Skip to content
Gurdx

Docs / API reference

Fraud Label Feedback

Labels an identity (IP, email, email domain, phone, card BIN, customer id, device id or text) as fraud or legitimate, or marks a dashboard event as a true or false positive.

Overview#

feedback/event is a POST method with a JSON body. Send either type + value, or the event_id of an event from your dashboard or webhooks, plus label: fraud or legit. Optional reason, source and occurred_at are kept with the label.

When to call it#

  • Support confirms that an email, phone, device or customer account belongs to a fraudster, or clears one that was wrongly suspected.
  • An alert you received was right (fraud) or wrong (legit): send its event_id. For a payment alert, the label is also applied to that transaction as fraud_confirmed or legit_confirmed.

How it works#

Gurdx stores a keyed hash of the identity and a masked value, never the raw value. A fraud label raises the risk of that identity in later checks: payments reusing it fire rule GX2001 (same customer) or GX2002 (shared device, card or IP), IP checks rate it high risk, and email and phone checks mark it invalid with a reason. A legit label offsets earlier fraud evidence. The evidence halves every 90 days. One label is kept per identity: re-sending it returns unchanged, sending the other label updates it.

If you turn on Auto-blacklist confirmed fraud on the Learning page, fraud labels are also added to a "Confirmed fraud" blacklist.

Notes#

  • Free: not counted against your quota, available on every plan.
  • Test mode validates and returns a sample result without storing anything.
  • An unknown event_id, an invalid value or a missing label returns error 131 (invalid_feedback) with HTTP 200.

Request#

POST https://gurdx.cretip.com/api/feedback/event
  • Authenticate with the key parameter or an Authorization: Bearer header.
  • Free — not counted against your quota.
  • Available on: Free trial Standard Premium Pay-as-you-go

Parameters#

NameTypeDescription
type
optional body
string What you are labelling: ip, email, email_domain, phone, card_bin, customer_id, device_id or text. Required unless you send event_id.
value
optional body
string The IP, email, phone number, BIN, id or text. Required with type.
event_id
optional body
integer Instead of type + value: the id of a dashboard event (sent as event_id in webhooks). fraud marks it a true positive, legit a false positive.
label
required body
string fraud or legit.
reason
optional body
string Free text kept with the label.
source
optional body
string Who decided, e.g. support, risk_team, chargeback_portal.
occurred_at
optional body
string|integer When it was decided: ISO-8601 date or UNIX timestamp. Defaults to now.

Every method also accepts format, lang, mode, userID. See Options.

Code samples#

curl -X POST "https://gurdx.cretip.com/api/feedback/event" \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "type": "email",
    "value": "buyer@example.com",
    "label": "fraud",
    "reason": "stolen card confirmed by issuer",
    "source": "risk_team"
}'

Response#

Success#

{
    "data": {
        "type": "email",
        "value": "b***@example.com",
        "label": "fraud",
        "status": "created"
    },
    "status": "success",
    "executionTime": 3
}

Error#

Errors are delivered with HTTP 200 — always check the status field.

{
    "status": "error",
    "code": 101,
    "type": "invalid_key",
    "description": "The API Key is missing or invalid."
}

Response fields#

NameTypeDescription
data.type string The identity type (absent for event_id).
data.value string The identity, masked: Gurdx stores only a keyed hash of it.
data.event_id integer The event labelled (only for event_id).
data.label string fraud or legit.
data.status string created, updated or unchanged.

Found a mistake? Tell us on the contact page. Contact