openapi: 3.0.3 info: title: Forter Accounts API description: 'Forter is a fraud prevention and digital identity platform for online commerce. Its Core API returns real-time trust decisions for orders, payments, account signups, and logins, and supports chargeback recovery, abuse prevention, and data-privacy workflows. GROUNDING NOTE: The paths, HTTP methods, and authentication scheme in this document are grounded in Forter''s public documentation at docs.forter.com (see each operation''s `x-forter-status`). Request and response BODY schemas are MODELED for orientation - Forter does not publish a machine-readable OpenAPI, and the full order/account payloads are large and provisioned per-integration. Treat the schemas below as representative, not authoritative; confirm exact fields against your account''s customized API reference in the Forter Portal. ACCESS: Forter is enterprise / contact-sales. Credentials (a per-account site ID and an API key) are provisioned by Forter during onboarding. Requests are sent to a dedicated per-tenant host by prepending your site ID to the API host - `https://{siteId}.api.forter.secure.com/{endpoint}`. The generic host `api.forter.secure.com` shown in the servers block is the documented form; the bare host does not resolve without the site-ID prefix.' version: '1.0' contact: name: Forter url: https://www.forter.com servers: - url: https://api.forter.secure.com description: 'Documented API host. In practice, prepend your account site ID: https://{siteId}.api.forter.secure.com' security: - basicAuth: [] tags: - name: Accounts description: Signup and login (account takeover) decisions. paths: /v2/accounts/signup/{accountId}: parameters: - $ref: '#/components/parameters/AccountId' post: operationId: submitSignup tags: - Accounts summary: Submit a signup for a decision description: Send account registration information at signup to receive a fraud or abuse decision for the new account. x-forter-status: Path/method confirmed against docs.forter.com (Signup). Request/response schema MODELED. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AccountEventInput' responses: '200': description: A Forter decision for the signup. content: application/json: schema: $ref: '#/components/schemas/Decision' '401': $ref: '#/components/responses/Unauthorized' /v2/accounts/authentication-result/{loginId}: parameters: - name: loginId in: path required: true description: A unique identifier for the login / authentication event. schema: type: string post: operationId: submitAuthenticationResult tags: - Accounts summary: Submit a login / authentication result for an ATO decision description: Send login attempt information to receive an account takeover (ATO) decision. Used to protect the login flow with Forter's identity graph. x-forter-status: Path/method confirmed against docs.forter.com (Authentication result). Request/response schema MODELED. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AccountEventInput' responses: '200': description: A Forter account takeover decision. content: application/json: schema: $ref: '#/components/schemas/Decision' '401': $ref: '#/components/responses/Unauthorized' components: responses: Unauthorized: description: Missing or invalid credentials (site ID / API key). content: application/json: schema: $ref: '#/components/schemas/Error' parameters: AccountId: name: accountId in: path required: true description: A unique identifier for the account. schema: type: string schemas: Decision: type: object description: MODELED representation of a Forter decision response. The real payload includes richer recommendation and reason detail. properties: forterDecision: type: string description: The Forter recommendation. enum: - approve - decline - not reviewed - verification requested forterToken: type: string description: The Forter managed token correlating this event. reasonCode: type: string recommendation: type: string Error: type: object description: MODELED error envelope. properties: status: type: string message: type: string AccountEventInput: type: object description: MODELED subset for signup and login events (registration or authentication details plus connection information). properties: accountId: type: string eventTime: type: integer loginMethod: type: string accountData: type: object additionalProperties: true connectionInformation: type: object additionalProperties: true securitySchemes: basicAuth: type: http scheme: basic description: 'HTTP Basic authentication with your Forter API key as the username (empty password). Requests must also carry the `x-forter-siteid` header (your site ID), an `api-version` header (for example `10.1`), and `Content-Type: application/json`. Credentials are provisioned by Forter during onboarding.'