Skip to main content
POST
ATO risk evaluate
Evaluates a login event against the ATO heuristic engine. The platform tracks failed logins per subject in a rolling one-hour window and derives a risk level from the current count. When a threshold is crossed, an alert is created and a risk signal is automatically ingested into the risk signal pipeline. See the account takeover detection guide for the full workflow, threshold reference, and integration patterns.

Threshold rules

Request

string
required
User identifier (user ID, email, or external ID).
string
required
Login event type: login.failed, login.failed.repeated, login.success, login.new_device
string
Type of subject. Defaults to user.
string
Source IP address for the login attempt.

Response

string
The subject that was evaluated.
string
Type of subject (user).
string
Current ATO risk level: normal | elevated | high | critical
integer
Numeric risk score: 10 (normal), 50 (elevated), 70 (high), 90 (critical).
integer
Number of failed logins in the current one-hour window.
boolean
true if a new alert was triggered by this evaluation.
string
Alert category when triggered: velocity_exceeded or credential_stuffing.
string
UUID of the auto-ingested risk signal (only present when an alert fired).
string
The event type that was evaluated.

Authorizations

X-API-Key
string
header
required

API key for machine-to-machine authentication

Body

application/json
subject_id
string
required
ip_address
string
user_agent
string
device_fingerprint
string
action
string

Response

ATO evaluation result

risk_score
integer
decision
string
signals
object[]