Features

Detected out of the box, protected at the source.

No advertising or resale: technical signals are limited to security, pseudonymised and configurable per site.

Machine recognition

Signals from the device

Shugoi compares technical signals to help your application recognise a previously seen environment. A changed IP, VPN or browser can reduce the match.

Cross-browser comparison

Comparable signals can be combined across browsers, with measurable differences depending on the environment and privacy settings.

même machine reconnue d'un navigateur à l'autre

Out-of-the-box detection

Tor

Tor network signals can feed your decision rule and challenge policy.

Automated browsers

Common automation signals (Playwright, Puppeteer…) can trigger your rule; no detection is infallible.

signaux webdriver & profils headless connus

Virtualised environments

Some virtualisation indicators can contribute to a decision, depending on the browser and operating system.

Modified browsers

Known profiles and inconsistencies can be flagged, without promising complete coverage of anti-detect tools.

Abusive accounts

Server rules, quotas and technical signals help limit repeated signups; they complement your account controls.

Protection

Browser-side verification

The flow can require JavaScript and proof of work; clients without a browser are handled according to your rule.

preuve de travail SHA-256 · difficulté adaptative

Per-machine allowlist

Allow your trusted machines and block the rest, or the reverse, depending on your phase.

identifiant pseudonyme stable cross-browser

Anti-scraping rate limit

Challenge and verification endpoints are IP-bounded to stop resource exhaustion.

bornes par IP · challenge 307 · SSE borné

Protected content

Protected pages use a short-lived signed grant and a private cache policy.

render-grant HMAC · TTL court · no-store

Resistant to extensions

Extensions that spoof the screen or browser are detected: critical measurements run in an isolated context and the integrity of their output is verified.

descripteurs instance & prototype · worker isolé · checksum de sortie

Signed render authorisation

For a protected page, Shugoi signs a short-lived authorisation tied to the site, the Machine ID and the page. The server rejects the render if a value does not match or the authorisation has expired.

grant signé · site + machine + page · durée courte

Re-obfuscated on every visit

The verification script changes shape on every request (reordered code, unreadable encoding): what is bypassed for one visitor does not apply to the next. ~500 ms in the background, invisible to your users.

rotation seedée · encodage opaque · variants par requête

SEO preserved

Verified bots (Googlebot, Bingbot…) receive the original page: filtering does not sacrifice your SEO.

split-render SSR · allowlist bots stricte (UA + IP)

No advertising cookie

Cookies used by Shugoi support security challenges and short-lived authorisations. Technical identifiers remain pseudonymised.

aucune revente · finalité sécurité uniquement

Operations

Real-time analytics

Blocks by reason, passes and trends, in real time from the dashboard.

Information notice

A notice explains processing and rights without presenting continuation as consent.

Multi-framework

Express and Fastify have verified Node integrations. Next.js, PHP and Laravel examples present complementary integration paths.

npm · intégrations Node vérifiées · autres adaptateurs disponibles

Server-side integration

Bind the Machine ID to the session token

At sign-in, your backend can store the Machine ID with the session token. On each request, it can compare the received Machine ID with the stored value and reject the token if they differ.

Add this binding to your site's authentication. Shugoi SDKs do not enable it automatically and cannot prevent a cookie from being stolen in the first place.

Ready to try it?

Private beta under allowlist: Starter is free for new accounts.