Verify API Response Fields and Examples
The Verify API returns a JSON object made up of the top-level objects below. session_details is always present; the rest appear depending on the products and features enabled for the account.
| Top-level object | Description |
|---|---|
session_details | Information about the session itself |
fingerprint | Browser, device and user-preference characteristics |
ip_intelligence | Data derived from the session IP address |
session_risk | Risk band, category and triggered telltales |
agent_trust | Agent detection and Web-Bot-Auth verification |
device_id | Combined device identity, risk and history |
proof_of_work | Proof of Work outcome |
email_intelligence | Email risk assessment and velocity counts |
aggregations | IP velocity counts |
data_exchange | Data Exchange blob status |
mics_verdict | Mobile integrity check results |
Session Characteristics (session_details)
session_details)These fields contain information about the session itself.
| Field Name | Description | Example Values | Applicable Component |
|---|---|---|---|
solved | When a session's risk level does not qualify it for transparent mode (no challenge) it is shown an interactive challenge. In that case, this field's value indicates if the challenge was successfully solved or not. If it was in transparent mode, the field value for a valid session is true. | true, false | Enforcement |
session | A unique token for the Arkose Labs session. A session is the whole experience from solution load to verification. | A unique token, e.g. 3595d2c014d3c5f01.1116018803 | Detection Enforcement |
session_created | An ISO 8601 UTC timestamp signifying the time the session was created. | e.g. 2019-07-15T02:45:13+00:00, or null | Detection Enforcement |
check_answer | An ISO 8601 UTC timestamp signifying the time that the Enforcement Challenge user supplied answers were evaluated. | e.g. 2019-07-15T02:45:13+00:00, or null | Detection Enforcement |
verified | An ISO 8601 UTC timestamp signifying the time that the request to the verify endpoint was made. | e.g. 2019-07-15T02:45:13+00:00 | Detection Enforcement |
attempted | Whether the user attempted to solve the Enforcement Challenge, or not. | true, false | Detection Enforcement |
security_level | A number that indicates the security level used for this session. Be aware that security_level can have a null value — usually because the session was an audio mode session. Audio mode does not use security_level. | A security level, e.g. 20 | Enforcement |
session_is_legit | Indicates if Arkose Labs certifies there are no telltales of non-legitimate activity in the session. | true, false | Detection Enforcement |
previously_verified | Indicates if a session has already been verified. | true, false | Detection Enforcement |
session_timed_out | Indicates if a session timed out before it was solved. Note: the default timeout value / token lifespan is 30 minutes. | true, false | Detection Enforcement |
suppress_limited | Indicates if the session qualified for low security, but failed verification. Low security is when a session has qualified to run in transparent mode, or use a no wrong answer enforcement challenge, such as the pick your favorite color challenge. | true, false | Enforcement |
theme_arg_invalid | Whether the theme arg setting at verification matched the original theme arg passed in at session setup. A theme arg is a parameter passed by a customer to Arkose Labs. It requests a security tier or UX test mode. | true, false | Enforcement |
suppressed | Suppressed is the old name for transparent mode. This field shows if the user was offered transparent mode. | true, false | Enforcement |
punishable_actioned | Punishable is an attack mitigation tactic, which randomly fails verification attempts, even if the response was correct. This field indicates if punishable was activated. | true, false | Enforcement |
telltale_user | The winning telltale from the list of telltales that were identified as possible candidates (telltale_list field) during a session. | A string such as 999b-fwh, or null | Detection Enforcement |
telltale_origin | Indicates the source configuration of a telltale_user. | A string such as 999b-fwh, or null | Detection Enforcement |
failed_low_sec_validation | Indicates that the intention was to offer the user a low security session, but they failed to qualify for it when the verification was attempted. | true, false | Enforcement |
lowsec_error | An identifier showing why a user was denied a low security session. | "user_credits", "rate_limit_local", "validation_checks", "rate_limit_global", or null | Detection Enforcement |
lowsec_level_denied | The low security level that was denied to the user. | A security level, e.g. 5, or null | Detection Enforcement |
ua | The User Agent string for the user that interacted with the EC. | e.g. "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" | Detection Enforcement |
ip_rep_list | An identifier which specifies which IP reputation database this IP address has been seen at. | "tor", "sfs_tor", "sfs", or null | Detection Enforcement |
optional | An object containing optional return values such as client_encrypted_mode_key or get_pass values. Also, relevant data being sent to Arkose Labs via our accepted methods (see Data Exchange, requires Support login) appears in this object. The specific keys and values inside this object vary based on implementation. | e.g. {"blob": "lHpwagBqx3JOI7t9Ka0KUdIeHZbIjAYPPB72kDu2Zb5BwNiC6qJx5gS0f5c3EzcZ9d"}, or null | Detection Enforcement |
game_number_limit_reached | Game number limit is an optional setting that restricts the number of attempts a user can have at solving the EC. This field can show if the user reached the number of attempts allowed. | true, false | Enforcement |
user_language_shown | Shows the language code of the language in which the challenge was presented to the user. | A string such as "en", or null | Enforcement |
telltale_list | The list of telltales that were identified as possible candidates during a session. | An array of strings e.g. ["999b-fwh"], or null | Detection Enforcement |
challenge_type | The type of challenge that the end-user solved. | A string e.g. "audio", "transparent", "visual", "pow", "pow+visual", "pow+audio", or null | Detection Enforcement |
device_id | Device ID returned from the detection hub. | A string, or null | Detection Enforcement |
stateless_device_id | An object containing the Stateless Device ID and its version, plus the previous ID and version. See the stateless_device_id object section below. | An object, or null | Detection Enforcement |
stateless_device_id object
stateless_device_id objectReturned inside session_details.
