Salv risk API

Risks levels are assigned to persons according to configured risk rules. It is up to client how to interpret each particular level. Risk rules are configured in Salv UI. Person risk is scored every time one of the following triggering events occurs: - the person is created - the person is updated - a transaction is added to the person - a monitoring alert is created for the person - the status of a monitoring alert of the person is updated - the status of a screening alert of the person is changed to any true positive status - the status of a screening alert of the person is changed from any of true positive statuses to non true positive status Person risk scoring happens in the background and the service does not guarantee any time frame for it. Risk levels can be overridden by client operators for any particular person. They would need to choose one of the preconfigured override reasons, which are also configured in Salv UI.

OpenAPI Specification

salv-risk-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: Salv AML alert risk API
  description: '# Introduction

    Welcome to the Salv AML API documentation.


    The Salv API is built on HTTP. Our API is RESTful. It has predictable resource URLs. It returns HTTP response codes to indicate errors. It also accepts and returns JSON in the HTTP body. You can use your favorite HTTP/REST library for your programming language to use Salv API.


    API definition to import into Postman can be downloaded at https://docs.salv.com/api/public.yaml

    '
  version: 1.0.9
  contact:
    name: Support
    email: support@salv.com
  x-logo:
    url: salv.svg
    altText: Salv API
servers:
- url: https://{environment}.salv.com/api/
  variables:
    environment:
      default: app
      enum:
      - app
      - demo
      description: 'Select environment:

        * `app` - Production

        * `demo` - Sandbox

        '
security:
- OAuth2:
  - aml
tags:
- name: risk
  description: "Risks levels are assigned to persons according to configured risk rules. It is up to client how\nto interpret each particular level.\n\nRisk rules are configured in Salv UI.\n\nPerson risk is scored every time one of the following triggering events occurs:\n- the person is created\n- the person is updated\n- a transaction is added to the person\n- a monitoring alert is created for the person\n- the status of a monitoring alert of the person is updated\n- the status of a screening alert of the person is changed to any true positive status\n- the status of a screening alert of the person is changed from any of true positive statuses to non true positive status\n\nPerson risk scoring happens in the background and the service does not guarantee any time frame for it.\n\nRisk levels can be overridden by client operators for any particular person. They would need to choose one \nof the preconfigured override reasons, which are also configured in Salv UI.\n"
  x-displayName: Risks
paths:
  /v1/persons/{personId}/risks:
    get:
      tags:
      - risk
      summary: Fetch person risk factors
      operationId: getPersonRisks
      parameters:
      - name: personId
        in: path
        description: ID of person
        required: true
        schema:
          type: string
          minLength: 1
      responses:
        '200':
          description: successful operation
          content:
            application/json:
              schema:
                $ref: models.yaml#/components/schemas/ApiPersonRisks
components:
  securitySchemes:
    OAuth2:
      type: oauth2
      description: 'In order to use the API, you need to generate client credentials using [Salv UI](https://demo.salv.com/credentials).

        Never share your secret keys. Keep them guarded and secure.


        We use OAuth2 client credentials flow to issue our API tokens.

        By default our API tokens have expiration time of 50 years, so effectively they never expire.

        Please do not make any assumptions about the content of the access_token.

        At the moment we use a JWT token, but it can change to any other string with the future updates.


        An API token can be invalidated using Salv UI by deleting the client credentials that were used to generate the token.


        Please make sure you only request it once per reasonable amount of time,

        as `oauth/token` endpoint has a rate limit of **10 requests per minute** per IP address.


        | Environment | Token URL |

        |-------------|-----------|

        | Production | `https://app.salv.com/oauth/token` |

        | Sandbox | `https://demo.salv.com/oauth/token` |


        Use the token URL matching your selected server environment.

        '
      flows:
        clientCredentials:
          tokenUrl: https://app.salv.com/oauth/token
          x-tokenUrl-sandbox: https://demo.salv.com/oauth/token
          scopes:
            aml: Can use AML API
x-tagGroups:
- name: General
  tags:
  - changelog
  - getting-started
  - data-upload
  - aml
  - note
  - webhooks
  - custom-list-record
  - custom-list-usable-field-public
- name: Monitoring
  tags:
  - monitoring-overview
  - monitoring-checks
  - alert
- name: Screening
  tags:
  - screening-overview
  - screening-checks
  - screening-searches
  - screening-list-groups
  - screening-alerts
- name: Risks
  tags:
  - risk
- name: Alert management
  tags:
  - alerts
  - manual-alerts
- name: Deprecated
  tags:
  - unresolved-alerts