Origin restrictions
Site keys are limited to approved hostnames and supported wildcard subdomains.
Verinexa combines short-lived challenges, origin and action binding, single-use response tokens, risk controls, workspace isolation, and private server verification.
Client-side completion alone is never treated as permission to continue a protected action.
Site keys are limited to approved hostnames and supported wildcard subdomains.
Challenge and response lifetimes are configurable and enforced by the server.
Responses can be checked against the intended registration, login, contact, checkout, or API action.
Consumed tokens cannot be replayed for another request or business action.
Per-site thresholds, challenge policies, retries, quotas, and issuance limits reduce abuse.
Customer sites, logs, credentials, usage, and custom visual libraries are scoped to their workspace.
Verinexa records the configuration and operational signals required to issue challenges, validate responses, investigate errors, enforce quotas, and provide account security.
Verinexa reduces automated abuse, but it should be combined with secure authentication, authorization, validation, rate limiting, monitoring, fraud controls, and safe business logic.
Report suspected vulnerabilities privately through the security contact defined for the deployment. Do not include production secrets, customer data, or destructive proof-of-concept activity.
This action may affect your integration.