🎉 Tickety V3 has now been released! Read more →
Verification

Web Security

Extra checks on browser verification that can block risky attempts or quietly record them.

Web Security is a second layer on top of Web Verification. Tickety weighs up each browser attempt, gives it a threat score, and either lets it through, blocks it, or records it and stays out of the way. You decide how strict that is.

It only affects Web Verification. Discord Captcha and Click to Pass never touch a browser, so nothing on this page applies to them.

Access the Web Dashboard

Open your Tickety Dashboard. Log in using your Discord Account.

  1. Once logged in, locate and click on the "Configuration" section in the sidebar under the VERIFICATION category.

  2. Open General Settings, then click Settings on the Web Verification card.

Every setting below needs premium. A free server can open the dialog and save it, but nothing is scored and nothing is blocked, and the built in simulator reports Inactive.

Core Policy 👑

  • Enable Advanced Web Features - Turns risk scoring and the blocking rules on for browser verification. Everything else here waits on this toggle.
  • Enforcement mode - Enforce (Allow/Block) actively blocks matching sessions. Monitor (Log only) lets them through and only records what it would have done.
  • Threat threshold - A slider from 0 to 100. An attempt that reaches this score is blocked in Enforce, or flagged in Monitor. Lower is stricter. It ships at a recommended value, which is a sensible place to leave it until your analytics tell you otherwise.
  • 👑 Blocked countries - Members connecting from a country on this list are blocked outright. Search for any supported country, up to 200 of them.

In Monitor with no log channel set, the dialog warns you that nothing is being recorded. Pick a channel under Logging on the Verification Configuration page first, otherwise monitoring gives you nothing to read.

Rules that block outright 👑

These four toggles are all or nothing. When one of them matches, the attempt is blocked.

  • Block Identity-Hiding Browsers - Blocks the attempt when the browser looks like it is hiding or faking its identity.
  • Block Developer Tools - Blocks the attempt when developer tools are open during verification.
  • Block Incognito Mode - Blocks the attempt when the member is verifying in a private or incognito window.
  • 👑 Block VPN / Proxy / Tor - Blocks the attempt when the connection looks like a VPN, a proxy or Tor.

Incognito windows and VPNs are ordinary for a lot of people, not just for raiders. Turning those two on will turn away real members. Leave them off and let the score handle it unless you are dealing with an active raid.

Threat Score Builder 👑

The right hand column decides how much weight each signal carries in the score. Start from a preset:

  • Recommended - The balanced settings Tickety ships with.
  • Protective - Leans harder on every signal, for servers under pressure.
  • Relaxed - Softer, for communities where a false block costs you more than a bot does.

Move any slider yourself and the preset switches to Custom. Each signal can also be switched off entirely, which takes it out of the score without changing the rest. Reset puts everything back to Recommended.

The signals you can weight:

  • 👑 VPN / Proxy / Tor
  • Incognito
  • Identity-hiding browser
  • Developer tools
  • Suspicious session (moderate)
  • Suspicious session (high)
  • Possible alt account
  • Likely alt account
  • Bot-like behavior
  • Unusual behavior

Risk Simulator 👑

Risk Simulator at the bottom of the dialog shows how your current settings would treat a made up attempt. Four scenarios are ready to load:

  • Clean Session - A normal member on an ordinary browser.
  • Network Risk - A connection that looks risky.
  • Likely Alt - A profile that looks like a second account.
  • High Automation - An attempt that looks scripted rather than human.

Each one comes back as Allow, Block, Monitor only or Inactive, with a short breakdown of what pushed it there. It changes nothing and touches no real member, so run it before you switch anything to Enforce.

What a blocked member sees

The browser page turns into Verification Blocked with a short list of plain language reasons, so the member knows roughly why. They can try again after a short wait.

Nothing else in your server changes: they keep their unverified roles and stay on your member list. If you want them to be able to reach you, quarantine rather than kick, and offer an appeal panel. See Punishments and Appeals.

Your verification log gains a Web Information block on each pass and fail, showing whether the attempt was blocked or flagged, whether the captcha passed, and what was detected.

Checking your results

Open Analytics in the sidebar and pick the Verification tab. The Web Security panel shows:

TileWhat it counts
AllowedAttempts that passed the policy
BlockedAttempts turned away in Enforce
Would Have BlockedAttempts caught while only monitoring
Average Threat ScoreThe average score across the range

Under those sit Top Detections, Blocklist Hits by Country and Recent Checks, which is where you find out whether your rules are catching bots or catching your members.

The panel reads "Web security is not switched on" until you enable it, and is blurred behind a premium prompt on free servers.

A safe rollout

Set a log channel

Pick one under Logging on the Verification Configuration page, so there is somewhere for the records to land.

Start in Monitor

Turn on Enable Advanced Web Features with Enforcement mode on Monitor (Log only). Nobody is blocked yet.

Read the analytics for a week

Watch Would Have Blocked and Top Detections. If real members are showing up there, raise the threshold or lower the weight of the signal that is catching them.

Switch to Enforce

Once the numbers look right, set Enforcement mode to Enforce (Allow/Block) and save.

Limits

FreePremium
Scoring and blockingnoyes
Blocked countriesnoup to 200
Threat Score Buildernoyes
Risk Simulatornoyes
Web Security in Analyticsnoyes
👑

This feature requires a Premium Subscription.

On this page