TURNSTILE MIGRATION

Recalibrate managed outcomes instead of translating tokens.

GIWS V2 has its own decision pipeline, proof-of-work step, SDK lifecycle, credentials, and response contract. Outcomes should be measured, not assumed equivalent.

Maintained documentation3 sectionsAPI contract

Choose the V2 presentation

Use checkbox for an explicit control or invisible/programmatic execution for automatic verification. Managed policy still controls step-up.

  • checkbox
  • invisible
  • managed execution

Update client and backend together

Replace the loader and widget API, then send the GIWS response and secret to the GIWS verification endpoint.

  • Register exact origins
  • Use the new public and secret keys
  • POST the response to /api/siteverify from the backend
  • Handle expiry, error, and challenge events

Calibrate before removal

Review completion, proof, challenge, timeout, and block rates by action before retiring the previous integration.

  • Do not compare provider scores token-for-token
  • Test weak-device proof behavior
  • Exercise the accessible interactive fallback
  • Keep a tested rollback point until cutover is accepted
Open the V2 guide