Account Opening

The Account Opening API is designed to detect and prevent fake accounts, bots, and synthetic identity abuse before an account is created. It analyzes various attributes including behavioral, device, identity, and velocity signals in real time to assess the trustworthiness of a signup attempt. The API returns a recommended action, enabling businesses to protect their platform from the first user interaction.

Use this endpoint at the moment a user submits your signup form, but before creating the account in your system. By incorporating this check into your signup flow, you can intercept high-risk events and enforce tailored interventions like additional verification or outright blocking.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Body Params
string
required

Unique identifier for this opening event.

string
required

The username that will be associated with the account. Please supply this even if it is the same as the email.

string

needed The full name of the user.

string

needed Your globally unique identifier for registered user accounts. Use this as the persistent user identifier, consistent across Account Integrity APIs.

string
required

The email address that will be associated with the account.

boolean

True if the user successfully completed an email verification (e.g. OTP). False if verification was not performed.

string

The phone number that will be associated with the account.

boolean

True if the user successfully completed a phone verification (e.g. OTP). False if verification was not performed.

date-time
required

The date and time of when the account opening was requested.

Formatted as yyyy-MM-dd'T'HH:mm:ssZ per ISO 8601. See the dates section of the Introduction for more information about date formats.

string
enum
required

needed Method used for authentication.

  • PASSWORD - User provided a password for this login attempt.
  • PASSKEY - User provided a passkey for this login attempt.
  • GOOGLE - User logged in with a Google account.
  • FACEBOOK - User logged in with a Facebook account.
  • APPLE - User logged in with an Apple account.
  • LINKEDIN - User logged in with a LinkedIn account.
  • X - User logged in with an X account.
  • EMAIL_OTP - User logged in with an email one time password.
  • PHONE_OTP - User logged in with a phone one time password.
  • OTHER - User logged in with a different method from the ones listed above.
string
enum
required

Indicating the role of the account; one of BUYER, SELLER, BUSINESS, OTHER.

Allowed:
device
object

needed Device & fingerprint context.

string
enum

needed The channel through which the account integrity event was initiated.

  • WEB - Event originated from a web browser.
  • MOBILE_APP - Event originated from a native mobile application.
Allowed:
tags
array of strings

A list of attributes or short descriptors associated with the account opening.

tags
Headers
int64

The team id requested for authentication. This should normally be omitted, as it's only relevant when auth credentials allow requests for multiple teams.

string
enum

Override the decision response for testing Account Integrity API integrations.
This header allows you to specify the exact decision you want returned, bypassing normal
decision processing. Only valid for test teams.

Available actions:

  • ALLOW - Let the event proceed normally. No additional checks are needed.
  • DENY - Reject the event outright and do not persist or apply the change.
  • STEP_UP - Pause the flow and require extra verification (for example, MFA or a challenge).
  • FLAG - Allow the event. Signifyd will use this flag in downstream flows like checkout to apply added scrutiny where needed.
  • ALERT - Allow the event but immediately notify the user of unusual activity (for example, via email or SMS).
Allowed:
Responses

Language
Credentials
Basic
base64
:
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json