Docs / Use-case guides
Payment fraud prevention
Score every purchase, deposit or withdrawal before you capture the payment, and route risky ones to review or decline.
The problem#
Stolen cards, card testing and fake accounts all look like normal checkouts until you combine context. A single field rarely proves anything, but a billing country that differs from the IP country, a disposable email, a prepaid BIN and a very high basket together are worth a second look.
Signals to combine#
- Payment fraud: one call that returns a 0 to 100
scoreand the list of rules that fired. Send as much of the customer, billing, shipping and cart data as you have. - BIN lookup: card scheme, type, prepaid flag and issuing country.
- IP reputation: proxy, VPN, Tor and hosting flags.
- Email scoring: disposable and low-quality addresses.
- Blacklists and custom rules for your own known-bad values and business exceptions.
Integration flow#
- Collect the order data on your server at the moment the customer pays. Never send full card numbers: a BIN (first 6 to 8 digits) is enough.
- Call
POST /scoring/paymentwith the data and auserID. - Read
data.score,data.rulesanddata.custom_rules_applied. - Decide using your thresholds below.
- Store the score with the order so you can tune thresholds against real outcomes later.
<?php
$payload = ['data' => [
'action' => 'purchase',
'transaction_id' => $order->id,
'transaction_amount' => 149.90,
'transaction_currency' => 'USD',
'isDigitalProducts' => true,
'customer_id' => $user->id,
'customer_email' => $user->email,
'customer_ip' => $_SERVER['REMOTE_ADDR'],
'billing_country' => 'US',
'payment_type' => 'card',
'card_number' => substr($cardNumber, 0, 8),
]];
$ch = curl_init('https://gurdx.cretip.com/api/scoring/payment');
curl_setopt_array($ch, [
CURLOPT_POST => true,
CURLOPT_POSTFIELDS => json_encode($payload),
CURLOPT_HTTPHEADER => ['Content-Type: application/json', 'Authorization: Bearer ' . getenv('GURDX_KEY')],
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 5,
]);
$res = json_decode(curl_exec($ch), true);
$score = $res['data']['score'] ?? null; // null: API error, fail open or to review
Note: Errors are returned with HTTP 200 and
"status": "error". Checkstatusbefore readingdata.
Suggested thresholds#
These are starting points, not rules. Tune them on your own chargeback data.
| Score | Action |
|---|---|
| 0 to 39 | Approve |
| 40 to 69 | Manual review, or step-up verification such as 3-D Secure or an OTP |
| 70 to 100 | Decline, or hold until verified |
Digital goods and high-value items deserve lower review thresholds. If the call fails or times out, prefer routing to review over silently approving.
Warning: A score is a signal, not a verdict. Legitimate customers travel, use VPNs and shop with new cards. Always keep a path for a human to override.
After the decision#
Raise a webhook or chat alert for fraud_payment events so your team sees what was held. Continue with Chargeback reduction.
Found a mistake? Tell us on the contact page. Contact