Account Login

The Account Login API is designed to detect and prevent account takeover (ATO) attempts in real time by analyzing device, session, and behavioral signals during the login process. It returns a recommended action enabling targeted interventions that stop fraud without harming trusted users.

Use this endpoint at the moment a user submits their login credentials, whether the login attempt succeeds or fails. Calling the API for both outcomes allows Signifyd to detect patterns like credential stuffing, phishing attempts, and anomalous behavior across devices and IPs. By embedding this check into your login flow, you can step up or block high--risk login attempts while maintaining a seamless experience for trusted users.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Body Params
string
required

Unique identifier for this login event.

string
enum
required

needed Method used for authentication.

  • PASSWORD - User provided a password for this login attempt.
  • PASSKEY - User provided a passkey for this login attempt.
  • GOOGLE - User logged in with a Google account.
  • FACEBOOK - User logged in with a Facebook account.
  • APPLE - User logged in with an Apple account.
  • LINKEDIN - User logged in with a LinkedIn account.
  • X - User logged in with an X account.
  • EMAIL_OTP - User logged in with an email one time password.
  • PHONE_OTP - User logged in with a phone one time password.
  • OTHER - User logged in with a different method from the ones listed above.
string
enum
required

The result of the authentication attempt.

  • SUCCESS - User provided a valid login for this account.
  • FAILURE - User provided an invalid login for this account.
Allowed:
date-time
required

The date and time when the current login was attempted.

Formatted as yyyy-MM-dd'T'HH:mm:ssZ per ISO 8601. See the dates section of the Introduction for more information about date formats.

date-time

The date and time of the user's previous successful login.

Formatted as yyyy-MM-dd'T'HH:mm:ssZ per ISO-8601.

userAccount
object
required

Details about the user account that was being attempted to login to.

device
object

needed Device & fingerprint context.

string
enum

needed The channel through which the account integrity event was initiated.

  • WEB - Event originated from a web browser.
  • MOBILE_APP - Event originated from a native mobile application.
Allowed:
tags
array of strings

A list of attributes or short descriptors associated with the login event.

tags
Headers
int64

The team id requested for authentication. This should normally be omitted, as it's only relevant when auth credentials allow requests for multiple teams.

string
enum

Override the decision response for testing Account Integrity API integrations.
This header allows you to specify the exact decision you want returned, bypassing normal
decision processing. Only valid for test teams.

Available actions:

  • ALLOW - Let the event proceed normally. No additional checks are needed.
  • DENY - Reject the event outright and do not persist or apply the change.
  • STEP_UP - Pause the flow and require extra verification (for example, MFA or a challenge).
  • FLAG - Allow the event. Signifyd will use this flag in downstream flows like checkout to apply added scrutiny where needed.
  • ALERT - Allow the event but immediately notify the user of unusual activity (for example, via email or SMS).
Allowed:
Responses

Language
Credentials
Basic
base64
:
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json