// crytify — request trust engine for developers
Decide
before
you render.
One call before your page renders. Crytify returns allow, challenge, or block — bots never see protected content.
1,000 free credits/day · no credit card
decisions
One API call, three possible outcomes. You act on the string, Crytify carries the reasoning.
// deploy at the paths attackers actually hit
works with: PHP · Next.js · Express · Laravel · CodeIgniter · WordPress · custom APIs
api
the core endpoint — evaluates all 27 detectors, returns the verdict
geo, ASN, org, network type — use the signal however you want
GET /v1/usage & /v1/me — free, no credits consumed
protection_modes
Match strictness to the sensitivity of the page — per request, not per site.
| easy | medium · default | hard | |
|---|---|---|---|
| cost | 2 credits | 4 credits | 8 credits |
| posture | low friction — never challenges, only blocks obvious threats | balanced — challenges suspicious, blocks confirmed threats | strict — challenges by default, only high-trust passes freely |
| challenge page | — | ✓ | ✓ |
| best for | content pages, marketing | dashboards, accounts, forms | login, admin, checkout, APIs |
self_learning
Failed challenges, confirmed automation, and abusive fingerprints feed a shared reputation network. An attacker burned on one protected site arrives pre-flagged at every other one.
It compounds: every request makes the next decision sharper.
pricing
Credits represent compute — deeper checks cost more. Every plan gets every feature; plans only change volume.
// ship it before the next bot wave
Decide before you render.
1,000 free credits/day · no credit card · no commitment