ShieldLabs

Anonymous visitor identification and fraud-prevention platform. A browser ES-module snippet loaded from cdn.shieldlabs.ai collects 100+ device and network signals and returns six persistent identifiers (DeviceID, VisitorID, CookieID, SessionID, RequestID and a caller-supplied hashed UserHID) plus an explainable 0-100 Risk Score built from weighted anonymity signals — VPN, proxy, Tor, privacy relay, datacenter, IP reputation, anti-detect browser, geolocation spoofing, OS mismatch, incognito, browser automation and suspicious paid clicks. ShieldLabs deliberately makes no allow/challenge/block decision: it returns the score and the signals behind it, and the customer's own code owns the verdict. Delivery is a signed at-most-once webhook (identification.scored, HMAC-SHA256 in X-Shield-Signature, no retries), backed by two server-side REST surfaces — a free History API on account.shieldlabs.ai and a billed Management API on api.shieldlabs.ai — described by a public OpenAPI 3.1 specification the company maintains in its own MIT-licensed GitHub repo. Self-serve and per-identification priced, with a 5,000-identification free tier and no sales gate.

ShieldLabs publishes 1 API on the APIs.io network: Server API. Tagged areas include Fraud Detection, Abuse Prevention, Visitor Identification, Device Fingerprinting, and Bot Detection.

The ShieldLabs catalog on APIs.io includes 1 event-driven AsyncAPI specification.

ShieldLabs’ developer surface includes documentation, API reference, getting-started guide, support, engineering blog, pricing, signup flow, and 33 more developer resources.

68.5/100 exemplar Agent 49/100 agent native Full breakdown ↓
scored 2026-08-20 · rubric v0.12.0
1 APIs 1 MCP Servers
Fraud DetectionAbuse PreventionVisitor IdentificationDevice FingerprintingBot Detectionvpn-proxy-detectionRisk ScoringIdentitySecurityWebhookAnti-Fraudtraffic-quality

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-08-20 · rubric v0.12.0
Composite quality — 68.5/100 · exemplar
Contract Quality 18.7 / 25
Developer Ergonomics 15.7 / 20
Access Clarity 15.3 / 20
Operational Transparency 9.2 / 13
Contract Governance 2.0 / 12
Discoverability 7.6 / 10
Agent readiness — 49/100 · agent native
Machine-Readable Contract 18 / 18
Agentic Access Contract 0 / 10
Documented Reversibility 0 / 6
MCP Server 12 / 12
Machine-Readable Auth 10 / 10
Idempotency 9 / 9
Stable Error Semantics 8 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 6 / 6
Agent Skills 5 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 8 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/shieldlabs: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 1

Individual APIs this provider publishes, each with its own machine-readable definition.

ShieldLabs Server API

Server-side REST API described by a public OpenAPI 3.1 specification (three operations plus one OpenAPI-3.1 webhook). Two hosts, implemented by two different internal services a...

MCP Servers 1

Model Context Protocol servers that expose these APIs to AI agents.

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Shieldlabs Rate Limits

3 limits

RATE LIMITS

Event Specifications 1

AsyncAPI definitions for this provider's event-driven and streaming APIs.

JSON Schema 1

Standalone JSON Schema definitions for this provider's data models.

ShieldLabs webhook event

4 properties

JSON SCHEMA

Examples 1

Example request and response payloads for these APIs.

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Shieldlabs Authentication

http · 2 schemes

SECURITY

Shieldlabs Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Shieldlabs Vulnerability Disclosure

