Home
Aetherisz+ · Developers

Stop bots. Let people through.

Aetherisz+ is our own human-verification and abuse-protection layer. Add it to any website or app in a few lines — no account needed to read these docs, keys take a minute once you sign in.

1 · Visitor interacts

The widget asks the visitor to slide to verify. Only aggregate motion statistics leave the browser — never cursor coordinates, keystrokes or personal data.

2 · Aetherisz+ decides

Our servers score the interaction, run a single-use proof-of-work challenge and produce a short-lived verification token valid for 30 seconds.

3 · Your backend confirms

Your server posts that token to the verify API with your secret key. Tokens are burned on first use, so a replayed token is always rejected.

This is what your visitors see

A live widget — try it. The name on the right becomes your own key name; the privacy and terms links stay with Aetherisz+.

I'm not a robot
Slide to verify
Your AppPrivacy · Terms

Protected by Aetherisz+

Slide the handle to try it.

1 · Render the widget (React)
import { HumanCheck } from "@aetherisz/react";

<HumanCheck
  siteKey="az-site-xxxxxxxx"
  brandName="Your App"
  onVerified={(token) => setToken(token)}
/>
2 · Verify on your server
const res = await fetch("https://aetherisz.in/api/v1/aetherisz/verify", {
  method: "POST",
  headers: {
    "Content-Type": "application/json",
    "X-Aetheris-Secret-Key": process.env.AETHERISZ_SECRET_KEY,
  },
  body: JSON.stringify({ token, client_ip: req.ip }),
});

const result = await res.json();
// { success: true, score: 85, action: "allow" }
if (!result.success) return res.status(403).json({ error: result.reason });

Responses & error codes

ReasonStatusWhat it means
token_expired_or_reused200Token was already used or older than 30 seconds — reject the request.
missing_token400No token in the body.
invalid_key401Secret key is wrong or revoked.
quota_exhausted402Free allowance used up — add credit to continue.
rate_limited429Too many checks per minute. Retry after the Retry-After header.
unavailable503Security service unreachable. Aetherisz+ fails closed — deny the request.

Quotas you can see

Every response carries X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset, so your app always knows where it stands.

Fails closed

If the security service is unreachable you get 503 — never a silent allow. Attackers cannot win by taking the checker offline.

Privacy by design

No cursor paths, no keystrokes, no fingerprints sold on. Only aggregate signals, kept for a short retention window.

Ready to protect your app?

Sign in to create keys and watch every verification — passed, rejected and why — in your console.

Create free keys