# Castle

**Canonical:** https://apis.io/providers/castle/  
**Website:** https://castle.io  
**APIs profiled:** 1

Castle is a fraud and account-abuse prevention platform that stops bots, credential stuffing, account takeover, and multi-accounting through behavioral analysis and device fingerprinting — without CAPTCHAs or puzzles for legitimate users. Developers integrate a client-side SDK (browser and mobile) that generates a short-lived request token, then call Castle's backend Risk API and Filter API to score authentication and transaction events in real time. Castle returns machine-learning risk scores and signals (bot, proxy/VPN, residential proxy, impossible travel, device reputation) that drive a policy rules engine, Lists, and webhooks. It serves security and trust-and-safety teams across gaming, fintech, marketplaces, and SaaS.

## Kin Score — 44.0 / 100 (developing)

Scored 2026-08-30 under rubric 0.17.2. Trend: flat (+0.0 from 44.0).

| Facet | Score |
|---|---|
| Discoverability | 75.9 |
| Contract Quality | 42.7 |
| Governance | 18.2 |
| Contract Governance | 18.2 |
| Operational Transparency | 42.1 |
| Developer Ergonomics | 57.7 |
| Commercial Clarity | 32.9 |
| Access Clarity | 32.9 |

## Agent readiness — 23.6 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | bearer |
| Idempotency | no |
| Error Semantics | documented |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | yes |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (1)

- **Castle API** — Castle's REST API for real-time fraud and abuse detection. The Risk API scores authenticated user events (login, transaction, profile update), the Filter API scores anonymous/pr...

## MCP servers (1)

- **Castle MCP Server**

## Security (3)

- **Castle Authentication** — http · 1 scheme
- **Castle Domain Security** — TLSv1.3 · HSTS · DMARC
- **Castle Trust Center** — SOC 2, GDPR

## Tags

Company, Security, Fraud Prevention, Bot Detection, Device Fingerprinting, Account Takeover, Risk Scoring, Identity

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/castle/). Scores are computed from the provider's own public artifacts under a published rubric.
