
> **ℹ️ Info**
> 
 If you are a minFraud Legacy customer, please refer to our
[minFraud Legacy documentation](/minfraud/minfraud-legacy).

If you are a Proxy Detection Legacy customer, please refer to our
[Proxy Detection Legacy documentation](/minfraud/proxy-detection).


minFraud is our transaction risk API, consisting of the minFraud Score, Insights
and Factors services.

## Guides

<!-- prettier-ignore-start -->




- heading: "Evaluate a Transaction"
  url: "/minfraud/evaluate-a-transaction"
  text: "Start evaluating your transactions by installing, configuring, and using a minFraud client API."
- heading: "Report Transactions"
  url: "/minfraud/report-a-transaction"
  text: "Use the Report Transaction API to report chargebacks, false positives, suspected fraud, or spam/abuse."
- heading: "Integrate Device Tracking"
  url: "/minfraud/track-devices"
  text: "Capture more data and catch more fraud using our device tracking libraries."


<!-- prettier-ignore-end -->

## Resources

<!-- prettier-ignore-start -->




- heading: "API Documentation"
  url: "/minfraud/api-documentation"
  text: "Learn about each minFraud service's request and response objects."
- heading: "Release Notes"
  url: "/minfraud/release-notes"
  text: "Review minFraud release notes to understand changes to the minFraud API."
- heading: "Knowledge Base"
  url: "https://support.maxmind.com/knowledge-base/minfraud-web-services"
  text: "Consult our knowledge base for articles about using minFraud."


<!-- prettier-ignore-end -->

## [minFraud Release Notes](/minfraud/release-notes/)
> **ℹ️ Info**
> 

[Sign up to be notified](https://comms.maxmind.com/minfraud-rss-release-notes)
whenever a new minFraud release note is posted.

## [Evaluate a Transaction](/minfraud/evaluate-a-transaction/)
<p>Evaluating a transaction consists of setting up device tracking, creating an
object that contains the details of the transaction, and then submitting the
transaction to the minFraud service for evaluation.</p>
## Implementation
<p>MaxMind offers and highly recommends using official client libraries to access
our minFraud services. If you cannot or do not wish to use our client libraries,
please review our [minFraud API Documentation page](/minfraud/api-documentation)
for details on our JSON API.</p>

## [minFraud Alerts](/minfraud/alerts/)
<p>After initial scoring, we continue to monitor transactions with risk scores less
than or equal to 10 for another 24 hours. If we receive new information related
to these transactions that leads to a transaction having a re-calculated risk
score greater than or equal to 75, we send out a minFraud Alert.</p>
<p>You can receive minFraud Alerts via email or webhook.</p>
## Receive minFraud Alerts via email
<p>You can set an email where you would like to receive minFraud Alerts through the
[minFraud Alert configuration screen in your account portal](https://www.maxmind.com/en/accounts/current/minfraud/alerts/settings)
(login required).</p>

## [minFraud API Documentation](/minfraud/api-documentation/)
> **ℹ️ Info**
> 
 If you are a [minFraud Legacy](/minfraud/minfraud-legacy/)
customer, please see our
[What's New in minFraud Score, minFraud Insights, and minFraud Factors](/minfraud/whats-new-in-minfraud-score-and-minfraud-insights/)
document for a summary of the changes. 
## Overview
<p>To learn more about the minFraud services and to purchase credits, please visit
the
[minFraud Overview page](https://www.maxmind.com/en/solutions/fraud-prevention/overview).
To better understand the differences between each minFraud service, review our
[minFraud Service Comparison page](https://www.maxmind.com/en/solutions/fraud-prevention/plans-pricing)
and the
[API response body documentation](/minfraud/api-documentation/responses#response-body).</p>
## OpenAPI Specification
<p>The
[minFraud OpenAPI specification](https://github.com/maxmind/openapi/blob/main/bundled/minfraud.yaml)
([raw file](https://raw.githubusercontent.com/maxmind/openapi/main/bundled/minfraud.yaml))
describes the minFraud web services, including transaction reporting,
dispositions, and alert webhooks. Use the raw file with API tools and code
generators.</p>

## [minFraud API Requests](/minfraud/api-documentation/requests/)
## Authorization and Security
<p>The HTTP <code>Authorization</code> header is required for authorization. The username is
your
[MaxMind account ID](https://www.maxmind.com/en/accounts/current/license-key).
The password is your
[MaxMind license key](https://www.maxmind.com/en/accounts/current/license-key).</p>
> **⚠️ Warning**
> 
 You must be approved for a trial or purchase credit for
use with our web services in order to receive an account ID and license key.

