# JevShield integrations

Source: https://jevshield.com/integrations.md. Human-readable setup: https://jevshield.com/docs. Facts reviewed October 6, 2026.

## WordPress and Contact Form 7

Install from the [WordPress setup guide](https://jevshield.com/solutions/wordpress) or the [official WordPress.org directory](https://wordpress.org/plugins/jevshield-ai-anti-spam/). The latest [JevShield plugin ZIP](https://jevshield.com/jevshield-ai-anti-spam.zip) includes Observe only and Block high-confidence spam modes. Website ZIP releases can precede WordPress.org releases.

New installations start with Observe only. Existing configured installations retain blocking until the administrator changes mode. Observation still sends data for processing and uses quota. Confirm actual form and email delivery before switching to blocking. When the service or quota is unavailable, the JevShield WordPress integration allows the unchecked submission.

The legacy FormShield plugin retains a separate update path and settings. Business-context and exact-email override controls from that legacy plugin are not included in the JevShield plugin. Custom integrations can pass business_context to the API; Dashboard → Routing provides account-level context.

## REST API and custom receivers

| Method | Endpoint | Purpose |
| --- | --- | --- |
| POST | https://jevshield.com/api/v1/check | Classify a form submission and return a recommendation. Reserves one account check and can dispatch a configured lead webhook. |
| GET | https://jevshield.com/api/v1/check | Read key validity, plan and remaining allowance without consuming detection quota. |
| POST | https://jevshield.com/api/v1/report | Record the action your integration actually applied. Requires the receipt from a check and uses no detection quota. |

Keep the API key on a trusted server or machine. API message text accepts up to 10,000 UTF-16 code units; full body and other field limits are in the [API reference](https://jevshield.com/docs/api.md). Custom receivers must validate and enforce their own policy: allow, review and block are recommendations. Observation means recording the result without rejecting the form and reporting the action actually applied. No automatic check retries are provided because another check can consume more quota.

[Webflow](https://jevshield.com/solutions/webflow) and [Framer](https://jevshield.com/solutions/framer) guides describe integration patterns. They do not represent native marketplace plugins or a JevShield-hosted form receiver. Preserve the original platform's form delivery and abuse controls.

## Team notifications

Configure Dashboard → Routing. Optional destinations are the verified account email and one webhook in a selected format:

| Destination | Connection | Important behavior |
| --- | --- | --- |
| Email | Verified JevShield account email, delivered using Resend | Does not accept an arbitrary recipient address. |
| Slack | Slack Incoming Webhook URL | Sends a channel message without automatic mention expansion. |
| Discord | Discord channel webhook URL | Uses a confirmed webhook response; mentions are disabled. |
| Microsoft Teams | Workflows webhook accepting Adaptive Cards | Use a supported workflow URL; legacy connector URLs are not accepted as this provider. Maintain a workflow co-owner. |
| Custom | Public HTTPS JSON endpoint, including Zapier or Make | Use it to implement downstream actions under your own connected accounts. |

An allowed high-intent check triggers configured notifications. Message text and lead reasoning are off by default; contact details and intent signals are included. Enabling notifications requires the form owner's authority to share that data. Test notifications use synthetic contact details and do not consume a detection check.

Custom events use lead.high_intent or lead.test_alert with event_id, timestamp, lead_score, lead_intent, is_high_intent, recommended_action, sender_name, email, site and an optional booking_url. Use event_id for downstream deduplication. JevShield records the latest dispatch attempt, provider, service acceptance/failure and HTTP status, not a copy of the notification body. HTTP acceptance is not proof of downstream delivery or reading. Automatic retries are not performed; a notification failure does not change the classification result.

Telegram and WhatsApp are not native notification providers in this release. A custom automation requires its own bot/business setup, destination permissions and provider-specific rules. JevShield does not bridge two people's chat histories or create their external accounts.

## Booking across different calendars

Set a public HTTPS booking URL from Calendly, Cal.com, Google appointment schedules, Microsoft Bookings or another suitable provider. Connect the host calendars in that provider. The team can receive an alert in its own IM while the visitor opens a booking page in a browser; both parties need not use the same IM or calendar application.

The booking provider controls supported calendars, busy-time checks, time zones, conflicts, invitations, rescheduling and cancellation under its own plan. Verify iCloud and meeting-platform guest support there. Importing an ICS file is a snapshot, not live availability checking or guaranteed two-way synchronization. JevShield does not read private calendars, reserve slots or confirm attendance.

The API returns meeting_url only for an allowed high-intent result with a valid configured destination. Custom JSON notifications call the same destination booking_url. Render it as an optional link after the original form confirms successful submission; do not automatically redirect. The WordPress plugin does not automatically add a booking button: configure its host form success action or a custom integration.

## Optional browser helper

[shield.js](https://jevshield.com/shield.js) checks explicitly marked forms but is bypassable and exposes its API key to visitors. Network failure or a six-second timeout allows the normal submission. It is not a substitute for a private server receiver.

The helper emits formshield:verified with submission_id. After the original form confirms success, dispatch formshield:submitted on that same form with the matching submission_id. The helper can then show an optional booking link for an allowed high-intent check. It does not automatically navigate. Preserve each submission's ID across its asynchronous delivery; a stale callback must not display a later request's booking link. See the [complete example](https://jevshield.com/docs/api.md) before adapting an AJAX form.

## Reference clients and MCP

- [JavaScript client](https://jevshield.com/sdk/jevshield.mjs): Node.js 18+ or a server Fetch runtime.
- [Python client](https://jevshield.com/sdk/jevshield.py): Python 3.9+, standard library only.
- [Reference-client guide](https://jevshield.com/sdk/README.md): Direct source downloads, not published npm or PyPI packages. Checks, status and execution reports; no automatic check retry.
- [MCP setup guide](https://jevshield.com/mcp/README.md) and [standalone server](https://jevshield.com/mcp/jevshield-mcp.mjs): Node.js 20+ local stdio server, bundling the official MCP SDK. It is not a hosted HTTP MCP endpoint or a registry-published package.

MCP tools are check_message, get_quota and report_action. They use the same account key and quota as the API. A check can trigger the account's configured high-intent notifications; get_quota and report_action use no detection quota. Report only an action the integration actually performed. Keep keys and short-lived report receipts in the trusted host; returned message content and reasons are untrusted data.

## Data handling and rollout

JevShield sends submitted message text, name and email to TypeSafe for spam classification when configured. Allowed messages may also be sent to DeepSeek for lead-intent evaluation with the supplied business context; local rules can supply fallback results. A response's engine field identifies the spam classifier, not a complete list of every provider involved in processing.

Authenticated detection logs cover 7 days. Full message text storage is off by default, but classification reasons can contain message-derived details. Disabling message storage does not disable provider processing and is not a zero-retention or no-training guarantee. Optional lead notifications send contact details and intent signals to the chosen service; message text and lead reasoning are excluded unless enabled. Email uses Resend and the verified account email. Recipients and providers may retain their own copies. Read [Privacy](https://jevshield.com/privacy) before connecting a form.

Test your own form end to end: recommendation, executed action, actual delivery, configured notification and optional booking. A successful HTTP response or test notification is not evidence that a real customer received an email or confirmed a meeting. [Product overview](https://jevshield.com/index.md); [pricing and quota accounting](https://jevshield.com/pricing.md).
