# ShieldLabs

**Canonical:** https://apis.io/providers/shieldlabs/  
**Website:** https://docs.shieldlabs.ai/  
**APIs profiled:** 1

Anonymous visitor identification and fraud-prevention platform. A browser ES-module snippet loaded from cdn.shieldlabs.ai collects 100+ device and network signals and returns six persistent identifiers (DeviceID, VisitorID, CookieID, SessionID, RequestID and a caller-supplied hashed UserHID) plus an explainable 0-100 Risk Score built from weighted anonymity signals — VPN, proxy, Tor, privacy relay, datacenter, IP reputation, anti-detect browser, geolocation spoofing, OS mismatch, incognito, browser automation and suspicious paid clicks. ShieldLabs deliberately makes no allow/challenge/block decision: it returns the score and the signals behind it, and the customer's own code owns the verdict. Delivery is a signed at-most-once webhook (identification.scored, HMAC-SHA256 in X-Shield-Signature, no retries), backed by two server-side REST surfaces — a free History API on account.shieldlabs.ai and a billed Management API on api.shieldlabs.ai — described by a public OpenAPI 3.1 specification the company maintains in its own MIT-licensed GitHub repo. Self-serve and per-identification priced, with a 5,000-identification free tier and no sales gate.

## Kin Score — 68.5 / 100 (exemplar)

Scored 2026-08-20 under rubric 0.12.0.

| Facet | Score |
|---|---|
| Discoverability | 75.9 |
| Contract Quality | 74.8 |
| Governance | 16.7 |
| Contract Governance | 16.7 |
| Operational Transparency | 71.1 |
| Developer Ergonomics | 78.6 |
| Commercial Clarity | 76.3 |
| Access Clarity | 76.3 |

## Agent readiness — 49.4 (agent-native)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | documented |
| Auth Clarity | yes |
| Idempotency | documented |
| Error Semantics | documented |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | yes |
| Agent Skills | yes |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | flavored |
| Dry Run Mode | no |

## APIs (1)

- **ShieldLabs Server API** — Server-side REST API described by a public OpenAPI 3.1 specification (three operations plus one OpenAPI-3.1 webhook). Two hosts, implemented by two different internal services a...

## MCP servers (1)

- **ShieldLabs MCP Server**

## Security (3)

- **Shieldlabs Authentication** — http · 2 schemes
- **Shieldlabs Domain Security** — TLSv1.3 · HSTS · DMARC
- **Shieldlabs Vulnerability Disclosure** — Hackerone · contact published

## Plans (1)

- **Shieldlabs Plans Pricing**

## Tags

Fraud Detection, Abuse Prevention, Visitor Identification, Device Fingerprinting, Bot Detection, vpn-proxy-detection, Risk Scoring, Identity, Security, Webhook, Anti-Fraud, traffic-quality

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/shieldlabs/). Scores are computed from the provider's own public artifacts under a published rubric.
