All systems

Identity & Risk System

Determine if a user is real, safe, and trustworthy

Combine email, phone, IP, and behavioral signals into a single risk decision before bad actors reach your product.

Get API key

Engine

Identity & Risk Engine

One call returns a complete risk picture: email, IP, phone, and behavioral signals composed into a single decision.

POST /v1/systems/signup/protect
Request
{
  "email": "[email protected]",
  "ip_address": "45.33.32.156",
  "phone": "+14155552671"
}
Response
{
  "risk_score": 0.87,
  "is_safe": false,
  "confidence": 0.94,
  "flags": [
    "disposable_email",
    "vpn_detected"
  ],
  "signals": {
    "email_valid": true,
    "phone_valid": false,
    "vpn_detected": true,
    "disposable_email": true
  }
}

Protect your product from fake signups, bots, fraud, and account abuse. Instead of calling validation, networking, and text APIs separately and building the scoring logic yourself, the Identity & Risk Engine returns a single structured decision.

API Reference

Base URL: https://requiems.xyz

Overview

Use Cases

  • Block fake signups, disposable emails, and high-risk IPs at registration
  • Score users before they transact or access sensitive features
  • Identify automated traffic using behavioral and network signals
  • Re-evaluate existing accounts when anomalous activity is detected
  • Layer fraud signals without building scoring logic yourself

Features

Email validation with disposable and MX record checks
Phone number validation and carrier lookup
IP geolocation, VPN, proxy, and TOR detection
ASN and threat intelligence signals
Domain age and reputation checks
Single structured risk decision in one API call

API Endpoints

Protect Signup

Evaluate a new user at signup. Returns a full risk decision with per-signal breakdown across email, phone, and IP.

POST
https://requiems.xyz/v1/systems/signup/protect

Parameters

Name Type Required Description
email string Optional Email address to validate and score. At least one of email, phone, or ip_address is required.
phone string Optional Phone number in E.164 format to validate and check for VoIP or virtual numbers.
ip_address string Optional IPv4 or IPv6 address to check for VPN, proxy, TOR, and hosting status.

Try it out

Live Demo
Request

Email address to validate and score. At least one of email, phone, or ip_address is required.

Phone number in E.164 format to validate and check for VoIP or virtual numbers.

IPv4 or IPv6 address to check for VPN, proxy, TOR, and hosting status.

Response Fields

Field Type Description
risk_score number Composite risk score from 0.0 (clean) to 1.0 (high risk)
is_safe boolean True when risk_score is below the safety threshold with no critical flags
confidence number Confidence in the decision from 0.0 to 1.0, based on which signals resolved successfully
flags array<string> Array of triggered risk flags. Possible values: disposable_email, vpn_detected, proxy_detected, tor_detected, is_hosting
signals.email object Email validation result including disposable detection and MX check
signals.phone object Phone number validation result with country code and VoIP/virtual detection
signals.ip object IP intelligence including VPN/proxy/TOR status and fraud score

Code Examples

curl -X POST https://requiems.xyz/v1/systems/signup/protect \
  -H "requiems-api-key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "email": "[email protected]",
    "ip_address": "45.33.32.156",
    "phone": "+14155552671"
  }'

Error Responses

422

validation_failed

All of email, phone, and ip_address were omitted. At least one is required.

401

unauthorized

Missing or invalid API key in the requiems-api-key header

Score Risk

Score a user for risk without the full signal breakdown. Lower latency than /signup/protect, suited for background re-scoring and rate limiting.

POST
https://requiems.xyz/v1/systems/risk/score

Parameters

Name Type Required Description
email string Optional Email address to include in the risk score.
phone string Optional Phone number in E.164 format.
ip_address string Optional IPv4 or IPv6 address to check.

Try it out

Live Demo
Request

Email address to include in the risk score.

Phone number in E.164 format.

IPv4 or IPv6 address to check.

Response Fields

Field Type Description
risk_score number Composite risk score from 0.0 to 1.0
is_safe boolean True when the risk score is below the safety threshold
confidence number Confidence in the score based on resolved signals
flags array<string> Array of triggered risk flags

Code Examples

curl -X POST https://requiems.xyz/v1/systems/risk/score \
  -H "requiems-api-key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"email": "[email protected]", "ip_address": "45.33.32.156"}'

Error Responses

422

validation_failed

All of email, phone, and ip_address were omitted

401

unauthorized

Missing or invalid API key

Verify User

Deep-verify an email address using domain-level signals including WHOIS age, MX records, and domain availability. Optional IP check. Use for high-value or suspicious accounts.

POST
https://requiems.xyz/v1/systems/user/verify

Parameters

Name Type Required Description
email string Required Email address to verify. Domain-level WHOIS, MX, and DNS checks are run automatically.
ip_address string Optional Optional IPv4 or IPv6 address. When provided, VPN and proxy signals are added to the result.

Try it out

Live Demo
Request

Email address to verify. Domain-level WHOIS, MX, and DNS checks are run automatically.

Optional IPv4 or IPv6 address. When provided, VPN and proxy signals are added to the result.

Response Fields

Field Type Description
verified boolean True when risk score is below 0.3, confidence is above 0.5, email is valid, domain has MX, and domain is registered
confidence number Confidence in the verification result, based on how many signals resolved
risk_score number Composite risk score from 0.0 to 1.0
flags array<string> Triggered risk flags. Possible values: email_invalid, disposable_email, no_mx, domain_not_registered, young_domain, whois_unavailable, ip_risk
signals.email object Email validation result
signals.domain object Domain intelligence including WHOIS age, MX and A record presence, and registration status
signals.ip object IP risk signals. Null when ip_address was not provided

Code Examples

curl -X POST https://requiems.xyz/v1/systems/user/verify \
  -H "requiems-api-key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"email": "[email protected]", "ip_address": "45.33.32.156"}'

Error Responses

422

validation_failed

email field is missing or empty

401

unauthorized

Missing or invalid API key

Frequently Asked Questions

All-in-one backend for SaaS products

Authentication, validation, fraud detection, payments intelligence, and global data, delivered through one unified API.