For SaaS

See — and verify — the agents already using your product

Agents are signing up in your app and calling your API right now, and your browser analytics can’t see the ones that don’t run JS. Lume names every request as human, bot, or user-delegated agent, server-side and unsampled, and verifies which agents are genuinely who they claim, so your funnel numbers are trustworthy and your own code can gate, route, or charge on identity you can prove. Lume shows and verifies; it never blocks.

Sound familiar?

What Lume does for you

See the agents using your product

Agents are already hitting your app and your API. Lume names them across every endpoint by operator and type (17 agent types), server-side and unsampled, so you can tell a user-delegated agent from a crawler from a scraper, in the same view as the humans.

A product-analytics denominator you can trust

Bots and headless traffic quietly inflate signups, activation, and usage, and browser analytics can’t even see agents that don’t run JS. Lume separates humans from non-humans server-side, so the numbers under your funnel and dashboards are ones you can actually trust.

Verify agents in your own code

The Identification API takes a request’s headers and returns the agent’s operator, type, and whether it’s genuinely who it claims, so your app can gate, route, throttle, or log before you trust it. Lume gives you the truth; the action stays in your code.

Ready for the agentic web

As AI agents act on behalf of your users, classify every request as human, bot, or user-delegated agent: the foundation for any allow / charge / rate-limit decision. Verified identity you can build on, not a spoofable user-agent string.

Fits your product

Classify from your edge or CDN logs with zero client JS, or verify inline in your own code with the Identification API. One ingest token and you’re live.

Identification APITypeScript SDKREST ingestVercel middlewareCloudflare WorkerAWS CloudFrontFastlyCDN logsEdge logs

SaaS FAQ

Isn’t this just bot security or a WAF?

No. Lume is the identity and evidence layer upstream of enforcement. It shows and verifies who each request is and feeds that to your WAF or app. It doesn’t block traffic, and it isn’t a fraud or bot-security product; it makes the decisions you already make more accurate.

Can I gate or route agents in my own code?

Yes. The Identification API (Starter and up) returns each request’s operator, type, and verified status, so your app decides what to allow, route, throttle, or log. Lume never blocks. It gives you the truth, and the action is yours.

Does the SDK add latency or another supply-chain surface?

It doesn’t have to touch your request path at all. The edge/CDN log path adds zero client JS and zero latency, reading requests you already emit. The SDK batches events out of band, so tracking never sits inline, and when you want a synchronous verdict the Identification API is cache-backed for low latency.

Does a “verified” agent mean it’s safe?

No. Verification proves who an agent is (that it genuinely is the operator it claims), not how it behaves. A green check is never a synonym for “safe”; pair verified identity with your own rate limits and rules.

Do you store our users’ IPs?

Never a full one. The IP is used at ingest to verify and classify, then truncated to a network prefix (/24 or /48) before anything is persisted. It’s the evidence layer, not another store of personal data.

Know who and what is using your product.

Free plan, one ingest token. See the agents in your app and API, and verify the ones you trust.

Start for free →