# Profile access

## POST

Try it

Send information on an attempt to access or edit a customer profile to receive a fraud decision. Used for account takeover at profile touchpoint, card testing, and digital key use cases. The response may also include recommendations for additional authentication (MFA) and a correlation ID to include with the authentication result.

### Credentials

- **HTTP Basic:** basicAuth

### Path Parameters

- **id** (string, *required*)

### Header Parameters

- **api-version** (string, *required*)
- **x-forter-siteid** (string, *required*)

### Body Parameters

- **body** (accountAccessRequestRequest, *required*)
  - **accessRequestType** (string: VIEW_PERSONAL_PREFERENCES | UPDATE_PASSWORD | UPDATE_PAYMENT | UPDATE_PHONE | UPDATE_EMAIL | UPDATE_ADDRESS | REDEEM_ACCOUNT_ASSETS | SHARE_CREDENTIALS | DIGITAL_KEY_ACCESS | DIGITAL_CHECK_IN, nullable)
  - **accountId** (string, *required*)
  - **accountOwner** (object, *required*)
    - **email** (string)
    - **firstName** (string)
    - **lastName** (string)
    - **socialNetworkData** (array of objects)
  - **additionalAccountEventIdentifiers** (object)
  - **additionalInformation** (object)
  - **channelType** (string: WEB | PHONE | DYNAMIC_PHONE | MOBILE | MOBILE_IN_STORE | IOS | ANDROID | WAP | STORE | MERCHANT_EMPLOYEE | MAIL_ORDER | AUTOMATIC_RENEWAL_OR_INSTALLMENT_PAYMENT | MERCHANT_INITIATED | UNKNOWN | POS | API_ONLY | PERSONAL_POS | PHONE_LINK, nullable)
  - **connectionInformation** (ConnectionInformation, *required*)
  - **eventTime** (number, *required*)
  - **merchantIdentifiers** (object)
  - **newAddress** (object)
    - **address1** (string)
    - **city** (string)
    - **country** (string)
    - **savedData** (object)
  - **newEmail** (object)
    - **email** (string)
    - **emailVerification** (object)
  - **newPaymentMethods** (object)
  - **newPhone** (object)
    - **phone** (string)
    - **smsVerified** (object)
  - **originalOrderId** (string, nullable)
  - **passwordUpdateTrigger** (string: MERCHANT_POLICY | USER_FORGOT_PASSWORD | LOGGED_IN_USER, nullable)

### Responses

**200**
- **Example adaptiveAuthAccountsResponse**
  - **accountId** (string, *required*)
  - **correlationId** (string, *required*)
  - **decisionReason** (string)
  - **forterDecision** (string: APPROVE | DECLINE | VERIFICATION_REQUIRED | NOT_REVIEWED, *required*)
  - **merchantPolicyId** (string, *required*)
  - **recommendation** (string)
  - **verificationMethod** (VerificationMethod)

**400** Bad Request (Often missing a required parameter)

**401** Unauthorized (No valid API key provided)

**404** Not Found (The requested item doesn't exist)

**500** Server Error (Something went wrong on Forter's end)

### Request Example

```bash
curl --request POST \
  --url https://api.forter-secure.com/v2/accounts/profile-access/{id} \
  --header 'accept: application/json' \
  --header 'content-type: application/json' \
  --header 'api-version: 10.1' \
  --header 'x-forter-siteid: a1b2c3d4e5f6' \
  --data-raw '{
    "accountId": "e520-ba9a-367-60b",
    "accountOwner": {
      "email": "john_s@test.com",
      "firstName": "John",
      "lastName": "Smith",
      "socialNetworkData": [
        {
          "networkName": "FACEBOOK",
          "profileId": "10000054564897"
        }
      ]
    },
    "connectionInformation": {
      "customerIP": "10.0.0.127",
      "userAgent": "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.2526.73 Safari/537.36"
    },
    "eventTime": 1415287568000,
    "newAddress": {
      "address1": "235 Montgomery st.",
      "city": "San Francisco",
      "country": "US",
      "savedData": {
        "usedSavedData": true
      }
    }
    // Other fields omitted for brevity
}'
```

### Responses Example

**200**
```json
{  
  "accountId": "e520-ba9a-367-60b",  
  "correlationId": "HGJ7512345H3DE",  
  "decisionReason": "",  
  "forterDecision": "",  
  "merchantPolicyId": "0ee8ba28a8654c659addbae9253b707c",  
  "recommendation": "",  
  "verificationMethod": {  
    "correlationId": "HGJ7512345H3DE",  
    "status": "FRICTIONLESS",  
    "statusCode": "100",  
    "statusMessage": "Verification code sent",  
    "type": "THREE_DS",  
    "verificationId": "345H3DEHGJ7512",  
    "verificationSpecificData": {  
      "ThreeDS": {},  
      "email": {},  
      "phone": {}  
    }  
  }  
}
```
