Skip to content

Evaluate entity

Request

Evaluates an entity against the tenant's configured recommendation rules. The entity is enriched with third-party intelligence data and matched against enabled rules in priority order. Only the first matching production rule applies to the returned recommendation. Any matching preview rule is returned separately in preview_rule for impact analysis without affecting the final decision. If no production rule matches, the recommendation defaults to ALLOW.

Security
risk_access_token
Bodyapplication/jsonrequired
entity_typestringrequired

The type of entity to evaluate.

Value:"ip_address"
Example:"ip_address"
entity_valuestringrequired

The value of the entity to evaluate. When entity_type is ip_address, this must be a valid IPv4 or IPv6 address.

Example:"1.2.3.4"
curl -i -X POST \
  https://api.sbx.transmitsecurity.io/risk/v1/evaluate \
  -H 'Authorization: Bearer <YOUR_JWT_HERE>' \
  -H 'Content-Type: application/json' \
  -d '{
    "entity_type": "ip_address",
    "entity_value": "1.2.3.4"
  }'

Responses

Entity evaluated successfully.

Bodyapplication/json
entity_typestringrequired

The type of entity to evaluate.

Value:"ip_address"
Example:"ip_address"
entitystringrequired

The entity value that was evaluated (echoed back from the request).

Example:"1.2.3.4"
recommendationstringrequired

Recommendation derived from the first matching production rule. Defaults to ALLOW when no production rule matches.

Enum:"ALLOW""TRUST""CHALLENGE""DENY"
Example:"DENY"
matched_ruleobject

The production rule that matched the entity, if any. Only present when a production rule matches.

dataip_enrichment_data (object)required
One of:

Third-party intelligence data used during evaluation. Fields are populated on a best-effort basis; any field may be omitted when the provider does not return a value for the given IP.

preview_ruleobject

Preview rule that would have matched if it were in production mode. Allows you to assess the impact of preview rules before promoting them to production.

Response
{ "entity_type": "ip_address", "entity": "1.2.3.4", "recommendation": "DENY", "matched_rule": { "rule_name": "Block restricted jurisdictions" }, "data": { "country_code": "CN", "asn_id": "AS4134", "organization_name": "Example ISP", "organization_type": "hosting", "ip_timezone": "Asia/Shanghai", "ip_is_vpn": true, "ip_is_anonymizer": false } }