Forter Accounts API

Signup and login (account takeover) decisions.

OpenAPI Specification

forter-accounts-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: Forter Accounts API
  description: 'Forter is a fraud prevention and digital identity platform for online commerce. Its Core API returns real-time trust decisions for orders, payments, account signups, and logins, and supports chargeback recovery, abuse prevention, and data-privacy workflows.


    GROUNDING NOTE: The paths, HTTP methods, and authentication scheme in this document are grounded in Forter''s public documentation at docs.forter.com (see each operation''s `x-forter-status`). Request and response BODY schemas are MODELED for orientation - Forter does not publish a machine-readable OpenAPI, and the full order/account payloads are large and provisioned per-integration. Treat the schemas below as representative, not authoritative; confirm exact fields against your account''s customized API reference in the Forter Portal.


    ACCESS: Forter is enterprise / contact-sales. Credentials (a per-account site ID and an API key) are provisioned by Forter during onboarding. Requests are sent to a dedicated per-tenant host by prepending your site ID to the API host - `https://{siteId}.api.forter.secure.com/{endpoint}`. The generic host `api.forter.secure.com` shown in the servers block is the documented form; the bare host does not resolve without the site-ID prefix.'
  version: '1.0'
  contact:
    name: Forter
    url: https://www.forter.com
servers:
- url: https://api.forter.secure.com
  description: 'Documented API host. In practice, prepend your account site ID: https://{siteId}.api.forter.secure.com'
security:
- basicAuth: []
tags:
- name: Accounts
  description: Signup and login (account takeover) decisions.
paths:
  /v2/accounts/signup/{accountId}:
    parameters:
    - $ref: '#/components/parameters/AccountId'
    post:
      operationId: submitSignup
      tags:
      - Accounts
      summary: Submit a signup for a decision
      description: Send account registration information at signup to receive a fraud or abuse decision for the new account.
      x-forter-status: Path/method confirmed against docs.forter.com (Signup). Request/response schema MODELED.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AccountEventInput'
      responses:
        '200':
          description: A Forter decision for the signup.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Decision'
        '401':
          $ref: '#/components/responses/Unauthorized'
  /v2/accounts/authentication-result/{loginId}:
    parameters:
    - name: loginId
      in: path
      required: true
      description: A unique identifier for the login / authentication event.
      schema:
        type: string
    post:
      operationId: submitAuthenticationResult
      tags:
      - Accounts
      summary: Submit a login / authentication result for an ATO decision
      description: Send login attempt information to receive an account takeover (ATO) decision. Used to protect the login flow with Forter's identity graph.
      x-forter-status: Path/method confirmed against docs.forter.com (Authentication result). Request/response schema MODELED.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AccountEventInput'
      responses:
        '200':
          description: A Forter account takeover decision.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Decision'
        '401':
          $ref: '#/components/responses/Unauthorized'
components:
  responses:
    Unauthorized:
      description: Missing or invalid credentials (site ID / API key).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  parameters:
    AccountId:
      name: accountId
      in: path
      required: true
      description: A unique identifier for the account.
      schema:
        type: string
  schemas:
    Decision:
      type: object
      description: MODELED representation of a Forter decision response. The real payload includes richer recommendation and reason detail.
      properties:
        forterDecision:
          type: string
          description: The Forter recommendation.
          enum:
          - approve
          - decline
          - not reviewed
          - verification requested
        forterToken:
          type: string
          description: The Forter managed token correlating this event.
        reasonCode:
          type: string
        recommendation:
          type: string
    Error:
      type: object
      description: MODELED error envelope.
      properties:
        status:
          type: string
        message:
          type: string
    AccountEventInput:
      type: object
      description: MODELED subset for signup and login events (registration or authentication details plus connection information).
      properties:
        accountId:
          type: string
        eventTime:
          type: integer
        loginMethod:
          type: string
        accountData:
          type: object
          additionalProperties: true
        connectionInformation:
          type: object
          additionalProperties: true
  securitySchemes:
    basicAuth:
      type: http
      scheme: basic
      description: 'HTTP Basic authentication with your Forter API key as the username (empty password). Requests must also carry the `x-forter-siteid` header (your site ID), an `api-version` header (for example `10.1`), and `Content-Type: application/json`. Credentials are provisioned by Forter during onboarding.'