Session Details Response Structure

Session Details

This section constitutes the basic session level details such as challenge details, pressure levels, whether the attacker surpassed basic defenses, etc.

Field NameDescriptionExample ValuesApplicable Product
solved

When a session's risk level does not qualify it for transparent mode (no challenge) it is shown an interactive challenge. In that case, this field's value indicates if the challenge was successfully solved or not.

If it was in transparent mode, the field value for a valid session is true.

true, falseArkose Protect
sessionA unique token for the Arkose Labs session. A session is the whole experience from solution load to verification.A unique token, e.g.
3595d2c014d3c5f01.1116018803,
or null
Arkose Detect
Arkose Protect
session_createdAn ISO 8601 UTC timestamp signifying the time the session was createde.g.
2019-07-15T02:45:13+00:00,
or null
Arkose Detect
Arkose Protect
check_answerAn ISO 8601 UTC timestamp signifying the time that the Enforcement Challenge user supplied answered were evaluatede.g.
2019-07-15T02:45:13+00:00,
or null
Arkose Protect
verifiedAn ISO 8601 UTC timestamp signifying the time that the request to the verify endpoint was made.e.g.
``2019-07-15T02:45:13+00:00
Arkose Detect
Arkose Protect
attemptedWhether the user attempted to solve the Enforcement Challenge, or not.true, falseArkose Protect
security_level

A number that indicates the security level used for this session.

Be aware that security_level can have a null value - usually because the session was an audio mode session. Audio mode does not use security_level.

A security level, e.g. 20Arkose Protect
session_is_legitIndicates if Arkose Labs certifies there are no telltales of non-legitimate activity in the session.true, falseArkose Detect
Arkose Protect
previously_verifiedIndicates if a session has already been verifiedtrue, falseArkose Detect
Arkose Protect
session_timed_outIndicates if a session timed out before it was solvedtrue, falseArkose Detect
Arkose Protect
suppress_limitedIndicates if the session qualified for low security, but failed verification. Low security is when a session has qualified to run in transparent mode, or use a no wrong answer enforcement challenge, such as the pick your favorite color challenge.true, falseArkose Protect
theme_arg_invalid

Whether the theme arg setting at verification matched the original theme arg passed in at session setup.

A theme arg is a parameter passed by a customer to Arkose Labs. It requests a security tier or UX test mode.

true, falseArkose Protect
suppressedSuppressed is the old name for transparent mode. This field shows if the the user was offered transparent mode.true, falseArkose Protect
punishable_actionedPunishable is an attack mitigation tactic, which randomly fails verification attempts, even if the response was correct. This field indicates if punishable was activated.true, falseArkose Protect
telltale_userUID for a combination of telltales that identify a particular bad user or organization.A string such as 999b-fwh,
or null
Arkose Detect
Arkose Protect
failed_low_sec_validationIndicates that the intention was to offer the user a low security session, but they failed to qualify for it when the verification was attempted.true, falseArkose Protect
lowsec_errorAn identifier showing why a user was denied a low security session."user_credits", "rate_limit_local", "validation_checks", "rate_limit_global", or nullArkose Detect
Arkose Protect
lowsec_level_deniedThe low security level that was denied to the user.A security level, e.g. 5Arkose Detect
Arkose Protect
uaThe User Agent string for the user that interacted with the EC.
"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7)
AppleWebKit/537.36 (KHTML, like Gecko)
Chrome/92.0.4515.159 Safari/537.36“
Arkose Detect
Arkose Protect
ip_rep_listAn identifier which specifies which IP reputation database this IP address has been seen at."tor", "sfs_tor", "sfs", or nullArkose Detect
Arkose Protect
optional

An object containing optional return values such as client_encrypted_mode_key or get_pass values.

Also, relevant data being sent to Arkose Labs via our accepted methods (see: Data Exchange (Requires Support login)) appears in this object.

The specific keys and values inside this object vary based on implementation

[{"blob":
"lHpwagBqx3JOI7t9Ka0KUdIeHZbIjAYPPB72k
Du2Zb5BwNiC6qJx5gS0f5c3EzcZ9d"}
]
, or null
Arkose Detect
Arkose Protect
game_number_limit_reachedGame number limit is an optional setting that restricts the number of attempts a user can have at solving the EC. This field can show if the user reached the number of attempts allowed.true, falseArkose Protect
user_language_shownShows the language code of the language in which the challenge was presented to the user.A string such as “en“ or nullArkose Protect
telltale_listThe list of telltales that were identified as possible candidates during a session.A string e.g. "999b-fwh", or nullArkose Detect
Arkose Protect
device_id
[Early Access]
Note: You must request that Arkose turn on device_id for your account. Otherwise, its value will always be null
device_id can identify changes a user's device if those two devices are distinguishable based on collected fingerprints.
device_id isn't comprised of uniquely identifiable attributes and so can't be used for situations when, for example, a user switched from one iPhone 14 to another while keeping all the settings the same.
A string containing a hash value or null
challenge_typeThe type of challenge that the end-user solved.A string e.g. "audio", "transparent", "visual" or nullArkose Detect
Arkose Protect

User Preference Field

This field contains information about the session set by its user.

Field NameDescriptionExample ValuesApplicable Product
timezone_offsetThe timezone offset from UTC.e.g. 1000 or nullArkose Detect
Arkose Protect