# Login Protection

## [Overview](https://docs.forter.com/login-protection#overview) Overview

The Login API is used at the time of customer login to prevent unauthorized users from accessing a user's account, conducting malicious activity at the time of login and gaining access to PII, payment data and other account related assets.

### [Primary Use Cases](https://docs.forter.com/login-protection#primary-use-cases) Primary Use Cases

There are a number of ways you can utilize the login protection offered by this API. The Login API can be used to enforce the following scenarios:

- **Account take over (ATO)**: To prevent incidents where fraudsters use stolen credentials to try and gain access user accounts, leading to data theft, fraud, and brand damage.

- **MFA Optimization**: Enhances multi-factor authentication (MFA) by reducing friction for legitimate users while strengthening security against fraud.

- **Credential Stuffing & Bot Protection**: Safeguards accounts from automated attacks where fraudsters use stolen username-password pairs to gain unauthorized access. Credential stuffing exploits reused credentials from data breaches, while bots automate login attempts at scale.

- **Extended Session**: Allows users to stay logged in for a longer period without needing to re-authenticate, improving convenience and user experience.

## [Integration Steps](https://docs.forter.com/login-protection#integration-steps) Integration Steps

1. ### [Front-end Integration](https://docs.forter.com/login-protection#front-end-integration)  
   In your dedicated Forter portal, you will receive a JavaScript snippet for both sandbox and production. For native mobile apps, you will receive links to download Forter's Native SDKs. You'll paste the JS script on the appropriate pages of your website or call mobile SDK methods on relevant mobile app screens to load and asynchronously collect important behavioral data from your customer.

2. ### [Send login request for decision](https://docs.forter.com/login-protection#send-login-request-for-decision)  
   Forter's [Login API](https://docs.forter.com/reference/login "Login API") can provide a decision to approve a frictionless login or suggest that Multi-Factor Auth if suspicious activity is detected.

**Login API Request**
   Primary Data Points are:
   - **Account ID**: Customer's account UID in merchant's site.
   - **User Input**: Input details submitted by the user.
   - **ConnectionInformation**: Cyber intelligence data to analyze browsing behavior.
   - **LoginMethodType**: (e.g. Password vs SMS) and status or AUTH_TOKEN_REFRESH for refreshing an idle user session.
   - Details of AdvancedAuthenticationMethod if used.

**Login API Response**
   - **forterDecision**: The latest Forter decision about the attempted action.
   - **recommendation**: A specific recommendation for an action to help the customer complete their transaction.
   
3. ### [Send request to extend user session](https://docs.forter.com/login-protection#send-request-to-extend-user-session)  
   Forter's [Login API](https://docs.forter.com/reference/login "Login API") can also be used to extend an idle user's session.

**Login API Request**
   Forter can provide a decision to approve a frictionless login or suggest Multi-Factor Auth if suspicious activity is detected.

4. ### [Send authentication attempts](https://docs.forter.com/login-protection#send-authentication-attempts)  
   The [Authentication result API](https://docs.forter.com/reference/authentication-result "Authentication result API") is used to Inform Forter of authentication results after an MFA was required by a previous Login API request.
   
5. ### [Prepare and Upload Historical Data](https://docs.forter.com/login-protection#prepare-and-upload-historical-data)  
   To ensure the highest level of accuracy for our decisioning model, Forter customizes our model to fit the specific risk profile of each customer by training it with past signup and login data.

6. ### [Complete Integration Tests](https://docs.forter.com/login-protection#complete-integration-tests)  
   The purpose of Forter's integration tests is to ensure that your integration covers all relevant use cases.

7. ### [Deploy to Production](https://docs.forter.com/login-protection#deploy-to-production)  
   Once the integration tests have passed, deploy your code to your production environment with necessary adjustments.

8. ### [Data Validation](https://docs.forter.com/login-protection#data-validation)  
   Once in production, Forter uses a Data Validation tool to execute automated tests across your live data.

9. ### [Listen Mode](https://docs.forter.com/login-protection#listen-mode)  
   In "listen mode", Forter will monitor the production traffic on your site and calibrate our models.

10. ### [Go Live](https://docs.forter.com/login-protection#go-live)  
    Confirm that your production site is handling responses as expected as Forter begins to send decisions and recommendations.
