← All docs

Integrations

Choose a transport that can actually deliver your configured cloaking method. ShieldGate rejects incompatible method and integration pairs instead of silently substituting another delivery path.

Choose the transport first

A delivery method describes how an allowed visitor receives the offer; an integration describes where ShieldGate owns the request before your safe page is rendered. Both values are stored with the site and checked at the dashboard save boundary, in the installer, and again by the public decision service.

TransportSupported delivery methodsPrimary use
jsredirect, loading, iframe, prepageFast onboarding when a client tag is acceptable
phpredirect, meta, loading, iframe, cookie_overlay, mouse_engagement, reverse, prepagePHP entry point before the safe page emits output
wpredirect, meta, loading, iframe, cookie_overlay, mouse_engagement, reverse, prepageWordPress hook before theme rendering
cf_worker, nginx, caddy, traefik, apache, openlitespeedreverse, prepage handoffReverse-render proxy at the edge or web server
dnsshadow, reverseCustomer domain mapped to the ShieldGate shadow or reverse route
zipprepage bundlePackaged safe-page delivery where the bundle owns the page

If a combination is not listed, do not deploy it. The dashboard displays the reason and the server refuses the saved configuration with a non-money compatibility response.

Same-URL delivery

Use these ShieldGate-hosted entries when you want a server-rendered URL-preserving surface. Query parameters such as UTMs and click IDs are preserved through the signed handoff.

Reverse render:  https://your-host/r/SITE_KEY
Shadow iframe:   https://your-host/m/SITE_KEY
Prepage gate:    https://your-host/g/SITE_KEY?mode=prepage&next=reverse

The /g route is a Stage-1 gate, not a replacement for the selected Stage-2 method. After verification, it preserves the configured method: meta refresh, loading, iframe, consent, engagement, shadow, reverse, or redirect.

WordPress plugin

Download the site-bound ZIP from Dashboard → Sites → your site → Install. Upload it through WP-Admin → Plugins → Add New → Upload Plugin, activate it, and clear any full-page cache once. The plugin runs before theme output, signs its decision request, honors the stored method, and keeps the safe page as the fallback when a visitor is blocked or the decision service is unavailable.

PHP include

The dashboard-generated PHP bootstrap is intentionally small. Paste it before any output in the entry script. It downloads the versioned SDK from /api/public/a.php, caches it locally for five minutes, and then loads the cached SDK. The SDK sends a signed server request and supports redirect, meta, loading, inline iframe, consent, engagement, and reverse delivery according to the saved method.

<?php
// Generated in Dashboard → Sites → Install → PHP.
// Paste before <!DOCTYPE>, whitespace, or any output.
// The generated loader contains your site key but never embeds the site secret.
?>

Cloudflare Worker and web-server proxy

The generated Worker, Nginx, Caddy, Traefik, Apache, and OpenLiteSpeed artifacts are currently reverse-render transports. They route ordinary document requests to /r/SITE_KEY and preserve public API routes. They are not generic HTML rewriters, so the dashboard does not offer them for client-only methods such as meta, loading, iframe, consent, or engagement.

Apply the generated artifact to the customer-facing hostname, preserve forwarded visitor headers, disable intermediary caching for decision responses, and reload the proxy only after its configuration validates successfully. Use the integration checker on the Install page after deployment.

JavaScript tag

The JavaScript tag is appropriate for redirect, loading, or inline iframe delivery when the safe page is allowed to arrive before the tag executes. It is not a first-byte transport: browser source, cache, and network tooling can already contain the safe page. The tag is therefore rejected for meta, consent, and engagement methods. For those methods use PHP, WordPress, or the Neutral Gate Shell entry URL.

<script
  data-site-key="SITE_KEY"
  src="https://your-host/api/public/a.js"
></script>

Prepage composition

Configure Turnstile, reCAPTCHA, or the built-in challenge in Flow → Delivery. The gate withholds the destination until server-side verification succeeds. Direct methods redeem an exchange token; shadow and reverse receive an opaque signed handoff to /m or/r. A failed gate never returns the money URL.

Integration checker

Paste the public customer URL into the Install page checker after deployment. It grades only signals exposed by the selected integration. A JavaScript install is expected to expose its loader tag; a server-side install is expected to expose a server response or redirect. The result is diagnostic and is not used as authorization evidence.

Trackers and postbacks

Conversion postbacks remain separate from delivery. Point your signed postback at the site-specific endpoint and keep the signing secret on the server:

GET https://your-host/api/public/postback/SITE_KEY
    ?cid={clickid}&payout={payout}&status={status}&sig={hmac}