Where does Decionis sit relative to Kong, Envoy, or Cloudflare? #8
|
There's a Kong plugin, and Envoy / Fastly / Cloudflare filters in the ecosystem. Are those Decionis enforcing at the gateway, and when should a team gate at the edge versus calling the SDK in-process? |
Replies: 1 comment
|
Short answer: those adapters are enforcement points, and the verdict they enforce comes from the Decionis Protocol. Presence is the human verification layer of Decionis — the Kong, Envoy, Fastly, Cloudflare and Vercel adapters ship as part of Presence, but they do not decide anything themselves. Each one calls through to the Decionis Protocol for the actual gate. Presence establishes that a real human is present; Decionis decides whether this action executes, and proves the verdict. That layering is why an adapter stays deliberately thin: an adapter that re-derived its own verdict from a score would be out of contract. What the adapters actually do Each implements the same enforcement contract and enforces one of four dispositions —
On a pass, a short-lived ES256 JWS is issued and adapters verify it offline against a published JWKS, so the hot path doesn't pay a round trip. The proof format is identical across all four; only the crypto runtime differs (WebCrypto, How the verdict flows Presence runs its deterministic checks locally, then hands a cryptographically bound signal package to the Decionis execution gate. Liveness becomes a policy input rather than a verdict — a low liveness score raises the risk on the decision, and device and presence evidence travel as decision context. The protocol's verdicts map straight onto what the adapter enforces: Gateway/edge versus in-process SDK Treat this as a wiring choice, not a policy choice — both paths run the same fail-closed pipeline, so picking one doesn't change what is enforced.
They compose, and in production they usually should: the edge establishes presence, the SDK gates the consequential action, and the same protocol decides both. Related: How does Presence relate to Decionis? · Where Decionis sits in the stack · Can Decionis govern AI agent tool calls? Have a different architecture or integration question? Start a new discussion — we answer publicly whenever we can. |
Short answer: those adapters are enforcement points, and the verdict they enforce comes from the Decionis Protocol.
Presence is the human verification layer of Decionis — the Kong, Envoy, Fastly, Cloudflare and Vercel adapters ship as part of Presence, but they do not decide anything themselves. Each one calls through to the Decionis Protocol for the actual gate. Presence establishes that a real human is present; Decionis decides whether this action executes, and proves the verdict.
That layering is why an adapter stays deliberately thin: an adapter that re-derived its own verdict from a score would be out of contract.
What the adapters actually do
Each implements the same enforcement con…