Crytify is a bot detection API. Send it a visitor's IP and
headers (and optionally a browser fingerprint), get back ALLOW / CHALLENGE /
BLOCK before you render a single byte of your page.
This repo has copy-pasteable integration examples for PHP and Node.js. It is not the API source or the detection engine — just the client-side glue code to call it from your own app.
- Sign up (free): https://crytify.com/register — 1,000 API calls/day, no card required
- Full docs: https://crytify.com/docs
- Dashboard: https://dashboard.crytify.com
No install, no dependencies. Download the file straight from Crytify (always the current version — nothing in this repo goes stale) and add two lines to the top of any page you want protected:
PHP
curl -o crytify.php https://crytify.com/download/crytify.phprequire_once __DIR__ . '/crytify.php';
crytify_gate('cry_live_xxxxxxxxxxxx');Python (Flask / Django / FastAPI)
curl -o crytify.py https://crytify.com/download/crytify.pyfrom crytify import crytify_gate
@app.route('/login')
@crytify_gate('cry_live_xxxxxxxxxxxx')
def login():
...Node.js (Express / any http framework)
curl -o crytify.js https://crytify.com/download/crytify.jsconst { crytifyGate } = require('./crytify');
app.use('/login', crytifyGate('cry_live_xxxxxxxxxxxx'));Get your API key at crytify.com/register — a default key is created automatically when you sign up.
If you'd rather call the API yourself (custom middleware, a non-PHP/Node
framework, more control over the request), use php/CrytifyClient.php
directly:
require 'CrytifyClient.php';
$crytify = new CrytifyClient('cry_live_xxxxxxxxxxxx');
$result = $crytify->trust($_SERVER['REMOTE_ADDR'], getallheaders());
if ($result->isBlock()) {
http_response_code(403);
exit('Access denied.');
}
if ($result->isChallenge()) {
header('Location: ' . $result->challengeUrl());
exit;
}
// Visitor passed — render your page normallyMore complete examples in this repo:
| File | What it shows |
|---|---|
php/examples/server-side-gate.php |
Plain PHP page-top gate |
php/examples/page-protection.php |
Backend endpoint for the client-side fingerprint check |
php/examples/CrytifyGateFilter.php |
CodeIgniter 4 filter |
node/examples/express.js |
Express middleware, per-route |
node/examples/nextjs-middleware.mjs |
Next.js Edge Middleware |
For visitors that do run JavaScript but are driven by automation tooling (headless browsers, bot frameworks), add the fingerprint collector — it's served pre-built, no build step on your end:
<script src="https://crytify.com/assets/crytify-fingerprint.js"></script>See crytify.com/docs for the full client-side setup guide.
Crytify combines network intelligence (hosting/proxy/VPN/Tor detection, ASN reputation), device/browser fingerprint consistency checks, and its own self-learning threat database (every block/challenge across all Crytify customers improves detection for everyone) to return a decision in ~150ms. See crytify.com/docs for the full request/response shape and all available options.
The example code in this repo is MIT-licensed — use it however you like. The Crytify API itself is a commercial service; see crytify.com for pricing.