| Field Name | Description | Example Values | Applicable Component |
|---|---|---|---|
device_id | The Stateless Device ID. | A string, e.g. a91cd4e726f8b3051d6e4a7c9f2b8d3e | Detection Enforcement |
device_id_version | Version of the Stateless Device ID. | A string, e.g. 2.0 | Detection Enforcement |
device_id_previous | Previous Stateless Device ID. | A string, e.g. 3f5a7c9e1b2d4f6a8c0e2b4d6f8a1c3e | Detection Enforcement |
device_id_previous_version | Version of the previous Stateless Device ID. | A string, e.g. 1.2 | Detection Enforcement |
Fingerprint (fingerprint)
fingerprint)The following sections (Browser Characteristics, Device Characteristics, User Preferences) are fields containing information that identify the browser, device, etc. the session ran on.
Browser Characteristics (fingerprint.browser_characteristics)
fingerprint.browser_characteristics)These fields contain information about the browser the session ran on.
| Field Name | Description | Example Values | Applicable Component |
|---|---|---|---|
browser_name | The name of the browser the user was using. | A string, e.g. Chrome or null | Detection Enforcement |
browser_version | The version of the browser the user was using. | A version number, e.g. 92.0.4515.159 or null | Detection Enforcement |
color_depth | The color depth of the device used for the session. | A number, e.g. 24 or null | Detection Enforcement |
session_storage | Whether session storage was available or not. | true, false | Detection Enforcement |
indexed_database | Whether the browser uses any indexed database API. | true, false | Detection Enforcement |
canvas_fingerprint | The canvas fingerprint value of the browser. | e.g. 1652956012 or null | Detection Enforcement |
Device Characteristics (fingerprint.device_characteristics)
fingerprint.device_characteristics)These fields contain information about the device the session ran on.
| Field Name | Description | Example Values | Applicable Component |
|---|---|---|---|
operating_system | The operating system used on the device. | e.g. Windows or null | Detection Enforcement |
operating_system_version | The version of the operating system used on the device. | e.g. XP or null | Detection Enforcement |
screen_resolution | The current screen resolution of the device. | e.g. [1920,1080] or null | Detection Enforcement |
max_resolution_supported | The maximum supported screen resolution of the device. | e.g. [1920,1080] or null | Detection Enforcement |
behavior | Whether the device / browser supports the addBehavior method. Note that addBehavior is considered obsolete with Windows 10. | true, false | Detection Enforcement |
cpu_class | The CPU class identifier of the device. | e.g. X86 or null | Detection Enforcement |
platform | The platform the device belongs to. | e.g. MacIntel or null | Detection Enforcement |
touch_support | Whether the device has touch support or not. | true, false | Detection Enforcement |
hardware_concurrency | The hardware concurrency support of the device. | e.g. 8 or null | Detection Enforcement |
ja4_hash | TLS client fingerprint used to identify applications/browsers. | e.g. t13d6912h1_8b2139ff7677_c50a3655fff1 or null | Detection Enforcement |
User Preferences (fingerprint.user_preferences)
fingerprint.user_preferences)This field contains information about the session set by its user.
| Field Name | Description | Example Values | Applicable Component |
|---|---|---|---|
timezone_offset | The timezone offset from UTC, in minutes. | e.g. 1000 or null | Detection Enforcement |
IP Intelligence (ip_intelligence)
ip_intelligence)These fields contain information related to and derived from the IP address associated with the session.
