Profile access - API Reference
Profile access
POST
Try it
Send information on an attempt to access or edit a customer profile to receive a fraud decision. Used for account takeover at profile touchpoint, card testing, and digital key use cases. The response may also include recommendations for additional authentication (MFA) and a correlation ID to include with the authentication result.
Credentials
- HTTP Basic: basicAuth
Path Parameters
- id (string, required)
Header Parameters
- api-version (string, required)
- x-forter-siteid (string, required)
Body Parameters
- body (accountAccessRequestRequest, required)
- accessRequestType (string: VIEW_PERSONAL_PREFERENCES | UPDATE_PASSWORD | UPDATE_PAYMENT | UPDATE_PHONE | UPDATE_EMAIL | UPDATE_ADDRESS | REDEEM_ACCOUNT_ASSETS | SHARE_CREDENTIALS | DIGITAL_KEY_ACCESS | DIGITAL_CHECK_IN, nullable)
- accountId (string, required)
- accountOwner (object, required)
- email (string)
- firstName (string)
- lastName (string)
- socialNetworkData (array of objects)
- additionalAccountEventIdentifiers (object)
- additionalInformation (object)
- channelType (string: WEB | PHONE | DYNAMIC_PHONE | MOBILE | MOBILE_IN_STORE | IOS | ANDROID | WAP | STORE | MERCHANT_EMPLOYEE | MAIL_ORDER | AUTOMATIC_RENEWAL_OR_INSTALLMENT_PAYMENT | MERCHANT_INITIATED | UNKNOWN | POS | API_ONLY | PERSONAL_POS | PHONE_LINK, nullable)
- connectionInformation (ConnectionInformation, required)
- eventTime (number, required)
- merchantIdentifiers (object)
- newAddress (object)
- address1 (string)
- city (string)
- country (string)
- savedData (object)
- newEmail (object)
- email (string)
- emailVerification (object)
- newPaymentMethods (object)
- newPhone (object)
- phone (string)
- smsVerified (object)
- originalOrderId (string, nullable)
- passwordUpdateTrigger (string: MERCHANT_POLICY | USER_FORGOT_PASSWORD | LOGGED_IN_USER, nullable)
Responses
200
- Example adaptiveAuthAccountsResponse
- accountId (string, required)
- correlationId (string, required)
- decisionReason (string)
- forterDecision (string: APPROVE | DECLINE | VERIFICATION_REQUIRED | NOT_REVIEWED, required)
- merchantPolicyId (string, required)
- recommendation (string)
- verificationMethod (VerificationMethod)
400 Bad Request (Often missing a required parameter)
401 Unauthorized (No valid API key provided)
404 Not Found (The requested item doesn't exist)
500 Server Error (Something went wrong on Forter's end)
Request Example
curl --request POST \
--url https://api.forter-secure.com/v2/accounts/profile-access/{id} \
--header 'accept: application/json' \
--header 'content-type: application/json' \
--header 'api-version: 10.1' \
--header 'x-forter-siteid: a1b2c3d4e5f6' \
--data-raw '{
"accountId": "e520-ba9a-367-60b",
"accountOwner": {
"email": "john_s@test.com",
"firstName": "John",
"lastName": "Smith",
"socialNetworkData": [
{
"networkName": "FACEBOOK",
"profileId": "10000054564897"
}
]
},
"connectionInformation": {
"customerIP": "10.0.0.127",
"userAgent": "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.2526.73 Safari/537.36"
},
"eventTime": 1415287568000,
"newAddress": {
"address1": "235 Montgomery st.",
"city": "San Francisco",
"country": "US",
"savedData": {
"usedSavedData": true
}
}
// Other fields omitted for brevity
}'
Responses Example
200
{
"accountId": "e520-ba9a-367-60b",
"correlationId": "HGJ7512345H3DE",
"decisionReason": "",
"forterDecision": "",
"merchantPolicyId": "0ee8ba28a8654c659addbae9253b707c",
"recommendation": "",
"verificationMethod": {
"correlationId": "HGJ7512345H3DE",
"status": "FRICTIONLESS",
"statusCode": "100",
"statusMessage": "Verification code sent",
"type": "THREE_DS",
"verificationId": "345H3DEHGJ7512",
"verificationSpecificData": {
"ThreeDS": {},
"email": {},
"phone": {}
}
}
}