API Documentation
REST • Webhooks • Pre-Auth Decision Engine
API & Integration Blueprint
Integrate deterministic BIN threat scores directly into your transaction authorization deciders with sub-12ms latency.
GET
/v1/intel/{bin_prefix}
< 12ms Edge
Retrieve real-time risk penalties, active threat indicators, and mitigation directives for any 6-digit or 8-digit BIN prefix.
Request Headers
Authorization: Bearer YOUR_FEED_API_KEY
Accept: application/json
Example cURL Request
curl -s -X GET "https://api.preauthintel.com/v1/intel/410040" \
-H "Authorization: Bearer sec_live_99f0a28b..." \
-H "Accept: application/json"
Response Payload (200 OK)
{
"bin": "410040",
"issuer": "CITIBANK, N.A. (COSTCO ANYWHERE)",
"brand": "VISA",
"type": "CREDIT",
"level": "BUSINESS",
"target_merchant": "Airbnb",
"threat_level": "CRITICAL",
"status": "bypass_3ds",
"risk_penalty": 50,
"mentions_24h": 18,
"recommended_action": "ENFORCE_3DS_STEP_UP",
"last_intercepted_at": "2026-10-04T12:00:22Z"
}
BLUEPRINT
Stripe Radar Custom Rules Blueprint
Add this rule inside your Stripe Dashboard → Radar → Rules to step up or block authorizations when compromised BINs are detected:
# Rule 1: Step-Up 3DS for Active Bypass Drops
request_3d_secure if :metadata['4043696_penalty']: > 30
# Rule 2: Hard Block on Critical Underground Drops
block if :metadata['4043696_penalty']: >= 50 and :amount_in_usd: > 100.00
STREAM
Real-Time Webhook Event Stream
Subscribe your backend endpoints to push notifications when adversary channels activate or decay a target BIN prefix:
bin.threat_flagged
Triggered immediately when an underground channel posts a working drop or exploit for a BIN prefix.
bin.velocity_spike
Triggered when carding bot mention frequency exceeds 10 messages within a 60-minute window.
bin.state_decayed
Triggered when mathematical decay lowers threat penalty back to 0 after channel chatter ceases.