Skip to main content
Before you start:
  • Import t.js from https://cdn.usefoil.com.
  • Use a publishable key (pk_*) in the browser and a secret key (sk_*) on your backend.
  • Keep the secret key server-side only.
  • The browser never receives Foil verdicts, scores, or visitor IDs.

1. Install the server SDK

2. Load the browser client

Start the client as early as possible on your page. Keep the returned promise for later use.

3. Get a session at action time

Right before signup, login, checkout, or another sensitive action, request a sealed handoff and send it to your backend. Add this function to the same <script type="module"> block as step 2. Each module script has its own scope, so a separate block can’t read foilPromise.

4. Verify on your backend

Verify the sealed token with your secret key. This is a local operation - no network call to Foil.
Verification confirms that the token is authentic and that your secret key can open it. It doesn’t check the token’s age or whether you have seen the token before. Before you enforce, add a freshness check as described in What verification doesn’t check.

5. Apply policy

Use the verdict to decide what to do: Start in report-only mode (log verdicts without blocking) to understand your traffic before enforcing.

What’s next

Browser SDK

Full SDK API reference

Server verification

Advanced verification patterns

Testing

Test your integration with bot traffic

Going to production

Rollout checklist and monitoring