Castle
Castle is a fraud and account-abuse prevention platform that stops bots, credential stuffing, account takeover, and multi-accounting through behavioral analysis and device fingerprinting — without CAPTCHAs or puzzles for legitimate users. Developers integrate a client-side SDK (browser and mobile) that generates a short-lived request token, then call Castle's backend Risk API and Filter API to score authentication and transaction events in real time. Castle returns machine-learning risk scores and signals (bot, proxy/VPN, residential proxy, impossible travel, device reputation) that drive a policy rules engine, Lists, and webhooks. It serves security and trust-and-safety teams across gaming, fintech, marketplaces, and SaaS.
Castle publishes 1 API on the APIs.io network. Tagged areas include Company, Security, Fraud Prevention, Bot Detection, and Device Fingerprinting.
The Castle catalog on APIs.io includes 1 event-driven AsyncAPI specification.
Castle’s developer surface includes documentation, API reference, getting-started guide, support, engineering blog, pricing, signup flow, and 25 more developer resources.
API Rating
APIs
Castle API
Castle's REST API for real-time fraud and abuse detection. The Risk API scores authenticated user events (login, transaction, profile update), the Filter API scores anonymous/pr...
MCP Servers
castle-mcp.yml
MCP SERVEREvent Specifications
Castle Webhooks
ASYNCAPIResources
Get Started 5
Portal, sign-up, and the first successful call
Documentation 2
Reference material describing how the API behaves
Agent Surfaces 3
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 7
Pagination, idempotency, versioning, errors, and events
Scroll for all 7
Build 3
SDKs, sample code, and the tooling you integrate with
Access & Security 4
Authentication, authorization, and security posture
Operate 3
Status, limits, changes, and where to get help
Commercial 3
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API