| Field Name | Description | Example Values | Applicable Component |
|---|---|---|---|
timezone | The timezone the session was originated from. | A string, e.g. America/Los_Angeles or null | Detection Enforcement |
user_ip | The IP address of the device used for the session. | An IP address, e.g. 199.220.42.206, or null | Detection Enforcement |
is_tor | Indicates if the IP is suspected of being a TOR connection (either active or previously hosted TOR nodes and exist). | true, false | Detection Enforcement |
is_vpn | Indicates if the IP is suspected of being a VPN connection. For example, it has been on a VPN and can include data center ranges. | true, false | Detection Enforcement |
is_proxy | Indicates if this IP address is suspected to be a proxy. | true, false | Detection Enforcement |
proxy_type | The specific type of proxy service detected for the IP address. | anonymous, transparent, corporate, consumer-privacy, public, edu, data center, not a proxy | Detection Enforcement |
country | Country the User IP belongs to. | A string, e.g. US or null | Detection Enforcement |
region | State/Region that the IP belongs to. | A string, e.g. California or null | Detection Enforcement |
city | The city the IP belongs to. | A string, e.g. Fremont or null | Detection Enforcement |
isp | The Internet Service Provider name. | A string, e.g. AT&T U-verse or null | Detection Enforcement |
public_access_point | Whether the IP address belongs to education and research institutions, corporates, or public WiFi such as hotel lobby, coffee shop, etc. | true, false | Detection Enforcement |
connection_type | Indicates how the IP address is connected to the internet. | A string, e.g. WiFi or null | Detection Enforcement |
latitude | The latitude coordinates of the device used for the session. Returned as a string. | e.g. "37.52809906" or null | Detection Enforcement |
longitude | The longitude coordinates of the device used for the session. Returned as a string. | e.g. "-121.97319794" or null | Detection Enforcement |
asn | Autonomous System Number (ASN). | An int, e.g. 14618 or null | Detection Enforcement |
network_info_rtt | Estimated effective round-trip time of the current connection, in milliseconds. | An int, e.g. 50 or null | Detection Enforcement |
Session Risk (session_risk)
session_risk)This object contains risk data for the session derived from triggered telltales.
| Field Name | Description | Example Values | Applicable Component |
|---|---|---|---|
risk_category | The type of threat detected on a session (standard bot, advanced bot, fraud farm, custom). | A string e.g. BOT-STD, BOT-ADV, FRD-FRM or CUSTOM | Detection Enforcement |
risk_band | The classification of a session as low / medium / high risk based on the max value from the custom and global risk scores. | A string e.g. LOW, MEDIUM or HIGH | Detection Enforcement |
global | An object containing 2 subfields, score & telltales.score — a value between 0 and 100 representing the risk associated with the session based on the global telltales that triggered on a session.telltales — list of global telltales triggered, each with the subfields name & weight. | {"score": 10, "telltales": [{"name": "g-reputation-recent-abuse-proxy", "weight": 10}]} | Detection Enforcement |
custom | An object containing 2 subfields, score & telltales.score — a value between 0 and 100 representing the risk associated with the session based on the customer telltales that triggered on a session.telltales — list of custom telltales triggered, each with the subfields name & weight. | {"score": 100, "telltales": [{"name": "outdated-browser-yandex-2", "weight": 7}]} | Detection Enforcement |
score and weight are both returned as numbers, not strings.
Agent Trust (agent_trust)
agent_trust)This object contains information about agent trust detection and the Web-Bot-Auth verification outcome for the session.
| Field Name | Description | Example Values | Applicable Component |
|---|---|---|---|
detected | Whether the session was classified as an agent trust client. | true, false | Enforcement |
detection_source | Which detection path identified the agent.
| "agentic_detection_service", “web_bot_auth", “corroborated" | Enforcement |
agent | Agent metadata. Present only when detected is true, otherwise null | {"name":"CaludeBot"}, null | Enforcement |
agent.name | Canonical name of the detected agent. Present only when detected is true. Falls back to the agent's operator URI when a canonical name can't be resolved. | "ClaudeBot", "GPTBot", "Atlas", "Fellou", "PerplexityBot", "https://openai.com" | Enforcement |
web_bot_auth | Outcome of RFC 9421 Web-Bot-Auth header verification captured at setup-session. This is an independent signal from detected / agent — a verified web_bot_auth payload with detected: false is valid, since it is cryptographic proof of identity without a matching heuristic allowlist entry. | {...}, null | Enforcement |
web_bot_auth.provided | Whether WBA headers were present on the setup-session request. | true, false | Enforcement |
web_bot_auth.agent | Bare URI of the bot operator's JWKS directory origin. | "https://openai.com", null | Enforcement |
web_bot_auth.key_id | RFC 7638 thumbprint of the signing key used to sign the request. | "NzbLsXh8uDCcd-6MNwXF4W_7noWXFZAfHkxZsRGC9Xs", null | Enforcement |
web_bot_auth.signature_verified | Whether the RFC 9421 signature cryptographically verified. | true, false | Enforcement |
web_bot_auth.signature_fail_reason | Reason verification failed; null on success. | "bad_signature", "missing_key", "directory_unreachable", "malformed_input", "signature_expired", "unsupported_profile", null | Enforcement |
Device ID (device_id)
This object combines the Stateful and Stateless Device IDs with device-level risk and history.
