@vyltr/sdk
v1.0.0
Published
Vyltr anti-bot SDK for Node.js — server-side bot detection without CAPTCHA
Maintainers
Readme
@vyltr/sdk
Server-side bot detection for Node.js — no CAPTCHA, no friction, GDPR compliant.
Vyltr detects bots using behavioral signals (mouse, scroll, timing) and server-side signals (IP reputation, User-Agent, TLS). < 1ms added latency.
Install
npm install @vyltr/sdkQuick Start
const createVyltr = require('@vyltr/sdk');
const vyltr = createVyltr('YOUR_SDK_KEY');Express Middleware
const express = require('express');
const createVyltr = require('@vyltr/sdk');
const app = express();
const vyltr = createVyltr('YOUR_SDK_KEY');
// Apply globally
app.use(vyltr.middleware());
// Or on a specific route
app.post('/login', vyltr.middleware(), (req, res) => {
console.log('Bot score:', req.vyltr.bot_score);
res.json({ ok: true });
});Next.js Middleware
// middleware.ts
import { NextRequest, NextResponse } from 'next/server';
import createVyltr from '@vyltr/sdk';
const vyltr = createVyltr(process.env.VYLTR_SDK_KEY!);
export async function middleware(request: NextRequest) {
const { blocked, result } = await vyltr.checkNextRequest(request);
if (blocked) {
return new NextResponse(JSON.stringify({ error: 'Access denied' }), { status: 403 });
}
const response = NextResponse.next();
response.headers.set('X-Bot-Score', String(result.bot_score));
return response;
}
export const config = { matcher: ['/api/:path*', '/login', '/register'] };Manual Verify
const result = await vyltr.verify({
ip: req.ip,
userAgent: req.headers['user-agent'],
pageUrl: req.url,
});
if (result.action === 'block') {
return res.status(403).json({ error: 'Bot detected' });
}IP Reputation Check
const info = await vyltr.checkIp('1.2.3.4');
// { risk_score: 85, risk_level: 'high', is_tor: true, country: 'FR', isp: '...' }Options
| Option | Default | Description |
|--------|---------|-------------|
| apiUrl | https://vyltr.ai/api/v1 | Custom API endpoint |
| timeout | 3000 | Request timeout (ms) |
| threshold | 65 | Bot score threshold for blocking |
| dryRun | false | Detect but never block |
Response Object
{
bot_score: number; // 0–100 (100 = certain bot)
is_bot: boolean;
action: 'allow' | 'challenge' | 'block';
bot_reasons: string[]; // Human-readable detection reasons
bot_type: string | null; // 'scraper' | 'credential_stuffing' | 'headless_browser' | ...
}GDPR
Vyltr is hosted in France 🇫🇷, processes no personal data, and is GDPR-compliant by design.
Privacy Policy
Get your free API key at vyltr.ai — free up to 10,000 requests/month.
