Skip to main content
POST

Authorizations

Authorization
string
header
required

HS256-signed JWT bearer token, obtained via the OAuth2 client-credentials grant (see Authentication).

Body

application/json

Decision request

credential
object
required
customer
object
required
transaction
object
required
airline
Airline · object

Airline / travel industry data. Present only for airline transactions.

backend_options
object

Provider-specific passthrough fields keyed by backend identifier. Not persisted.

Example:
billing
object

Billing address for the transaction

context
string

Ruleset context key. Defaults to "default" if omitted.

Example:

"checkout"

device
object
items
Item · object[]

Cart / order line items

metadata
object

Flat key-value pairs stored alongside the decision. Available to rules. Not sent to backends.

Example:
shipping
object

Shipping address for the transaction

Response

Decision result

Result of evaluating a transaction against the active ruleset.

id
string<uuid>

Unique decision identifier

Example:

"1e7b9c0a-2d43-4f6a-8d29-c4a1f2d05b3e"

amount
integer | null
Example:

5000

backend_results
BackendResult · object[]

One entry per backend rule that was executed.

context
string
Example:

"checkout"

credential_fingerprint
string

Deterministic HMAC-SHA256 payment credential identifier

Example:

"crd_4ba218..."

credential_type
enum<string> | null

Type of credential supplied in the request

Available options:
pan,
masked_pan,
sepa,
paypal
currency
string | null
Example:

"USD"

customer_id
string | null
Example:

"customer-123"

decision
enum<string>

BLOCK terminates on first match. REVIEW accumulates. ALLOW is the default when no rules match.

Available options:
ALLOW,
BLOCK,
REVIEW,
PROVISIONAL
device_fingerprint
string | null
Example:

"fp-9c1e4b7a"

device_ip
string | null
Example:

"1.2.3.4"

evaluated_at
string<date-time>
Example:

"2026-06-01T10:00:00Z"

events
object[]

Always empty on a freshly evaluated decision.

has_backend_error
boolean

True if any backend_results entry carries a non-nil error (e.g. "backend_capability_disabled").

Example:

false

integration
string | null

Integration type that originated this decision (e.g. 'interceptor')

Example:

"interceptor"

interceptor_id
string<uuid> | null

ID of the interceptor that originated this decision

Example:

null

latency_us
integer
Example:

4250

masked_credential
string | null

Display-safe masked representation, e.g. '411111 •••••• 4242' for cards or 's•••@example.com' for PayPal

Example:

"411111 •••••• 4242"

metadata
object | null

Merchant-supplied key-value pairs stored with the decision.

Example:
resolution
object | null

Always null on a freshly evaluated decision.

ruleset_id
string<uuid> | null
Example:

"6c1f4e8b-9a2d-4c7e-b5f3-8d1a6e9c4b2f"

ruleset_version
integer | null
Example:

7

source
enum<string>

RULE_ENGINE — condition rules only. BACKEND — backend rule(s) only. COMBINED — both.

Available options:
RULE_ENGINE,
BACKEND,
COMBINED
transaction_reference
string | null
Example:

"X36Q9C"

triggered_rules
TriggeredRule · object[]