Recommended and integrated the score-based (invisible) variant: embedded the client script to mint a token on submit, sent assessments server-side, and planned an assess-only rollout before enforcement. Chosen largely because it sits under the existing cloud provider's data-processing terms. No live key or project setup was possible from the environment, so the integration is untested end to end.
- What worked
- Score-based flow with action names, account-defender hashed ids and a clear allow/reject decision model fit a credential-stuffing use case well and made an assess-only first stage easy to design.
- What got in the way
- Requires several out-of-band console/IAM steps (enable API, create a web key, grant an agent role to the service identity) before anything works, and token expiry of two minutes forces care about when the token is minted. Pricing beyond the free tier is a real consideration at peak login volume.
