Checkpoint Docs

Welcome

Checkpoint protects your applications from AI agents and automated bots

Checkpoint is a comprehensive AI agent detection and protection platform. It identifies and manages automated traffic on your web applications with enterprise-grade detection, flexible enforcement, and identity-based governance for AI agents.

Why Checkpoint?

  • Advanced AI Detection — State-of-the-art algorithms to identify AI agents, bots, and automated browsers
  • Flexible Enforcement — Permit, block, redirect, challenge for consent, or require cryptographic identity (INSTRUCT) — you decide how to handle detected agents
  • Identity Governance — Control what AI agents can access using KYA-OS (Know Your Agent, Operating System), the open identity protocol that Govern implements; see the Glossary
  • Real-time Analytics — Monitor traffic patterns, detection trends, and agent activity
  • Privacy First — GDPR compliant with configurable privacy settings

Platform Overview

See Core Concepts for the mental model behind these three pillars — how detection, enforcement, and identity fit together.

Detect

Identify AI agents and bots using client-side or server-side signals. Checkpoint supports multiple detection methods you can use independently or combine.

Server-side and edge detection are documented with their enforcement counterparts — see Middleware and Gateway below.

Learn more about detection methods →

Enforce

Take action on detected agents with configurable policies. Start in observe mode, then graduate to blocking, redirecting, or challenging when you're confident in your detection settings.

Learn more about enforcement →

Govern (KYA-OS)

Control what AI agents can access using identity-based governance. KYA-OS adds authentication, authorization, and consent to AI agent interactions.

Learn more about governance →

Choose Your Integration

View Marketing Pixel documentation
No Code
Marketing Pixel

Marketing Pixel

GTM-compatible pixel for marketing teams - no coding required

View Beacon documentation
Client Side
Beacon

Beacon

Lightweight tracking beacon for any website with WebWorker support

View Middleware documentation
Next.js
Middleware

Middleware

Middleware for Next.js to detect and block AI agents

View Express documentation
Node.js
Express

Express

Express middleware for detecting and blocking AI agents

View API documentation
Custom
API

API

API for detecting and blocking AI agents

You can start with one method and layer on more as your needs evolve: most integrations take under 10 lines of code.

All Methods at a Glance

Start with Detect. Detection-only integrations (Pixel, Beacon) log AI agent visits without blocking anything — zero risk, instant visibility — before you decide what to enforce.

MethodPillarIntegrationSeesOverheadBest For
Marketing PixelDetectScript tag / GTMJS-executing browsersNone — async, off-pathNo-code, marketing teams
Beacon SDKDetectnpmJS-executing browsers, richer signalsNone — async, non-blockingSPAs, static sites
GatewayDetect + EnforceDNS CNAMEEvery request to your domainIn-path at the edgeAny origin, zero code changes
MiddlewareDetect + Enforcenpm (Next.js / Express)Every request reaching your serverIn-requestServer-side, auth routes
KYA-OSGovernDashboard or self-hostAuthenticated agent identityIn-processAPI providers, SaaS platforms

Methods are composable. You can run Pixel, Middleware, and Govern simultaneously — they share the same dashboard and detections are automatically deduplicated.

Choose by Scenario

Goal: See which AI agents are visiting your site.

Recommended: Marketing Pixel or Gateway (observe mode)

The Pixel deploys through GTM with no code changes. If you want coverage for non-JS agents too, point your DNS at the Gateway instead. Both feed into the same dashboard.

Pixel setup → · Gateway setup →

Goal: Detect and block AI agents on server-rendered routes.

Recommended: Middleware (enforce mode) + Beacon for client-side coverage

Middleware protects server routes and API endpoints. Add Beacon on the client for browser-fingerprint signals. Together they cover both surfaces: every request that reaches the server, plus client-side signals from JS-executing browsers.

Middleware setup → · Beacon setup →

Goal: Protect API endpoints from unauthorized AI scraping.

Recommended: Gateway or Express Middleware

Gateway works with any backend language via DNS — no SDK needed. If you run Express/Node, the middleware gives you per-route control with access to request context.

Gateway setup → · Middleware setup →

Goal: Let verified AI agents access your platform on your terms.

Recommended: Govern (KYA-OS) + Middleware or Gateway for enforcement

Govern handles agent identity, consent, and scoped permissions. Pair it with enforcement so unverified agents are blocked while approved agents get structured access.

Govern overview → · Deployment guide →

Goal: Maximum coverage with multi-layer defense.

Recommended: Gateway + Middleware + Govern

Gateway catches traffic at the edge. Middleware adds server-side analysis with auth context. Govern provides identity verification for approved agents. All three report to the same dashboard with automatic deduplication.

Gateway setup → · Middleware setup → · Govern overview →

Progressive Adoption

Most teams start with Detect to understand their AI agent traffic — the Pixel or Beacon takes minutes to deploy and carries no risk. Once you see what's hitting your site, switch to Enforce to block unwanted agents. The upgrade is a config change, not a new integration: define your policies in the dashboard, then flip your middleware to enforce mode (or promote your gateway rules from log to a real verdict).

When you're ready to go further, Govern lets you move from "block everything" to "authorize the right agents." Verified agents authenticate, agree to terms, and access only what you permit — turning adversarial traffic into a controlled channel.

Quick Start

Ready to install? Follow the Quick Start Guide to have Checkpoint running in about 5 minutes.

Architecture Overview

Checkpoint uses a multi-layered approach to detect and manage automated traffic:

  1. Detection Layer — Analyzes requests using user agent, TLS fingerprint, headers, and behavioral signals
  2. Classification Engine — Classifies traffic as human, ai_agent, bot, or incomplete_data with confidence scores (0–100)
  3. Policy Engine — Evaluates enforcement rules (allow lists, deny lists, path rules, thresholds)
  4. Governance Layer — KYA-OS identity verification, delegation proofs, and scoped access control
  5. Analytics Layer — Tracks and reports detection metrics with session consolidation

Next Steps

  • Core Concepts — The mental model behind detection, enforcement, and identity
  • Quick Start — Get up and running in 5 minutes
  • Integrations — Server, platform, and analytics integrations for an existing stack
  • Cookbooks — Practical, step-by-step guides for common setups
  • Dashboard — Navigate the Checkpoint dashboard
  • API Reference — Complete REST API documentation

Support