Fraud Decision Engine You Control
You define what to measure, what counts as suspicious, how to classify the threat, and when to block. Every fraud rule adjustable per project, per fraud class, per fraud pattern your business actually faces.Define your metrics
Set your signals
Control your thresholds
Update without code

300M+
BotBye:\Requests Analyzed Daily1M+
BotBye:\Bots Detected Every Day10+
BotBye:\Attack Types Protected AgainstHow Rule-Based Fraud Detection Works
Step 1
Event
Send any user action — login, registration, transaction, or custom event. You choose which actions to score.| ID | IP Address | Event | Date |
|---|---|---|---|
| login | 16:44:3312.08.2026 | ||
| register | 16:44:2112.08.2026 | ||
| reset_password | 16:44:1912.08.2026 | ||
| withdrawal | 16:44:1812.08.2026 |
Step 2
Metrics
The engine builds a real-time behavioral profile for every account, IP, and device. You always know what’s being measured and why.events_1hMetric
ip_24hMetric
devices_1hMetric
Step 3
Signals
Tune the thresholds to fit your risk model. Multiple signals fire at once, each adding a weighted score to its fraud class. A weak signal alone won’t block a real user, but together they catch attacks with fewer false positives.multi_accountingSignal
account_sharingSignal
Step 4
Decision
One response, ready to enforce: ALLOW, CHALLENGE, or BLOCK — with full breakdown of scores and triggered signals.botFraud class
Block0.9
Challenge0.7
Why Risk Scoring Works Better
Adaptive Fraud Detection
Metrics, signals, fraud classes, thresholds – everything is configured per project. Different products can run entirely different risk profiles suited to their specific threat model.iGaming
Allowed38.01K
Declined27
Total38.04K
E-Commerce
Allowed12.31K
Declined168
Total12.48K
Real-Time Metrics
Risk profiles update with every event. The engine always reflects the current state — enabling sub-second detection of attacks as they happen.Dynamic Configuration
Create, update, or delete any metric or signal: changes take effect immediately. No redeployment, no engineering tickets, no downtime.ip_velocity
Signalgeo_distance
System Metricasn_reputation
SignalBuilt-in + Custom Rules
Battle-tested signals for common attacks work out of the box. As you learn your traffic, add custom metrics and signals for any threat specific to your business.Built-in
brute_force
impossible_travel
credential_stuffing
multi_accounting
CustomAdd
non_legal_ip
trouble_stuffing
ip_duplicate
promo_abuse
same_users
Weighted Risk Scoring
Each signal adds a score you define to its fraud class. Example: Brute force adds 0.4 to ATO score. Credential stuffing adds 0.35. Combined ATO score: 0.75 → exceeds block threshold (0.7) → BLOCK.multi_accountingSignal
account_sharingSignal
excessive_usageSignal
Custom Fraud Classes
Three built-in classes Bot, ATO, and Abuse work out of the box. Need more? Create any fraud class that fits your business logic, name it however you want, and assign its own thresholds and signals.botFraud class
Block0.9
Challenge0.7
reportedFraud class
Block0.6
Challenge0.3
unfilteredFraud class
Block0.8
Challenge0.7
Computed Metrics
Some fraud patterns can't be captured by counters alone. Computed metrics combine stored data with the current request in real time to detect complex patterns like impossible travel.impossible travel
800km–15min
Self-Learning Scoring
Every request the engine evaluates also updates its metrics. One integration, two outcomes: real-time protection and continuously improving accuracy.See the Fraud Rules Engine in Action
Easy for developers to integrate
Developers can get started quickly with our robust developer features including intuitive APIs and extensive documentation.Server-side integration
SDKs for Java, Node.js, Kotlin, PHP, and more. Validate tokens and enforce decisions with a few lines of code.
Read the docsProtection for Every Threat
Keep your websites, apps, and APIs secure with instant protection from day one and full control as you scale.FAQ
How does a risk scoring engine differ from traditional rule-based fraud detection?
Can I configure metrics and signals without writing code?
What fraud types does the engine detect out of the box?
How does score accumulation reduce false positives?
What is a composite key and why does it matter?
How quickly can I integrate the risk scoring engine?
Does the engine work with custom event types?
What is the pricing for the risk scoring engine?