| Field Name | Description | Example Values | Applicable Component |
|---|---|---|---|
arkose_id | Composite key of the Stateful and Stateless IDs. | A string, e.g. f83be5d914c7a2069e5f8b1d4a3c6e9f | Detection Enforcement |
confidence_score | Confidence in the uniqueness of the arkose_id. Returned as a number. | e.g. 99.986305 | Detection Enforcement |
device_first_seen | An ISO 8601 UTC timestamp for when the device was first seen. | e.g. 2025-03-22T08:15:44Z | Detection Enforcement |
device_last_seen | An ISO 8601 UTC timestamp for when the device was last seen. | e.g. 2026-01-09T11:37:21Z | Detection Enforcement |
device_spoofing_detected | Whether the current user has been detected spoofing their device. | true, false | Detection Enforcement |
risk_band | Risk band of the device. | A string | Detection Enforcement |
risk_score | Risk score of the device. | A number | Detection Enforcement |
risk_insights | Risk insights for the device. | An array of strings | Detection Enforcement |
stateful_device_id | The Stateful Device ID attributed to this user. | e.g. 8dd4a9dc-81de-4c3d-a685-b8eb546b382b | Detection Enforcement |
stateful_challenge_bypassed | Whether the current challenge was bypassed. | true, false | Detection Enforcement |
stateful_challenges_bypassed | Number of challenges the user has been allowed to bypass since their last solve. | An int, e.g. 1 | Detection Enforcement |
stateful_change_reasons | Reasons why a challenge may have been presented. | An array of strings | Detection Enforcement |
stateless_device_id | The current Stateless Device ID. | A string | Detection Enforcement |
stateless_device_id_version | Version of the Stateless Device ID. | e.g. 2.0 | Detection Enforcement |
stateless_device_id_previous | Previous Stateless Device ID. | A string | Detection Enforcement |
stateless_device_id_previous_version | Version of the previous Stateless Device ID. | e.g. 1.2 | Detection Enforcement |
For Further detailsSee Stateless Device ID and Stateful Device ID (needs Zendesk authentication).
Stateful Device ID (stateful_device_id)
stateful_device_id)This object will be removed in the future. The fields it returns are also available in the device_id object, prefixed with stateful_. For New integrations, please read from device_id objects.
Proof of Work (proof_of_work)
proof_of_work)| Field Name | Description | Example Values | Applicable Component |
|---|---|---|---|
challenged | Indicates that Proof of Work was enabled for the session. | true, false | Enforcement |
attempted | Indicates that the user submitted an attempt at Proof of Work. | true, false | Enforcement |
passed | Indicates that the Proof of Work attempt was passed by the user. | true, false | Enforcement |
difficulty_level | Indicates the difficulty level of the Proof of Work. | A string, or null | Enforcement |
transparent | Indicates that no UI was shown to the user. | true, false | Enforcement |
For Further detailsSee Proof of Work (Beta Preview) (needs Zendesk authentication).
Email Intelligence (email_intelligence)
email_intelligence)Returned when Email Intelligence is enabled and an email address is supplied with the session.
