Skip to main content
POST
Score a subject (phone and/or IP) synchronously

Headers

Idempotency-Key
string
Maximum string length: 128

Body

application/json
subject
object
required
context_id
string
context
object
client_reference
string
Maximum string length: 256
options
object

Response

Scored (possibly degraded — see degraded_sources; never 5xx for upstream outages)

score_id
string
required

Opaque score identifier, "sc_" followed by 32 lowercase hex characters. The prefix is pinned (v1.0.3) — clients may rely on it.

tier
enum<string>
required
Available options:
verify,
assess,
bureau
score_version
string
required
score
integer
required
Required range: 0 <= x <= 100
score_type
string
required
Allowed value: "ranking"
band
enum<string>
required
Available options:
minimal,
low,
medium,
high,
critical
Available options:
allow,
watch,
investigate,
step_up_auth,
challenge,
block
suppressed
object[]
required
disclosure
string
required
degraded_sources
string[]
required

Capabilities that answered this request on reduced evidence — the same names as components[].component and the health endpoint's capabilities map. Empty means every evaluated capability answered at full fidelity.

score_basis
string
coverage
enum<string>

Reporting-density context, never a score modifier — see scoring/COVERAGE.md

Available options:
strong,
partial,
thin
subject
object

Identity resolution of network assets only — never subscriber identity (RSP-4)

components
object[]
primary_risk_factor
object
benign_exclusions
string[]
context_applied
object
shadow
object

Present only when shadow_version requested (VER-2)

client_reference
string
cluster_id
string

Bureau tier only — stable infrastructure-cluster id (spec 4.3)

latency_ms
integer