautious, balanced or strict) and decide what verify means for each action.

  • A contact on our side

    Integration guides and support are provided to your team during onboarding.

Security and privacy of the integration

Tokens are signed, single-use and short-lived, and bound to the action they were issued for; replays are refused and reported. Browser evidence travels in an encrypted envelope on top of TLS. Each project has its own keys, and data is never shared across customers. The integration is consent-aware: pass your consent manager's answer at load time and Kavra applies the right legal basis per visitor region. More on the security page.

FAQ

Frequently asked questions

Something else? Talk to our team.

Do I need to change my DNS or put Kavra in front of my site?

No. Kavra is not a proxy or CDN. Your traffic keeps its current path; you add a script and one server-side call.

Does the script slow my pages down?

No. It is under 64 KB, loads asynchronously and never blocks rendering. The assessment itself runs on Kavra's side.

Can I use my own domain for the script?

Yes. Each project has its own collector host, and a custom first-party domain is supported.

How do I get the integration guide?

Integration guides, keys and support are provided to your team during onboarding. Tell us about your stack through the contact form.

See who is really on your site.

Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.