Documentation

Guides and reference for AgentGate: protect forms with an invisible browser check, validate tokens on your server, put a policy gateway in front of APIs, and give AI agents their own lane.

Overview

What AgentGate is, what it protects and how the pieces fit together.

Get started

Protect a form in three steps: create a site, embed the widget, validate the token.

Concepts

How the check decides, widget modes, tokens and clearances, monitor mode, signed agents and rules.

Browser widget

Every data-* attribute, the JavaScript API, callbacks, languages and Content Security Policy.

Server-side validation

Redeem every token with /v1/siteverify, handle errors, and retry safely.

Gateway

Check every request before it reaches your app: nginx auth_request or middleware.

Agents

For agent builders: sign requests, discover tools, handle prices and hand checks to a person.

Rules

The WAF-style rule language, managed rule groups and the threat intelligence rules can use.

Testing

Test site keys and secrets that always pass or fail, for end-to-end tests and CI.

Migration

Move from Turnstile, reCAPTCHA or hCaptcha: attributes, callbacks and server fields mapped.

Troubleshooting

Symptoms, causes and fixes, with every client and server error code.

Reference

Console and admin API, threat model and the changelog.

Legal

The early access terms of service, the acceptable use policy and the privacy notice.