Sign Up Protection - Overviews

Account Protection

Overview

Not every user who tries to create an account on your site has good intentions. Some are malicious actors attempting to create multiple accounts—whether for account aging and laying the groundwork for future fraud attacks or for abusing new account related discounts. Stopping abuse and fraud at the entry point protects your account ecosystem in multiple ways. It helps prevent losses from users exploiting promotions, ensures compliance with your terms and conditions, and allows you to measure meaningful customer metrics accurately—giving you greater control over your ecosystem.

The Signup API helps prevent fraudulent account creation by providing approve/decline decisions in real time when a user attempts to register. Implementing the Signup API is seamless, as outlined in the process below.

Primary Use Cases

There are a number of ways you can utilize the account sign up protection offered by this API. The Account Sign Up API can be used to enforce the following scenarios:

Integration Steps

  1. Front-end Integration

In your dedicated Forter portal, you will receive a JavaScript snippet for both sandbox and production. For native mobile apps, you will receive links to download Forter's Native SDKs. You'll paste the JS script on the appropriate pages of your website or call mobile SDK methods on relevant mobile app screens so that it can load and asynchronously collect important behavioral data from your customer. The script or mobileUID generated by the mobile SDK will also generate a unique token for each user on your site that should be included in the Account Sign Up API Request Body.

  1. Send signup request for decision

The Signup API is used for approving / declining account creation attempts by customers or end users.

Signup API Request

Data points collected are common signup properties:

{
  "accountId": "e520-ba9a-367-60b",
  "eventTime": 1415287568000,
  "connectionInformation": {
    "customerIP": "10.0.0.127",
    "userAgent": "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.2526.73 Safari/537.36",
    "forterTokenCookie": "2315688945984"
  },
  "channelType": "WEB",
  "accountData": {
    "personalDetails": {
      "firstName": "John",
      "lastName": "Smith",
      "email": "john_s@test.com"
    },
    "created": 1415273168,
    "type": "BUSINESS",
    "merchantAccountStatus": "open",
    "status": "ACTIVE"
  }
}

Signup API Response

The response body will include the accountId, correlationId, a decision, as well as parameters for the verification method and a recommendation for further identification if needed (i.e. MFA or supplementary identification documents). Upon receipt of the response, you can leverage the forterDecision and recommendation parameters in the response body to curate the customer journey or block bad actors from creating bogus accounts on your site.

Key Fields:

{
  "forterDecision": "VERIFICATION_REQUIRED",
  "recommendation": "EMAIL_VERIFICATION",
  "accountId": "e520-ba9a-367-60b",
  "correlationId": "HGJ7512345H3DE",
  "verificationMethod": {
    "correlationId": "HGJ7512345H3DE"
  }
}
{
  "forterDecision": "APPROVE",
  "recommendation": "",
  "accountId": "e520-ba9a-367-60b",
  "correlationId": "HGJ7512345H3DE",
  "verificationMethod": {}
}
  1. Send authentication attempts

The Authentication result API is used to Inform Forter of authentication results after an MFA was required by a previous Signup API request, using the provided correlation ID. While no decision is provided on this request, it is required in order to ensure optimal customer experience as well as continuously improving the decision model.

Authentication result API Request

Key Fields:

{
  "accountId": "e520-ba9a-367-60b",
  "eventTime": 1415287568000,
  "connectionInformation": {
    "customerIP": "10.0.0.127",
    "userAgent": "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.2526.73 Safari/537.36",
    "forterTokenCookie": "2315688945984"
  },
  "channelType": "WEB",
  "additionalAuthenticationMethod": {
    "verificationOutcome": "SUCCESS",
    "correlationId": "87363864834"
  }
}

Authentication Result API Response As this API is only used to provide Forter's model's additional information, the decision returned will always be "NOT_REVIEWED". Supplementary parameters like correlationId and accountId are also returned in the API response.

  1. Send account status updates

The Account status API is used to provide Forter model's additional information: indication of accounts closed by the merchant or accounts that changed in status that reflect agreement or disagreement with Forter's sign up decision (use / ignore the decision). The Account status API is only intended to provide Forter with additional details and does NOT return a new decision. Rather, the response will always be "NOT_REVIEWED".

Account Status API Request

Main data points are:

{
  "accountId": "e520-ba9a-367-60b",
  "eventTime": 1415287568000,
  "status": "SUSPENDED",
  "statusChangeReason": "user violation of coupon abuse policy",
  "connectionInformation": {
    "customerIP": "10.0.0.127",
    "userAgent": "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.2526.73 Safari/537.36",
    "forterTokenCookie": "2315688945984"
  },
  "type": "BUSINESS",
  "merchantAccountStatus": "open",
  "statusChangeBy": "MERCHANT_ADMIN"
}
  1. Prepare and Upload Historical Data

To ensure the highest level of accuracy for our decisioning model, Forter customizes our model to fit the specific risk profile of each of our customers. We achieve this by training the model with your past signup and login data in order to provide you with better accuracy from Day 1.

  1. Complete Integration Tests

The purpose of Forter's integration tests is to make sure that your integration covers all relevant use cases, while still in the sandbox or test environment. Each use case may need a different combination of attributes and values.

To make sure you have covered each of the use cases we expect in your integration, please go through the test scenario list in the Integration Tests section of Portal. For each, you'll need to create the scenario in your sandbox site that will generate a call to Forter's API. Then, select the corresponding API request that Forter received and click Run to verify that the sample request meets the criteria.

  1. Deploy to Production

Once the Integration tests have passed, and you've reviewed any gaps with a Forter Implementation Engineer please, deploy your code to your production environment, with two critical adjustments:

  1. Replace your Site ID and secret key with your production credentials.
  2. Update your Javascript snippet and Mobile SDKs to use your production Site ID and the production hash keys, if relevant.

Please note that this does not yet complete your integration. Until Forter has switched your site to Live (after Data Validation and Listen Mode), all Forter decisions will return "Not Reviewed".

  1. Data Validation

Once in production, Forter uses a Data Validation tool to execute a set of automated tests across your live data in aggregation. The test outputs are daily reports that validate the accuracy and completeness of the production data we receive from you. You can monitor this output in Forter Portal under Integration Center Tools.

We recommend checking the report daily to identify any failed tests, which will prevent you from moving forward to Listen Mode.

  1. Listen Mode

In "listen mode", we will monitor the production traffic on your site and calibrate our models before we begin to provide you with decisions. This is a critical stage to ensure you meet your KPIs, and usually lasts around 7-14 days. Your Implementation Engineer will update you on the specific timeline for your integration.

During this time, Forter will continue to return "Not Reviewed" decisions in the API response.

  1. Go Live

As Forter begins to send decisions and recommendations, confirm that your production site is handling responses as expected.