<p>We use
[basic HTTP authentication](https://en.wikipedia.org/wiki/Basic_access_authentication).
The APIs which require authentication are only available via HTTPS. Always use
HTTPS, so that your credentials are never transmitted unencrypted. If you
attempt to access this service via HTTP, you will receive a <code>403 Forbidden</code> HTTP
response.</p>

## [minFraud API Responses](/minfraud/api-documentation/responses/)
## Headers
<p>The <code>Content-Type</code> for a successful response varies based on the service as
outlined below:</p>


<div class="table">
  <table>
    <thead>
      <tr>
        <th>Service</th>
        <th>Content-Type</th>
      </tr>
    </thead>
    <tbody>
      <tr>
        <td>Score</td>
        <td>
          `application/vnd.maxmind.com-minfraud-score+json; charset=UTF-8;
          version=2.0`
        </td>
      </tr>
      <tr>
        <td>Insights</td>
        <td>
          `application/vnd.maxmind.com-minfraud-insights+json; charset=UTF-8;
          version=2.0`
        </td>
      </tr>
      <tr>
        <td>Factors</td>
        <td>
          `application/vnd.maxmind.com-minfraud-factors+json; charset=UTF-8;
          version=2.0`
        </td>
      </tr>
    </tbody>
  </table>
</div>

<p>Errors may be returned with the <code>Content-Type</code> set to
<code>application/vnd.maxmind.com-error+json; charset=UTF-8; version=2.0</code>. If this is
the case, then the body of the response contains a JSON document with two keys,
<code>code</code> and <code>error</code>. See the
[Errors](/minfraud/api-documentation/responses/#errors) section for more
details.</p>

## [minFraud Legacy Web Service API](/minfraud/minfraud-legacy/)
> **Note**
> 
 We have made a number of data changes to the minFraud
Legacy Standard and Premium, and GeoIP Legacy City and Insights (formerly Omni)
web services. Please see our
[blog post](https://blog.maxmind.com/data-changes-to-geoip-legacy-and-minfraud-legacy-web-services-in-may-2022/)
for more information, and how to prepare. 
>  **New minFraud APIs are available:** Please see
[What’s New in minFraud Score, minFraud Insights, and minFraud Factors](/minfraud/whats-new-in-minfraud-score-and-minfraud-insights)
and our
[minFraud Insights, minFraud Score, and minFraud Factors API documentation](/minfraud).
To learn more about the minFraud Insights, minFraud Score, and minFraud Factors
services and to purchase credits, please
[visit the minFraud Overview page](https://www.maxmind.com/en/solutions/fraud-prevention/overview).

<p>The minFraud web service is available using a simple URI-based API. To use this
service, you must have a valid
[MaxMind license key](https://www.maxmind.com/en/accounts/current/license-key).</p>

## [Normalizing Email Addresses for minFraud](/minfraud/normalizing-email-addresses-for-minfraud/)
<p>When providing an email address as an input to the minFraud services, you can
provide it either as plain text or as an MD5 hash.</p>
<p>If you provide the email as an MD5 hash, it’s important that you normalize it
before generating the hash. Otherwise minor, inconsequential differences could
cause minFraud to consider it a different address.</p>
<p>Our [client APIs](/minfraud/api-documentation/#client-apis) do this for you if
you enable sending the MD5 hash. This is the recommended way to do this.</p>

## [Proxy Detection Legacy Web Service](/minfraud/proxy-detection/)
> **⚠️ Warning**
> 
 To learn more about the risk associated with a particular
IP address, use the [minFraud Score service](/minfraud/evaluate-a-transaction/).
This service provides the IP Risk Score, a replacement for the proxyScore. To
identify anonymous IP addresses in support of geotargeting and ad serving
environments, we recommend using the
[GeoIP Anonymous IP database](https://www.maxmind.com/en/geoip-anonymous-ip-database).

