Skip to content
Gurdx
Built for Arabic & English teams

Stop fraud before it reaches your checkout

One API to score payments, verify cards and IBANs, spot VPNs and proxies, check emails and phone numbers, and moderate text — in milliseconds, with every decision explained.

No credit card. Live and test keys in one minute.

POST /scoring/payment
{
  "data": {
    "score": 82,
    "rules": [
      { "id": "PF10003", "description": "Customer IP address is probably VPN/Proxy/Hosting." },
      { "id": "PF10004", "description": "Customer email address is probably disposable." },
      { "id": "PF10002", "description": "High purchase rate according to customer_id." }
    ],
    "rulesChecked": 25,
    "rulesDetected": 3
  },
  "status": "success",
  "executionTime": 5
}
detection services
9detection services
response languages
8response languages
requests per second
1,000requests per second
response formats
4response formats

Nine services, one key

Combine only what you need. Every service returns a clear signal you can act on — block, review or allow.

Built for the places fraud happens

Pick the signals that matter to your business and combine them into one decision.

E-commerce & digital goods

Instant-delivery products are a favourite of fraudsters. Score every order before you deliver a code, top-up or voucher.

Fintech & payments

Validate IBANs and cards, detect risky geographies and keep deposits and withdrawals clean.

Gaming & top-ups

Spot account farming, bonus abuse and stolen-card top-ups while keeping real players moving.

Marketplaces

Verify buyers and sellers, moderate listings and reviews, and cut off repeat offenders.

Sign-up abuse

Catch disposable emails, fake phone numbers and VPN-hopping multi-accounters at registration.

Account takeover

Compare login geography and network reputation to your user history and step up verification when it looks off.

Chargeback reduction

Stop likely-fraud orders before they become disputes, and keep an auditable reason for every decision.

Integrate in minutes

Plain HTTPS and JSON. Authenticate with a key parameter or a Bearer header, read the score, decide.

  • Responses in JSON, XML, CSV or newline format
  • Localised in 8 languages with one parameter
  • A free test mode with fake-but-realistic data
  • Webhooks signed with HMAC-SHA256
View docs
curl -G "https://gurdx.cretip.com/api/lookup/ip" \
  --data-urlencode "key=YOUR_API_KEY" \
  --data-urlencode "ip=1.1.1.1"
Drop-in REST API

Integrate in minutes. One URL, one key.

Gurdx is plain HTTPS and JSON with a consistent response envelope and a single, predictable error format. Add a key, call an endpoint, read the score — your first check can be live in minutes.

  • One response shape for every service
  • Numbered error codes you can handle in a switch
  • Shared options: format, lang, mode, params, callback, userID
Read the introduction
Request
GET https://gurdx.cretip.com/api/lookup/ip?key=YOUR_API_KEY&ip=1.1.1.1
Response
{
  "data": { "ip": "1.1.1.1", "countryCode": "AU", "scoring": { "threat_score": 12 } },
  "status": "success",
  "executionTime": 4
}

Frequently asked questions

What is Gurdx?

Gurdx is a fraud-prevention and user-intelligence API. It scores IP addresses, payments, cards, IBANs, emails, phone numbers and text so you can block abuse automatically or send risky cases to review.

How hard is it to integrate?

It is a plain REST API over HTTPS that returns JSON. Add your key, call an endpoint and read the score. Most teams have their first check running in minutes, and test mode lets you build without spending quota.

How does the free trial work?

Register and you immediately get a live and a test key on a trial plan with a monthly quota and every service unlocked. Test-mode requests are always free.

What happens to the data I send?

Card numbers are never stored — only the BIN, the last four digits and a keyed hash. You can delete any user's data through the API at any time. See the privacy policy for details.

Is a score a final verdict?

No. Scores and rules are signals. We recommend blocking only the clear-cut cases and routing the middle band to manual review. Custom rules and blacklists let you encode your own policy.

What are the rate limits?

Up to 1,000 requests per second per account, plus a monthly quota depending on your plan. Going over returns a clear error code you can handle.

Ready to cut fraud without cutting conversion?

Start free, test with fake data, then go live with the same key shape.