Identity & Risk System
Determine if a user is real, safe, and trustworthy
Combine email, phone, IP, and behavioral signals into a single risk decision before bad actors reach your product.
Get API keyEngine
Identity & Risk Engine
One call returns a complete risk picture: email, IP, phone, and behavioral signals composed into a single decision.
{
"email": "[email protected]",
"ip_address": "45.33.32.156",
"phone": "+14155552671"
}
{
"risk_score": 0.87,
"is_safe": false,
"confidence": 0.94,
"flags": [
"disposable_email",
"vpn_detected"
],
"signals": {
"email_valid": true,
"phone_valid": false,
"vpn_detected": true,
"disposable_email": true
}
}
Protect your product from fake signups, bots, fraud, and account abuse. Instead of calling validation, networking, and text APIs separately and building the scoring logic yourself, the Identity & Risk Engine returns a single structured decision.
API Reference
Base URL: https://requiems.xyz
Overview
Use Cases
- Block fake signups, disposable emails, and high-risk IPs at registration
- Score users before they transact or access sensitive features
- Identify automated traffic using behavioral and network signals
- Re-evaluate existing accounts when anomalous activity is detected
- Layer fraud signals without building scoring logic yourself
Features
API Endpoints
Protect Signup
Evaluate a new user at signup. Returns a full risk decision with per-signal breakdown across email, phone, and IP.
https://requiems.xyz/v1/systems/signup/protect
Parameters
| Name | Type | Required | Description |
|---|---|---|---|
string |
Optional | Email address to validate and score. At least one of email, phone, or ip_address is required. | |
| phone | string |
Optional | Phone number in E.164 format to validate and check for VoIP or virtual numbers. |
| ip_address | string |
Optional | IPv4 or IPv6 address to check for VPN, proxy, TOR, and hosting status. |
Try it out
Live DemoRequest
Email address to validate and score. At least one of email, phone, or ip_address is required.
Phone number in E.164 format to validate and check for VoIP or virtual numbers.
IPv4 or IPv6 address to check for VPN, proxy, TOR, and hosting status.
Response Fields
| Field | Type | Description |
|---|---|---|
| risk_score | number |
Composite risk score from 0.0 (clean) to 1.0 (high risk) |
| is_safe | boolean |
True when risk_score is below the safety threshold with no critical flags |
| confidence | number |
Confidence in the decision from 0.0 to 1.0, based on which signals resolved successfully |
| flags | array<string> |
Array of triggered risk flags. Possible values: disposable_email, vpn_detected, proxy_detected, tor_detected, is_hosting |
| signals.email | object |
Email validation result including disposable detection and MX check |
| signals.phone | object |
Phone number validation result with country code and VoIP/virtual detection |
| signals.ip | object |
IP intelligence including VPN/proxy/TOR status and fraud score |
Code Examples
curl -X POST https://requiems.xyz/v1/systems/signup/protect \
-H "requiems-api-key: YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"email": "[email protected]",
"ip_address": "45.33.32.156",
"phone": "+14155552671"
}'
import requests
url = "https://requiems.xyz/v1/systems/signup/protect"
headers = {"requiems-api-key": "YOUR_API_KEY"}
payload = {
"email": "[email protected]",
"ip_address": "45.33.32.156",
"phone": "+14155552671"
}
response = requests.post(url, json=payload, headers=headers)
data = response.json()["data"]
if not data["is_safe"]:
print(f"Blocked: risk_score={data['risk_score']}, flags={data['flags']}")
else:
print("User passed risk check")
const response = await fetch('https://requiems.xyz/v1/systems/signup/protect', {
method: 'POST',
headers: {
'requiems-api-key': 'YOUR_API_KEY',
'Content-Type': 'application/json'
},
body: JSON.stringify({
email: '[email protected]',
ip_address: '45.33.32.156',
phone: '+14155552671'
})
});
const { data } = await response.json();
if (!data.is_safe) {
console.log('Blocked:', data.flags);
}
require 'net/http'
require 'json'
uri = URI('https://requiems.xyz/v1/systems/signup/protect')
request = Net::HTTP::Post.new(uri)
request['requiems-api-key'] = 'YOUR_API_KEY'
request['Content-Type'] = 'application/json'
request.body = {
email: '[email protected]',
ip_address: '45.33.32.156',
phone: '+14155552671'
}.to_json
response = Net::HTTP.start(uri.hostname, uri.port, use_ssl: true) do |http|
http.request(request)
end
data = JSON.parse(response.body)['data']
puts data['is_safe'] ? 'Passed' : "Blocked: #{data['flags'].join(', ')}"
Error Responses
validation_failed
All of email, phone, and ip_address were omitted. At least one is required.
unauthorized
Missing or invalid API key in the requiems-api-key header
Score Risk
Score a user for risk without the full signal breakdown. Lower latency than /signup/protect, suited for background re-scoring and rate limiting.
https://requiems.xyz/v1/systems/risk/score
Parameters
| Name | Type | Required | Description |
|---|---|---|---|
string |
Optional | Email address to include in the risk score. | |
| phone | string |
Optional | Phone number in E.164 format. |
| ip_address | string |
Optional | IPv4 or IPv6 address to check. |
Try it out
Live DemoRequest
Email address to include in the risk score.
