# Live in minutes with one script and one API call

Source: https://kavralab.com/integrations/

**Kavra** integrates with one script on your pages and one call from your backend. There is no DNS change and no traffic routing: your site stays where it is. Native iOS and Android SDKs cover mobile apps, a server-side API covers backend traffic, and webhooks stream every assessment into your own systems.

## How integration works

1. **Add the script**: One script tag on the pages you want protected. It loads asynchronously, never blocks rendering and can run from your own first-party domain.
2. **Send the token with the action**: When a visitor signs up, logs in, claims a bonus or checks out, your page sends the short-lived Kavra token along with the request.
3. **Verify on your server**: One server-side call with your project key returns the assessment: classification, findings and a recommendation.
4. **Act with your own rules**: Allow, verify or block. Start in observe-only mode and switch to enforcement when you trust the results.

## Supported platforms

| Platform | How it connects | Typical use |
|---|---|---|
| Websites and web apps | JavaScript script plus one server-side verification call | Signup, login, checkout, forms, promotions |
| iOS apps | Native iOS SDK plus the same server-side call | Account creation, login, payments in the app |
| Android apps | Native Android SDK plus the same server-side call | Referral and bonus flows, emulator and device farm traffic |
| Backend and APIs | Server-side request API, no browser needed | Public APIs, partner endpoints, layer-7 floods |
| Your systems | Signed webhooks with retries | Stream assessments into your data warehouse, SIEM or case tools |

## Where to place checks

Protect the actions where value changes hands. Each token is bound to the action it was issued for, so a token from one page cannot be replayed on another.

| Action | What Kavra catches there |
|---|---|
| Signup | [Fake accounts](https://kavralab.com/solutions/fake-accounts/), [multi-accounting](https://kavralab.com/solutions/multi-accounting/), [SMS pumping](https://kavralab.com/solutions/sms-pumping/) |
| Login | [Credential stuffing](https://kavralab.com/solutions/credential-stuffing/), [account takeover](https://kavralab.com/solutions/account-takeover/) |
| Bonus, promo or trial | [Bonus abuse](https://kavralab.com/solutions/bonus-abuse/), [free-trial abuse](https://kavralab.com/solutions/free-trial-abuse/) |
| Checkout | [Payment fraud](https://kavralab.com/solutions/payment-fraud/), [card testing](https://kavralab.com/solutions/card-testing/), [scalping](https://kavralab.com/solutions/scalping/) |
| Content and APIs | [Web scraping](https://kavralab.com/solutions/web-scraping/), [API abuse](https://kavralab.com/solutions/api-abuse/) |

## What your team needs

- **A few lines in your frontend**: Add the script and pass the token with the protected request.
- **One backend call**: Redeem the token with your project key and read the recommendation.
- **A policy**: Choose a preset (cautious, balanced or strict) and decide what verify means for each action.
- **A contact on our side**: Integration guides and support are provided to your team during onboarding.

## Security and privacy of the integration

Tokens are signed, single-use and short-lived, and bound to the action they were issued for; replays are refused and reported. Browser evidence travels in an encrypted envelope on top of TLS. Each project has its own keys, and data is never shared across customers. The integration is consent-aware: pass your consent manager's answer at load time and Kavra applies the right legal basis per visitor region. More on the [security page](https://kavralab.com/security/).

## FAQ

### Do I need to change my DNS or put Kavra in front of my site?

No. Kavra is not a proxy or CDN. Your traffic keeps its current path; you add a script and one server-side call.

### Does the script slow my pages down?

No. It is under 64 KB, loads asynchronously and never blocks rendering. The assessment itself runs on Kavra's side.

### Can I use my own domain for the script?

Yes. Each project has its own collector host, and a custom first-party domain is supported.

### How do I get the integration guide?

Integration guides, keys and support are provided to your team during onboarding. Tell us about your stack through the contact form.

---
Kavra Lab: bot and fraud detection that explains every decision. Book a demo: https://kavralab.com/contact/
