Public beta · the BotShield app is live on the web.
Console

A live human behind every account. Never who.

You have never been able to vouch for the accounts on your platform without collecting more about the people behind them. Now you can: trust your customers can see, and a yes you can prove.

How to require a person’s yes  →

console.botshield.ai/ticketz/trusted-accounts
The Trusted Accounts registry in the BotShield Console — each row carries your own account ref, one opaque handle, the day they secured it, and the state
Verify the customer · never the identity

One attribute. One tap. Nothing about your login changes.

01

Put the offer on your login.

One attribute. Password, Google, or a passkey — nothing else changes. Sign-up, settings, or the first time their agent asks.

02

They tap once.

A passkey fires — a WebAuthn assertion with user verification, on BotShield’s relying party — in their browser or on their phone. That is the whole ceremony. No OAuth, no redirect, no identity provider in the loop.

03

You get the fact.

Trusted, keyed to your own account id. Never a name, never an email.

04

You set the rules.

A post, a listing, a payout — any act can require a live human first, and the same ID answers every time.

Trusted Accounts in the BotShield app — the accounts this person has linked to their BotShield ID, each with an Unlink control

WHAT THEY SEE

Checks and balances.

Their login proves the account at the door. BotShield proves a person at the moment it matters — and the proof travels.

The door

They sign in as they always have.

Proves the account is held — a password known, or a passkey unlocked. After the door, the session carries it, whatever holds it.

Sign in / a password or a passkey
Sign in with a password Sign in with a passkey
The moment

A live human behind the account. Never who.

One tap. BotShield notarizes that a person was there — the same ID that secured the account, every time it matters. You get a fact you can check, keyed to your own account id.

✓ Signed in · ref 4a91-7c2e
Link BotShield ID — tap to secure this account
By construction

Every account carries a root. Every consequential act takes a person.

One BotShield ID secures one account on your platform. Each ID stands on its own signed-in Apple or Google account, and every act you gate takes a live tap with that ID’s passkey. We don’t promise a farm can’t be built. We make every account in it carry a root, and every act you gate cost a person.

One ID, one account.

A second attempt with the same ID is refused. An index, not a policy.

Every account carries a root.

Its own signed-in Apple or Google account behind it. You never learn which.

Every act you gate takes a person.

A live tap, every time you ask. A farm has to staff it.

A passkey behind every account.

Every BotShield ID is a passkey. Every secured account has one behind it — even where the login is still a password.

Common questions

Trusted Accounts FAQ

Does a Trusted Account replace my login?
No. Your sign-in stays exactly as it is. The offer sits on top of it: your user taps Link BotShield ID, a passkey fires in their browser or on their phone, and BotShield notarizes the relationship between the account and their BotShield ID. You keep your identity provider. You gain a fact about the account.
Do I need a BotShield Gate to use Trusted Accounts?
Not for the Trusted Account. A Trusted Account belongs to your organization, never to a gate: a Gate pass never creates one and never changes one. The Gate stays what it is, a check at a moment. Trusted Accounts is a registry that stands on its own.
What do I receive when a user secures their account?
One fact you can check: a live human is behind this account. In your registry the row carries your own reference to the account, one opaque handle made for your platform, the day they secured it, and its state, Trusted or Unlinked. Never a name, an email, a device, or anything from another platform.
What is the platform-user-ref, and what should I send?
Your own stable internal id for the account, the one your system already keys on. Never an email, never anything the user can change. BotShield keeps only a keyed hash of it, so the row is joinable to nothing outside your platform. Send it only from a page behind your own fresh sign-in.
Can one person secure two accounts on my platform?
Not with the same BotShield ID. One ID secures one account per platform, and a second attempt is refused. A second ID needs its own signed-in Apple or Google account behind it, and every gated act on that second account takes a live tap too. We don’t claim that can’t be done. We make every account carry a root, and every act you gate take a person.
What happens when someone unlinks, or when a password or email changes?
The row flips to Unlinked and your webhook is told. The person can unlink from the app at any time, and you can revoke from the Console. If their primary credential on your platform changes, report it and the notarized relationship is revoked, so a takeover never inherits a trusted state. The next time they reach the offer, they can secure it again.

Verify your customers. Never their identities.

We prove a person is behind the account. On demand.