Skip to content

Send label

Request

Sends the label to our servers for analysis to improve our recommendation system.

Security
risk_access_token
Bodyapplication/jsonrequired
label_typestringrequired

Type of label to send, which contains additional information that helps to classify the subject as fraudulent or legitimate. The API accepts both the enum values below and the legacy values (KNOWN_MALICIOUS, SUSPECTED_MALICIOUS, KNOWN_LEGIT, UNKNOWN) for backward compatibility.

Enum:"CONFIRMED_FRAUD""SUSPECTED_FRAUD""CONFIRMED_LEGIT""UNDETERMINED"
subjectobjectrequired

Subject of the label

use_casestring

Fraud scenario associated with the label. You can further classify the scenario by providing sub_category and, for supported scenarios, attack_method. For supported values and combinations, see Specify fraud scenarios with labels.

Enum:"ACCOUNT_TAKEOVER""DEVICE_TAKEOVER""FIRST_PARTY_FRAUD""IDENTITY_THEFT""MONEY_MULE""BOT_ATTACK""SYNTHETIC_IDENTITY""SOCIAL_ENGINEERING""NEW_ACCOUNT_FRAUD""CREDENTIAL_STUFFING"
sub_categorystring

Optional refinement of use_case. Valid values depend on the selected use_case. Do not provide this field for MONEY_MULE or CREDENTIAL_STUFFING. For supported values by use case, see Specify fraud scenarios with labels.

Enum:"PHISHING""MALWARE""CREDENTIAL_BREACH""DEVICE_TAKEOVER""SESSION_HIJACKING""RECOVERY_ABUSE""INVESTMENT_SCAM""ROMANCE_SCAM""TECH_SUPPORT_SCAM""PAYMENT_SCAM"
attack_methodstring

Optional attack method associated with the label. Valid values depend on the selected sub_category, or directly on use_case for MONEY_MULE and CREDENTIAL_STUFFING. Do not provide this field for FIRST_PARTY_FRAUD. For supported values and combinations, see Specify fraud scenarios with labels.

Enum:"PHISHING_EMAIL""PHISHING_SMS""PHISHING_VOICE""PHISHING_QR""KEYLOGGER""TROJAN""SPYWARE""BROWSER_MALWARE""COMBO_LIST""PASSWORD_SPRAYING"
sourcestring

Source of the information used to assign the label, such as manual review, customer complaints, chargebacks, another fraud system, automated detection, or law enforcement. For supported values and definitions, see Specify fraud scenarios with labels.

Enum:"MANUAL_REVIEW""CUSTOMER_COMPLAINTS""CHARGEBACKS""OTHER_VENDORS""AUTOMATED_DETECTION""LAW_ENFORCEMENT"
curl -i -X POST \
  https://api.sbx.transmitsecurity.io/risk/v1/label \
  -H 'Authorization: Bearer <YOUR_JWT_HERE>' \
  -H 'Content-Type: application/json' \
  -d '{
    "label_type": "CONFIRMED_FRAUD",
    "subject": {
      "type": "ACTION_ID",
      "value": "a05f8ae1-718f-4c33-a20c-682df281af7c",
      "recommendations": [
        "allow"
      ],
      "is_campaign_confirmed": true
    },
    "use_case": "ACCOUNT_TAKEOVER",
    "sub_category": "PHISHING",
    "attack_method": "PHISHING_EMAIL",
    "source": "MANUAL_REVIEW"
  }'

Responses

Label has been received and stored successfully.

Bodyapplication/json
messagestringrequired
label_idstringrequired

ID of the saved label

labelobjectrequired
afftectedActionIdsArray of stringsrequired
Example:
[ "af819f2b3e2f1b2820077cb09fe92de5769c4e4b24030cf683f4d0b155ac4999", "9b83568185c39e4acb3e5d09176f0a70efdf5c414c2d1d90cb803dfb0b93ec53" ]
Response
{ "message": "string", "label_id": "string", "label": { "label_id": "string", "label_type": "CONFIRMED_FRAUD", "subject": { … }, "use_case": "ACCOUNT_TAKEOVER", "sub_category": "PHISHING", "attack_method": "PHISHING_EMAIL", "source": "MANUAL_REVIEW", "label_timestamp": 1725961384920 }, "afftectedActionIds": [ "af819f2b3e2f1b2820077cb09fe92de5769c4e4b24030cf683f4d0b155ac4999", "9b83568185c39e4acb3e5d09176f0a70efdf5c414c2d1d90cb803dfb0b93ec53" ] }