ThreatPrevent
ThreatPrevent
Cyber Trust Intelligence
POST/v1/payment-risk

Payment Risk API

Evaluate an email address at the point a payment decision is being made. Designed for finance, fraud and payment approval workflows.

Common use cases

Payment approvalPayee verificationAccounts payable checksBusiness email compromise risk
Single request

Check one email address

Send a JSON object containing email.

cURL
curl -X POST https://api.threatprevent.io/v1/payment-risk \
  -H "Content-Type: application/json" \
  -H "x-api-key: YOUR_API_KEY" \
  -d '{"email":"accounts@example.com"}'
Example response
200 OK
{
  "endpoint": "payment-risk",
  "risk": "low",
  "risk_score": 20,
  "source_type": "payment_scan",
  "target": "hashed-or-normalised-target",
  "charged": true,
  "is_free": false,
  "unit_price_pence": 25,
  "billable_units": 1,
  "total_price_pence": 25,
  "charged_from_credit_pence": 25,
  "overage_pence": 0,
  "remaining_credit_pence": 2475
}
Try it

Interactive API explorer

Response
Response will appear here.
The API key stays in this browser component state and is sent directly to the ThreatPrevent API.
POST/v1/payment-risk/bulk

Bulk Payment Risk

Submit up to 10,000 email addresss in one HTTP request. Billing is calculated by records processed.

cURL
curl -X POST https://api.threatprevent.io/v1/payment-risk/bulk \
  -H "Content-Type: application/json" \
  -H "x-api-key: YOUR_API_KEY" \
  -d '{"emails":["accounts@example.com","finance@example.org","payee@example.net"]}'
Illustrative bulk response
{
  "results": [
    {
      "email": "accounts@example.com",
      "risk": "low"
    },
    {
      "email": "finance@example.org",
      "risk": "medium"
    },
    {
      "email": "payee@example.net",
      "risk": "low"
    }
  ],
  "charged": true,
  "is_free": false,
  "unit_price_pence": 25,
  "billable_units": 3,
  "total_price_pence": 75,
  "charged_from_credit_pence": 75,
  "overage_pence": 0
}
Try it

Interactive API explorer

Response
Response will appear here.
The API key stays in this browser component state and is sent directly to the ThreatPrevent API.

Risk interpretation

Low

No significant risk signal identified from the intelligence currently available.

Medium

A risk signal warrants additional review before making the decision.

High

Significant risk indicators are present and the decision should be escalated.

High

Escalate and independently verify before payment.

Medium

Review the payee and payment context before proceeding.

Low

Proceed according to your normal payment controls.

Decision-support notice

Threat intelligence is time-sensitive and cannot provide visibility of every threat. Risk results should be used as an additional decision signal rather than as the sole control for critical business decisions.