> For an index of all Botscent documentation, see https://botscent.nibnalin.me/llms.txt.

# A script tag

Add the page half of Botscent to any page with one script tag and check the install.

Add the page half of Botscent to any HTML page with a script tag. The script runs in the browser and needs no build step. The server half runs in the server for your pages or your API.

## Before you start

You need:

* Node.js 22.12 or later, to install the package and run the check.
* A server that serves static files from your own origin.

## 1. Install the package

Install `botscent` from npm.

```sh title="Terminal"
npm install botscent
```

With pnpm, yarn or bun, use their `add` command.

## 2. Add the page half

Copy `node_modules/botscent/dist/botscent.js` to the folder that your server serves as static files. This example uses `public`.

```sh title="Terminal"
cp node_modules/botscent/dist/botscent.js public/botscent.js
```

In the `<head>` of each page, add a deferred script tag for `/botscent.js`.

```html title="index.html"
<script defer src="/botscent.js"></script>
```

The script now starts itself on each page.

## 3. Add the server half

The script tag adds only the page half. Add the server half to the server for your pages or your API. Use the page for that server:

* [Express](/docs/express)
* [Hono](/docs/hono)
* [Cloudflare Workers](/docs/cloudflare-workers)
* [Netlify](/docs/netlify)
* [Vercel](/docs/vercel)
* [FastAPI and Starlette](/docs/fastapi)
* [Django](/docs/django)
* [Flask](/docs/flask)
* [Any other server](/docs/other-servers)

## 4. Read the verdict

The script exposes `window.botscent` with `verdict`, `subscribe`, `reportHeaders`, `diagnostics`, `start` and `VERSION`.

On every change of the page verdict, the script dispatches a `botscent` event on `window`. The event's `detail` is the new verdict. A listener for the first `botscent` event can already call `window.botscent`.

In a page script, call `botscent.verdict` to show the page verdict. Listen for the `botscent` event to show each change.

```html title="index.html"
<pre id="verdict"></pre>
<script>
  const show = () => (document.getElementById('verdict').textContent = JSON.stringify(botscent.verdict()))
  addEventListener('DOMContentLoaded', show)
  addEventListener('botscent', show)
</script>
```

In a normal browser, the page shows `{"type":"human","reasons":[]}`.

> **Warning:** Do not use the page verdict to allow access. The visitor's browser computes the page verdict. On your server, use `isVerified` on the request's own verdict, as [The trust model](/docs/trust-model) describes.

## 5. Check the install

Serve the page. Then run the check against its URL.

```sh title="Terminal"
npx botscent check https://your-site.example/
```

The `page-script` check prints `pass`, and the command exits with code 0.

Without a server half that sends the request's own verdict to the page, the `server-half` check prints `unknown`. If a check fails, see [Verify your install](/docs/verify).

## Debug output

To log the page half's decisions, add `data-debug` to the script tag.

```html title="index.html"
<script defer src="/botscent.js" data-debug></script>
```

The browser console now shows one line for each decision, with the prefix `[botscent]`.

## Content Security Policy

The script has no inline code and no `eval`. Under a strict Content Security Policy, `script-src` must allow the script's origin. When you serve the script yourself, that origin is `'self'`.

As an alternative, put a nonce on the script tag and add `'strict-dynamic'` to `script-src`. If the policy blocks the script, the `csp` check of `npx botscent check` fails.

## Next steps

* [The verdict](/docs/verdict): Read what `type`, `agent_name` and `reasons` mean.
* [From the page to the server](/docs/page-to-server): Send the page verdict to your server with `botscent.reportHeaders`.
* [Page API](/docs/page-api): Read every function on `window.botscent`.
* [examples/script](https://github.com/nalinbhardwaj/botscent/tree/main/examples/script): Run a page with the script tag.
