# API Abuse

## Headless API protection

Castle supports protection of endpoints where client-side code can't be injected, such as desktop apps or REST APIs.

### Real-time blocking

Rules execute in milliseconds to block API abuse inline without noticeable delay.

### Custom definitions

Define API abuse your way using advanced filtering and real-time velocity queries.

### Granular analytics

Leverage BI-grade analytics to expose API abuse and fraud rings at scale.

### Data enrichment

Enriched with device intelligence, risk scores, velocity metrics, and much more.

## Define API abuse using custom logic

Castle lets you use advanced filtering, real-time velocity queries, and custom lists to segment out API abuse with high precision.

- deny

- User Agent Age

- is < 5 min
   
   - and
   
- Proxy IP

- is true
   
   - and
   
- Count of events Get Access Keys

- by ISP
   
   - in the last 15 min
   
   - is > 15
   
   - or
   
- Signals
   
   - include Blocked User Agents

## Action on API abuse in real-time

Rules execute in milliseconds and can be used to adapt the user experience based on risk in real-time.

- deny

- Abuse Score

- is > 90
   
   - and
   
- Disposable Email

- is true
   
   - and
   
- Count events Registration

- by Device Fingerprint
   
   - in the last day
   
   - is > 3
   
   - or
   
- Signals
   
   - include Blocked country

- Add User ID Warned Account Sharers

- Remove User ID Allowed Users

- Send webhook

- https://hooks.zapier.com/hooks/catch/4378238094/ch3dka

- Send to Slack

- #security-alerts

### Real-time decisions

Assessments of data like user count per device or hourly failed logins executed in the blink of an eye.

### Inline blocking

Initiate request blocks or step-up verifications anywhere in your app without disrupting the user experience.

### Alerts & notifications

Ensure your team and users stay informed with triggered Slack notifications or webhooks.

## A holistic view of API abuse

Harness the power of BI-grade analytics to expose API abuse attacks and unravel fraud rings with precision.

### Event Data

| Timestamp            | Policy                            | Event                 | User                          | Location                   | Connection           | Device                    | Lists       | Signals                     |
|----------------------|-----------------------------------|-----------------------|-------------------------------|----------------------------|----------------------|---------------------------|-------------|-----------------------------|
| Sat, Aug 8 07:59:08 | Challenge Medium Abuse Score      | Challenge Requested    | kevin.qfanjul@gmail.com      | Spain, Gijón              | Telefonica de Espana | Chrome on Windows 10      |             | Disposable email domains, New device |
| Sat, Aug 8 07:59:08 | Deny Bad email                   | Registration Attempted | oleg.kalinovskiy75@gmail.com  | Ukraine, Khmelnytskyi     | Kyivstar             | Chrome on Windows 10      |             | Trusted user devices        |
| Sat, Aug 8 07:59:08 | Deny [ScAuth] Attempted Login    | Login Attempted       | themba.ndlovu@gmail.com      | South Africa, Cape Town   | Starlink             | Chrome on Windows 10      |             | Challenged IPs, Timezone Area Mismatch, Multiple Accounts Per Device |
| Sat, Aug 8 07:59:08 | Deny Password Reset Policy        | Password Reset        | priya.sharma@gmail.com       | India, Mumbai             | Jio                  | Chrome on Windows 10      |             | Multiple Accounts Per Device |
| Sat, Aug 8 07:59:08 | Challenge Trusted Device Policy    | Challenge Succeeded   | anton.volkov.2023@gmail.com  | Russian Federation, Chita  | Rostelecom           | Chrome on Windows 10      |             | Disposable email domains, Multiple Accounts Per Device |

## All the data you need to pinpoint API abuse

Every interaction is enriched with comprehensive device intelligence, risk scores, location data, and much more.

### Risk Scores

Out of the box risk scores for account abuse, account takeover, and bot abuse.

### Velocities

Compute personalized signals based on real-time metrics like counts, sums, averages, and more.

### Device fingerprinting

Persistent device identifiers resilient to storage resets and resistant to privacy plug-ins.

### Bot detection

Identify bot actions via bot scores, headless indicators, or velocity and rate limit checks.
