LuawardDocs

Checkpoint Security

Learn how key-page sessions and provider verification protect checkpoint completion.

Visitor session

When a visitor starts a key-page flow, Luaward creates a short-lived server-side session. Step order, completion state, and provider proof are checked on the server. The browser does not decide that a step has passed by itself.

If Turnstile is configured for the key page, the visitor must pass it before the protected flow proceeds. Without Turnstile credentials, that check is not enabled.

Provider proof

Luaward verifies Linkvertise hashes, Lootlabs return tokens, and Work.ink one-time tokens according to the provider configuration. The Strict option controls what happens when an external provider cannot be reached: strict steps refuse completion, while non-strict steps can continue without provider proof after the configured time and session checks.

Provider checks reduce automated bypasses, but no browser-based flow can guarantee that every bot or modified client will be stopped. Review provider settings and monitor failed visits from the key-system Dashboard.

Protect account credentials

Keep provider API tokens in the provider-account settings. Luaward stores these credentials server-side; do not put them into public page text, loader code, or client-side scripts.