<p>The proxy detection web service provides a score measuring the risk associated
with an IP address. It is called the IP risk score in our current minFraud
services.
[Learn more about the IP risk score on our knowledge base.](https://support.maxmind.com/knowledge-base/articles/minfraud-ip-risk-score)</p>

## [Report a transaction](/minfraud/report-a-transaction/)
<p>Reporting transactions as chargebacks, suspected fraud, spam/abuse, and/or false
positive (not fraud) to MaxMind helps us detect about 10-50% more fraud and
reduce false positives for you.</p>
<p>You can report a transaction manually through the account portal’s
[web form](https://www.maxmind.com/en/accounts/current/minfraud/report-transactions)
or your
[minFraud Transactions page](https://www.maxmind.com/en/accounts/current/minfraud-interactive/transactions).
This guide will show you how to programmatically report a transaction using our
official client libraries.</p>
## Implementation
<p>MaxMind offers and highly recommends using
[official client libraries](/minfraud/evaluate-a-transaction/#links-to-maxmind-client-apis)
to access the Report Transaction API. If you cannot or do not wish to use our
client libraries, please review our
[minFraud Report Transaction API Documentation](#api-documentation) for details
on our JSON API.</p>

## [Testing minFraud in the MaxMind Sandbox](/minfraud/sandbox-environment/)
MaxMind maintains a Sandbox environment so that you can do basic integration
tests with the web services. In order to set up a Sandbox account you must
already have a paid account, and you must be an account administrator.
[Learn how to set up a Sandbox account on our Knowledge Base.](https://support.maxmind.com/knowledge-base/articles/set-up-a-maxmind-sandbox-account)

Once you have your Sandbox account set up and activated, follow the steps below.

## Generate a License Key for the Sandbox
In order to test the web services in the Sandbox environment, you will need to
generate a license key from your Sandbox account.
[Learn how to generate a license key on our Knowledge Base.](https://support.maxmind.com/knowledge-base/articles/generate-a-maxmind-license-key)

The process is the same for your Sandbox account, but you must login to your
Sandbox account
[[direct link](https://sandbox.maxmind.com/en/accounts/current/license-key),
Sandbox account login required] rather than your regular MaxMind account.

## Build your integration
<p>Consult our [quick start guide](/minfraud/evaluate-a-transaction) or our
[list of client APIs](/minfraud/evaluate-a-transaction#links-to-maxmind-client-apis)
to develop your integration.</p>

## [Track Devices](/minfraud/track-devices/)
<p>The Device Tracking Add-On for the minFraud services identifies devices as they
move across networks and enhances the ability of the minFraud services to detect
fraud. If a fraudster changes proxies while they are using your site or app, or
between sessions, you may observe an increased risk score in the minFraud output
associated with their transactions.</p>
<p>We may increase the risk score if we detect order velocity on the device. We
also return a
[Device ID](/minfraud/api-documentation/responses#schema--response--device__id)
in minFraud Insights and Factors so that you can do your own modeling around
Device ID.</p>

## [What’s New in minFraud Score, minFraud Insights, and minFraud Factors](/minfraud/whats-new-in-minfraud-score-and-minfraud-insights/)
<p>MaxMind minFraud Score, minFraud Insights, and minFraud Factors provide a modern
RESTful way to access the minFraud data services. This document outlines the
major changes for developers when using these services.</p>
<p>For more information about ongoing enhancements to the minFraud services, see
our [release notes](/minfraud/release-notes).</p>
## General Changes
<p>The minFraud web services now follow REST principles.</p>
<p>Authentication is done using
[basic authentication](https://en.wikipedia.org/wiki/Basic_access_authentication)
over a TLS connection rather than passing the license key as a query parameter.</p>

## [Working with Transaction Dispositions](/minfraud/working-with-transaction-dispositions/)
<p>With minFraud Interactive, customers can create Custom Rules that are used to
assign a disposition to every transaction received in a minFraud request. Custom
Rules can set a transaction’s disposition to <code>accept</code>, <code>reject</code>, or
<code>manual_review</code>. For more information on Custom Rules and Dispositions, see the
documentation on our
[knowledge base](https://support.maxmind.com/knowledge-base/articles/use-custom-rules-and-dispositions-minfraud-maxmind).</p>
<p>After transactions are received, customers can use the account portal to review
all transactions dispositioned as <code>manual_review</code>. Transactions can then either
be <code>accept</code>ed or <code>reject</code>ed, and/or have a note added.
[Learn how to use the account portal to do manual review on our knowledge base.](https://support.maxmind.com/knowledge-base/articles/review-a-minfraud-transaction).
In order for these manual updates made in the account portal to be useful, they
need to find their way back into customers’ systems. The Dispositions API allows
customers to get a list of the manual updates and notes made to their
transactions.</p>