Phone number in E.164 format.
IPv4 or IPv6 address to check.
Response Fields
| Field | Type | Description |
|---|---|---|
| risk_score | number |
Composite risk score from 0.0 to 1.0 |
| is_safe | boolean |
True when the risk score is below the safety threshold |
| confidence | number |
Confidence in the score based on resolved signals |
| flags | array<string> |
Array of triggered risk flags |
Code Examples
curl -X POST https://requiems.xyz/v1/systems/risk/score \
-H "requiems-api-key: YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"email": "[email protected]", "ip_address": "45.33.32.156"}'
import requests
response = requests.post(
"https://requiems.xyz/v1/systems/risk/score",
headers={"requiems-api-key": "YOUR_API_KEY"},
json={"email": "[email protected]", "ip_address": "45.33.32.156"}
)
data = response.json()["data"]
print(f"risk_score={data['risk_score']}, is_safe={data['is_safe']}")
const { data } = await fetch('https://requiems.xyz/v1/systems/risk/score', {
method: 'POST',
headers: { 'requiems-api-key': 'YOUR_API_KEY', 'Content-Type': 'application/json' },
body: JSON.stringify({ email: '[email protected]', ip_address: '45.33.32.156' })
}).then(r => r.json());
console.log(data.risk_score, data.is_safe);
Error Responses
validation_failed
All of email, phone, and ip_address were omitted
unauthorized
Missing or invalid API key
Verify User
Deep-verify an email address using domain-level signals including WHOIS age, MX records, and domain availability. Optional IP check. Use for high-value or suspicious accounts.
https://requiems.xyz/v1/systems/user/verify
Parameters
| Name | Type | Required | Description |
|---|---|---|---|
string |
Required | Email address to verify. Domain-level WHOIS, MX, and DNS checks are run automatically. | |
| ip_address | string |
Optional | Optional IPv4 or IPv6 address. When provided, VPN and proxy signals are added to the result. |
Try it out
Live DemoRequest
Email address to verify. Domain-level WHOIS, MX, and DNS checks are run automatically.
Optional IPv4 or IPv6 address. When provided, VPN and proxy signals are added to the result.
Response Fields
| Field | Type | Description |
|---|---|---|
| verified | boolean |
True when risk score is below 0.3, confidence is above 0.5, email is valid, domain has MX, and domain is registered |
| confidence | number |
Confidence in the verification result, based on how many signals resolved |
| risk_score | number |
Composite risk score from 0.0 to 1.0 |
| flags | array<string> |
Triggered risk flags. Possible values: email_invalid, disposable_email, no_mx, domain_not_registered, young_domain, whois_unavailable, ip_risk |
| signals.email | object |
Email validation result |
| signals.domain | object |
Domain intelligence including WHOIS age, MX and A record presence, and registration status |
| signals.ip | object |
IP risk signals. Null when ip_address was not provided |
Code Examples
curl -X POST https://requiems.xyz/v1/systems/user/verify \
-H "requiems-api-key: YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"email": "[email protected]", "ip_address": "45.33.32.156"}'
import requests
response = requests.post(
"https://requiems.xyz/v1/systems/user/verify",
headers={"requiems-api-key": "YOUR_API_KEY"},
json={"email": "[email protected]", "ip_address": "45.33.32.156"}
)
data = response.json()["data"]
print(f"verified={data['verified']}, confidence={data['confidence']}")
const { data } = await fetch('https://requiems.xyz/v1/systems/user/verify', {
method: 'POST',
headers: { 'requiems-api-key': 'YOUR_API_KEY', 'Content-Type': 'application/json' },
body: JSON.stringify({ email: '[email protected]', ip_address: '45.33.32.156' })
}).then(r => r.json());
console.log(data.verified, data.confidence);
Error Responses
validation_failed
email field is missing or empty
unauthorized
Missing or invalid API key
Frequently Asked Questions
All-in-one backend for SaaS products
Authentication, validation, fraud detection, payments intelligence, and global data, delivered through one unified API.