Hackerone · contact published

SECURITY

Resources

Get Started 5

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 4

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 7

Pagination, idempotency, versioning, errors, and events

Scroll for all 7

Build 5

SDKs, sample code, and the tooling you integrate with

Access & Security 4

Authentication, authorization, and security posture

Operate 4

Status, limits, changes, and where to get help

Commercial 4

Pricing, plans, and the legal terms of use

Company 4

The organization behind the API

Other 1

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: shieldlabs
name: ShieldLabs
description: 'Anonymous visitor identification and fraud-prevention platform. A browser ES-module snippet loaded from cdn.shieldlabs.ai
  collects 100+ device and network signals and returns six persistent identifiers (DeviceID, VisitorID, CookieID, SessionID,
  RequestID and a caller-supplied hashed UserHID) plus an explainable 0-100 Risk Score built from weighted anonymity signals
  — VPN, proxy, Tor, privacy relay, datacenter, IP reputation, anti-detect browser, geolocation spoofing, OS mismatch, incognito,
  browser automation and suspicious paid clicks. ShieldLabs deliberately makes no allow/challenge/block decision: it returns
  the score and the signals behind it, and the customer''s own code owns the verdict. Delivery is a signed at-most-once webhook
  (identification.scored, HMAC-SHA256 in X-Shield-Signature, no retries), backed by two server-side REST surfaces — a free
  History API on account.shieldlabs.ai and a billed Management API on api.shieldlabs.ai — described by a public OpenAPI 3.1
  specification the company maintains in its own MIT-licensed GitHub repo. Self-serve and per-identification priced, with
  a 5,000-identification free tier and no sales gate.'
image: https://shieldlabs.ai/og/home.png
url: https://shieldlabs.apievangelist.com/apis.yml
created: '2026-08-19'
modified: '2026-08-19'
specificationVersion: '0.21'
tags:
- Fraud Detection
- Abuse Prevention
- Visitor Identification
- Device Fingerprinting
- Bot Detection
- vpn-proxy-detection
- Risk Scoring
- Identity
- Security
- Webhook
- Anti-Fraud
- traffic-quality
tags_raw:
- fraud-detection
- abuse-prevention
- visitor-identification
- device-fingerprinting
- bot-detection
- vpn-proxy-detection
- risk-scoring
- identity
- security
- webhooks
- anti-fraud
- traffic-quality
apis:
- name: ShieldLabs Server API
  description: 'Server-side REST API described by a public OpenAPI 3.1 specification (three operations plus one OpenAPI-3.1
    webhook). Two hosts, implemented by two different internal services and diverging in casing, envelope, auth headers, billing
    and rate limiting: the History API on https://account.shieldlabs.ai/api (Private API Key, `Authorization: Bearer sec_…`,
    snake_case, `{data,total}` envelope with limit/offset, free — does not consume request balance) and the Management API
    on https://api.shieldlabs.ai (Secret Key plus an `X-Shield-Domain` header, PascalCase bare arrays, bills one request per
    returned row with a minimum of one). The primary delivery path is outbound: a signed identification.scored webhook carrying
    the Risk Score, the weighted signals, 18 detection flags and traffic-source attribution, delivered at most once with no
    retries and recovered through a free History read on request_id.'
  humanURL: https://docs.shieldlabs.ai/api/overview
  baseURL: https://api.shieldlabs.ai
  tags:
  - Fraud Detection
  - Abuse Prevention
  - Visitor Identification
  - Device Fingerprinting
  - Bot Detection
  - vpn-proxy-detection
  - Risk Scoring
  - Identity
  - Security
  - Webhook
  tags_raw:
  - fraud-detection
  - abuse-prevention
  - visitor-identification
  - device-fingerprinting
  - bot-detection
  - vpn-proxy-detection
  - risk-scoring
  - identity
  - security
  - webhooks
  properties:
  - type: OpenAPI
    url: openapi/shieldlabs-server-api-openapi.yml
  - type: OpenAPI
    url: https://docs.shieldlabs.ai/references/openapi.yaml
  - type: JSONSchema
    url: json-schema/shieldlabs-identification-scored.schema.json
  - type: Examples
    url: examples/shieldlabs-identification-scored-example.json
  - type: Overlay
    url: overlays/shieldlabs-server-api-overlay.yaml
  - type: Documentation
    url: https://docs.shieldlabs.ai/api/overview
  - type: Documentation
    url: https://docs.shieldlabs.ai/api/server-api
  - type: Documentation
    url: https://docs.shieldlabs.ai/api/webhooks
  - type: APIReference
    url: https://docs.shieldlabs.ai/api/server-api
  - type: DataModel
    url: data-model/shieldlabs-data-model.yml
  - type: ToolCrosswalk
    url: mcp/shieldlabs-tool-crosswalk.yml
  - type: LLMsTxt
    url: https://shieldlabs.ai/llms.txt
  - type: LLMsTxt
    url: https://docs.shieldlabs.ai/llms.txt
maintainers:
