Aetherisz+ is our own human-verification and abuse-protection layer. Add it to any website or app in a few lines — no account needed to read these docs, keys take a minute once you sign in.
The widget asks the visitor to slide to verify. Only aggregate motion statistics leave the browser — never cursor coordinates, keystrokes or personal data.
Our servers score the interaction, run a single-use proof-of-work challenge and produce a short-lived verification token valid for 30 seconds.
Your server posts that token to the verify API with your secret key. Tokens are burned on first use, so a replayed token is always rejected.
A live widget — try it. The name on the right becomes your own key name; the privacy and terms links stay with Aetherisz+.
Slide the handle to try it.
import { HumanCheck } from "@aetherisz/react";
<HumanCheck
siteKey="az-site-xxxxxxxx"
brandName="Your App"
onVerified={(token) => setToken(token)}
/>const res = await fetch("https://aetherisz.in/api/v1/aetherisz/verify", {
method: "POST",
headers: {
"Content-Type": "application/json",
"X-Aetheris-Secret-Key": process.env.AETHERISZ_SECRET_KEY,
},
body: JSON.stringify({ token, client_ip: req.ip }),
});
const result = await res.json();
// { success: true, score: 85, action: "allow" }
if (!result.success) return res.status(403).json({ error: result.reason });| Reason | Status | What it means |
|---|---|---|
| token_expired_or_reused | 200 | Token was already used or older than 30 seconds — reject the request. |
| missing_token | 400 | No token in the body. |
| invalid_key | 401 | Secret key is wrong or revoked. |
| quota_exhausted | 402 | Free allowance used up — add credit to continue. |
| rate_limited | 429 | Too many checks per minute. Retry after the Retry-After header. |
| unavailable | 503 | Security service unreachable. Aetherisz+ fails closed — deny the request. |
Every response carries X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset, so your app always knows where it stands.
If the security service is unreachable you get 503 — never a silent allow. Attackers cannot win by taking the checker offline.
No cursor paths, no keystrokes, no fingerprints sold on. Only aggregate signals, kept for a short retention window.
Sign in to create keys and watch every verification — passed, rejected and why — in your console.
Create free keys