Risk API
Risk endpoints exposed by the Devotel CPaaS API Base path:/api/v1/risk/score
Endpoint count: 1
title: “Decode the composite verdict” description: “How the fused SMS-pumping, URL-reputation, Verify fraud, and voice-biometrics signals resolve into one 0-100 score, a band, and an advisory action.”
Decode the composite verdict
Score a destination before you commit a send or a call. Fraud and trust-operations teams wire this endpoint into their pre-send gate; callers also run it ahead of a high-value voice dispatch. The endpoint is read-only and advisory — it sends nothing, routes nothing, and enforces nothing — so you decide how to act on the recommendation it returns. The composite score folds four detectors into one verdict. The live SMS-pumping / artificial-traffic check and (when you passmessage_body) the outbound link-reputation scan run on the platform side; your own Verify Fraud Guard and Voice Biometrics scores pass in as verify_signal / voice_biometrics_signal and are folded into the same number. The composite is the worst present channel score, so a bad link or a flagged destination cannot be washed out by a clean aggregate. Band cutoffs reuse the SMS-pumping scorer’s thresholds, so a “high” verdict means the same thing whether the signal came from one channel or the fused whole.
Score a destination with a body scan
The Node SDK has no typed helper for this surface yet — the genericrequest() keeps auth, retries, and the { data, meta } envelope identical. Copy either form as written and substitute your own destination:
Request
low, 25–49 elevated, 50–79 high, 80–100 critical. Bands map to actions as critical → block, high → review, and elevated | low → allow. No pass-through scores and no message_body returns a clean score: 0 / band: "low" — the empty ask never reads as a threat. The per-channel channels array tells you which detector drove the verdict, so the composite is never a black box.
Unified cross-channel Trust & Fraud risk score for a destination
POST /api/v1/risk/scorestring
Stripe-style idempotency token. Pass a stable, client-generated value (1-255 chars) to dedupe retries on transient timeouts. The same key+credential+path replays the original response for 24h on 2xx (5min on 4xx, 30s on 5xx). Returns 409 if a concurrent request with the same key is already in flight; replayed responses include the
Idempotency-Replay: true response header.string (enum: true|false)
Sandbox opt-in for Clerk-session-authenticated requests. Set to
true to route the call through the test-mode pipeline: no real provider delivery, no credits deducted, response meta.test_mode: true. Ignored for live API keys (dv_live_sk_*) — server-to-server clients must use a test-prefixed key (dv_test_sk_*) to exercise sandbox. Test-prefixed keys unconditionally enable sandbox regardless of this header.