- FN: ShieldLabs
  url: https://shieldlabs.ai
  email: contact@shieldlabs.ai
generated:
  by: apis.io/add
  model: claude-opus-4-8
  confidence: 90
  at: '2026-08-19T16:02:26.724Z'
common:
- type: DeveloperPortal
  url: https://docs.shieldlabs.ai/
- type: Documentation
  url: https://docs.shieldlabs.ai/
- type: APIReference
  url: https://docs.shieldlabs.ai/api/server-api
- type: GettingStarted
  url: https://docs.shieldlabs.ai/quickstart
- type: Support
  url: https://docs.shieldlabs.ai/support
- type: Blog
  url: https://shieldlabs.ai/blog
- type: BlogRSS
  url: https://shieldlabs.ai/rss.xml
- type: GitHubOrganization
  url: https://github.com/ShieldLabs-ai
- type: SourceCode
  url: https://github.com/ShieldLabs-ai/shieldlabs-openapi
- type: Pricing
  url: https://shieldlabs.ai/pricing
- type: SignUp
  url: https://app.shieldlabs.ai/signup
- type: Login
  url: https://app.shieldlabs.ai/login
- type: TermsOfService
  url: https://docs.shieldlabs.ai/legal/terms
- type: PrivacyPolicy
  url: https://docs.shieldlabs.ai/legal/privacy-policy
- type: Twitter
  url: https://x.com/Shieldlabs_ai
- type: LinkedIn
  url: https://www.linkedin.com/company/shieldlabs-ai
- type: Authentication
  url: authentication/shieldlabs-authentication.yml
- type: Conventions
  url: conventions/shieldlabs-conventions.yml
- type: Idempotency
  url: conventions/shieldlabs-conventions.yml
- type: ErrorCatalog
  url: errors/shieldlabs-problem-types.yml
- type: RateLimits
  url: rate-limits/shieldlabs-rate-limits.yml
- type: Plans
  url: plans/shieldlabs-plans-pricing.yml
- type: Lifecycle
  url: lifecycle/shieldlabs-lifecycle.yml
- type: ChangeLog
  url: changelog/shieldlabs-changelog.yml
- type: ChangeLog
  url: https://docs.shieldlabs.ai/changelog
- type: Webhooks
  url: asyncapi/shieldlabs-webhooks.yml
- type: Sandbox
  url: sandbox/shieldlabs-sandbox.yml
- type: Components
  url: components/shieldlabs-components.yml
- type: Packages
  url: packages/shieldlabs-packages.yml
- type: SDKs
  url: packages/shieldlabs-packages.yml
- type: Conformance
  url: conformance/shieldlabs-conformance.yml
- type: Security
  url: https://docs.shieldlabs.ai/security
- type: VulnerabilityDisclosure
  url: security/shieldlabs-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/shieldlabs-domain-security.yml
- type: WellKnown
  url: well-known/shieldlabs-well-known.yml
- type: MCPServer
  url: mcp/shieldlabs-mcp.yml
- type: ToolCrosswalk
  url: mcp/shieldlabs-tool-crosswalk.yml
- type: AgentCard
  url: a2a/shieldlabs-a2a.yml
- type: AgentSkill
  url: skills/_index.yml
- type: LLMsTxt
  url: llms/shieldlabs-llms.txt
x-enrichment:
  date: '2026-08-19'
  status: enriched
  artifacts_added: 31
  pass: local-v1
x-evidence:
  round: '2026-08-19'
  admitted_from: Add-API gate auto-publish, submission shieldlabs-b6a2bad8 at 16:05:29 UTC, confidence 90. A FIRST attempt
    11 minutes earlier (shieldlabs-d19973c6, 15:54:05) carried the bare name with no URL, so the gate had nothing to research
    and parked it at confidence 2. That record was dropped as superseded, not as a rejection.
  slug: No rename needed — shieldlabs.ai already yields shieldlabs under the domain rule.
  host_health: shieldlabs.ai 200 / invented path 404. docs.shieldlabs.ai 200 / 404. api.shieldlabs.ai 404 on both, an API
    host with no root route. Checked with BOTH a default and a browser user-agent and the bytes are identical — unlike two
    providers profiled earlier today, ShieldLabs filters nobody.
  found_by_pipeline_not_by_my_probes: "My contract-discovery probes MISSED both of the following, and the enrichment pipeline\
    \ found them. Recorded because the probe list is what was wrong, not the provider.\n  OpenAPI  https://docs.shieldlabs.ai/references/openapi.yaml\
    \ — 200 text/yaml 18,115b, valid OpenAPI 3.1.0, \"ShieldLabs API\" v1.2, 3 paths, servers account.shieldlabs.ai/api and\
    \ api.shieldlabs.ai. I had probed /openapi.json and /openapi.yaml at the docs ROOT only.\n  MCP      https://docs.shieldlabs.ai/mcp\
    \ with a descriptor at /.well-known/mcp.json. An anonymous tools/list returns real tools over SSE. I had probed /_mcp/server,\
    \ the Mintlify path seen on another provider, and not /mcp."
  mcp_scope_note: The MCP server is REAL and unauthenticated, and it is a DOCUMENTATION server emitted by the Mintlify docs
    platform — not a ShieldLabs Server API server. Its tools search and read the docs corpus; none call the History or Management
    API, none identify a visitor, none return a Risk Score. An agent can learn how to integrate ShieldLabs through MCP but
    cannot transact with it. Recorded so the MCPServer pointer is not read as a transactional agent surface.
  two_llms_txt: Both shieldlabs.ai/llms.txt (9,660b) and docs.shieldlabs.ai/llms.txt (12,291b) are real text/plain. The submission
    recorded only the apex one.