Skip to main content
Heretic checks browser claims against connection measurements and browser tests. Each session returns a verdict with the findings that explain it. Your backend decides whether to allow the action, reject it, or request a phone challenge.

Collector

Add a script tag or npm package. Read the verdict and device identifiers from your server.

Challenge widget

Add verification to a form. The widget handles the browser check and any phone challenge; your server verifies the token.

Collector

Call heretic({ siteKey }) on your page, then send its request ID to your backend. Read the result at GET /v1/verdict/{request_id}. The response includes findings, the observed address, and available device identifiers. Signup rules shows how to compare them with your account records and bind a result to a signup attempt.

Challenge widget

Add a heretic-guard element to your form. In its default mode, the widget requests a phone challenge when the probe is contradicted or refused. Your server verifies the resulting token at POST /v1/siteverify. For a challenge you control from your backend, use the challenge API.

Get started

Create an account, or sign in if you already have one. The Developer Sandbox includes 1,000 probes and 1,000 challenges each month. Follow the quickstart to create a site, verify its domain, and run your first check.