# Heedeo docs

Heedeo identifies every agent on your site and lets you decide who gets in and what they can do. It verifies agents with the open Web Bot Auth standard and your list of trusted operators, identifies the person or company each agent acts for, counts per principal instead of per IP, and applies your per-route rules in your middleware: allow (200), challenge (401), throttle (429 with Retry-After) or block (403).

Status: ready. Access is by booking a short call (https://cal.com/heedeo/30min). The package is provided at onboarding.

## Docs

- [Quickstart](https://heedeo.com/docs/quickstart.md): Get access, add the Next.js middleware, write a first rule and test it with /api/decide.
- [How it works](https://heedeo.com/docs/how-it-works.md): Request lifecycle: Web Bot Auth verification, trusted operators, the principal, per-principal counting, verdicts and the passkey handoff.
- [Policy reference](https://heedeo.com/docs/rules.md): Every policy key, route matching and normalization, the cap and overCap, verdicts with HTTP statuses, and the demo policy decided row by row.
- [Security and data handling](https://heedeo.com/docs/security.md): What leaves your servers, every signature check, replay protection and its limits, SSRF-safe key fetching and failure modes.
- [Public API](https://heedeo.com/docs/api.md): The live endpoints on heedeo.com with real output: /api/visitor, /api/decide, /api/policy and /api/book.
- [FAQ](https://heedeo.com/docs/faq.md): Short answers on verification, detected agents, principals, passkeys, throttling, data and access.
- [How to verify our claims](https://heedeo.com/trust.md): Each claim with the curl that checks it, known limits of the demo, and what is not public yet.
- [Privacy](https://heedeo.com/privacy.md): What heedeo.com itself collects when you request a call, and what it is used for.

## Try it now, no signup

```bash
curl https://heedeo.com/api/visitor
curl "https://heedeo.com/api/decide?route=/signup&client=agent&signed=false"
curl https://heedeo.com/api/policy
```

## Everything at once

- https://heedeo.com/llms.txt: short map of the site
- https://heedeo.com/llms-full.txt: llms.txt plus every doc in one file
- https://heedeo.com/index.md: the landing page as markdown
- https://heedeo.com/openapi.json: OpenAPI spec

---

Docs index: https://heedeo.com/docs.md. How to verify our claims: https://heedeo.com/trust.md. Book a call: https://cal.com/heedeo/30min

Updated: 2026-10-02
