ATO risk evaluate
Account Takeover
Evaluate ATO risk
Evaluate a login event against account takeover heuristics. Tracks failed login velocity per subject and triggers alerts when thresholds are exceeded.
POST
ATO risk evaluate
Evaluates a login event against the ATO heuristic engine. The platform tracks failed logins per subject in a rolling one-hour window and derives a risk level from the current count. When a threshold is crossed, an alert is created and a risk signal is automatically ingested into the risk signal pipeline.
See the account takeover detection guide for the full workflow, threshold reference, and integration patterns.
Threshold rules
Request
string
required
User identifier (user ID, email, or external ID).
string
required
Login event type:
login.failed, login.failed.repeated, login.success, login.new_devicestring
Type of subject. Defaults to
user.string
Source IP address for the login attempt.
Response
string
The subject that was evaluated.
string
Type of subject (
user).string
Current ATO risk level:
normal | elevated | high | criticalinteger
Numeric risk score: 10 (normal), 50 (elevated), 70 (high), 90 (critical).
integer
Number of failed logins in the current one-hour window.
boolean
true if a new alert was triggered by this evaluation.string
Alert category when triggered:
velocity_exceeded or credential_stuffing.string
UUID of the auto-ingested risk signal (only present when an alert fired).
string
The event type that was evaluated.

