Form gate
One script tag on your form, one check on your server. Bots, scripted signups and Tor, VPN or proxy traffic get stopped. People just submit.
Create your account
Safari 18 · iPhonePassword
Account created
How it works
A reCAPTCHA alternative with no widget: the browser carries a token, your server checks it, and you decide what each kind of traffic gets.
gate.js tagOne script tag on your form, with your site key in data-sitekey.
<script
src="https://ipscanner.io/gate.js"
data-sitekey="site_4fQ8nZ2kLm7xR1vT9cBw"
async></script>A hidden ipscanner-token field, single use, renewed while the page is open.
<form method="post" action="/signup">
<input name="email" type="email">
<input name="password" type="password">
<!-- added by gate.js -->
<input type="hidden"
name="ipscanner-token"
value="c2l0ZV80ZlE4fDE3…">
</form>Send the token and your gs_ secret to /v1/gate/verify. The answer names the class and your action.
{
"success": true,
"class": "vpn",
"action": "flag",
"mode": "enforce",
"signals": ["network:vpn_server_list"],
"hostname": "example.com"
}In the dashboard. A change applies on the next submit, with no redeploy.
What it stops
Block scripted signups, flag VPN and proxy signups, let people through. You choose the action for each class.
Scripted and headless signups: webdriver set, a headless user agent.
AI agents filling in a form on someone's behalf.
Signups from Tor exit nodes.
Commercial VPN servers, with the provider named on paid plans.
Residential proxies, the kind rented to rotate fake accounts.
Cloud and datacenter addresses, where most signup scripts run.
Compare
The other three tell people from bots. The form gate also tells your server which network each submit came from, and lets you pick the action.
Vendor docs and pricing pages checked on October 11, 2026.
Protect a form freeVerify on your server
Post the form's token and your secret to /v1/gate/verify. Refuse the submit on block in enforce mode.
// token = the form's "ipscanner-token" field, ip = the visitor's address
const res = await fetch('https://ipscanner.io/v1/gate/verify', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ secret: process.env.IPSCANNER_GATE_SECRET, token, remote_ip: ip })
});
const v = await res.json();
if (!v.success || (v.action === 'block' && v.mode === 'enforce')) {
// reject the submission
}Monitor first, then block
Every submit lands in the Sites dashboard with its class and action. In monitor mode nothing is refused, so you can tune the policy on real traffic first.
FAQ
Create a gate, paste one script tag, add the check. Free runs in monitor mode; Starter blocks, from $19/mo.