| Sub-object | Contains |
|---|---|
email_assessment | The risk verdict for the email address, plus domain enrichment and handle analysis |
detumbled_email_stats | Character and typing-distance statistics for the detumbled handle |
domain_stats | Character and typing-distance statistics for the domain |
total_email_counts | Velocity counts for the email address |
detumbled_email_unique_counts | Unique-value velocity counts for the detumbled address |
detumbled_email_instance_counts | Instance velocity counts for the detumbled address |
deenumerated_email_unique_counts | Unique-value velocity counts for the deenumerated address |
domain_instance_counts | Velocity counts for the domain |
error | Error message if Email Intelligence could not be evaluated. Omitted on success |
email_assessment
email_assessment| Field Name | Description | Example Values |
|---|---|---|
email_address | The email address supplied with the session. | [email protected] |
detumbled_email_address | The address with tumbling (e.g. plus-addressing, dots) removed. | [email protected] |
deenumerated_email_address | The address with trailing enumeration removed. | [email protected] |
suggested_action | The recommended action for this email address. | e.g. email_no_risk |
email_risk_score | Risk score for the email address. | A number, e.g. 0 |
email_domain | The domain part of the address. | gmail.com |
email_handle_length | Length of the handle. | An int, e.g. 9 |
is_tumbled_email | Whether the address is tumbled. | true, false |
is_enumerated_email | Whether the address is enumerated. | true, false |
deenumerated_email_handle_length | Handle length after deenumeration. | An int, e.g. 9 |
is_invalid_email | Whether the address is invalid. | true, false |
is_role_email | Whether the address is a role account (e.g. support@). | true, false |
is_private_relay | Whether the address is a private relay address. | true, false |
detumbled_email_first_seen | An ISO 8601 UTC timestamp for when the detumbled address was first seen. | e.g. 2026-03-11T01:56:18Z |
detumbled_email_first_seen_in_days | Days since the detumbled address was first seen. | An int, e.g. 0 |
domain_relative_usage_factor | Relative usage of the domain. | A number, e.g. 2 |
is_suspicious_email_handle | Whether the handle looks suspicious. | true, false |
anomalous_handle_composition | Whether the handle composition is anomalous. | true, false |
domain_shannon_entropy | Shannon entropy of the domain. | A number, e.g. 2.95 |
domain_metric_entropy | Metric entropy of the domain. | A number, e.g. 0.3277 |
deenumerated_domain_length | Domain length after deenumeration. | An int, e.g. 9 |
is_mx_record_present | Whether an MX record is present for the domain. | true, false |
is_mx_valid | Whether the MX record is valid. | true, false |
domain_enrichment | Domain registration and reputation data. See below. | An object |
email_assessment.domain_enrichment
email_assessment.domain_enrichment| Field Name | Description | Example Values |
|---|---|---|
is_domain_missing | Whether the domain could not be found. | true, false |
domain_age | Age of the domain in days. | An int, e.g. 11168, or null |
domain_creation_date | Date the domain was created. | e.g. 1995-08-13, or null |
domain_org | Registered organisation for the domain. | e.g. Google LLC |
domain_name_servers | Name servers for the domain. | An array of strings, or null |
is_disposable | Whether the domain is a disposable email provider. | true, false |
domain_registration_country | Country the domain was registered in. | e.g. us |
error | Error message if enrichment failed. Omitted on success. | A string |
Velocity count objects
total_email_counts, detumbled_email_unique_counts, detumbled_email_instance_counts, deenumerated_email_unique_counts and domain_instance_counts all share the same shape.
| Field Name | Description | Example Values |
|---|---|---|
short_term_count | Numeric count of the aggregation metric in the short term. | An int, e.g. 1 |
short_term_period_minutes | The time period over which the short term count was aggregated, in minutes. | An int, e.g. 360 |
long_term_count | Numeric count of the aggregation metric in the long term. | An int, e.g. 3 |
long_term_period_minutes | The time period over which the long term count was aggregated, in minutes. | An int, e.g. 10080 |
error | Error message if counts could not be retrieved for the aggregation. Omitted on success. | A string |
For Further readingSee the Email Intelligence API Reference (needs Zendesk authentication).
Aggregations (aggregations)
aggregations)IP velocity counts for the session.
| Field Name | Description | Example Values | Applicable Component |
|---|---|---|---|
error | Error message if aggregations have failed or are incomplete. | A string, or null | Detection Enforcement |
ip.short_term.count | Number of sessions seen from this IP in the short term window. | An int, e.g. 2, or null | Detection Enforcement |
ip.short_term.interval_minutes | Length of the short term window, in minutes. | An int, e.g. 60, or null | Detection Enforcement |
ip.short_term.threshold | Threshold configured for the short term window. | An int, e.g. 360, or null | Detection Enforcement |
ip.long_term.count | Number of sessions seen from this IP in the long term window. | An int, e.g. 2, or null | Detection Enforcement |
ip.long_term.interval_minutes | Length of the long term window, in minutes. | An int, e.g. 1440, or null | Detection Enforcement |
ip.long_term.threshold | Threshold configured for the long term window. | An int, e.g. 100, or null | Detection Enforcement |
See IP Velocity Fields for how these counts are configured and used.
Data Exchange (data_exchange)
data_exchange)| Field Name | Description | Example Values | Applicable Component |
|---|---|---|---|
blob_received | Whether a Data Exchange blob was received with the session. | true, false, null | Detection Enforcement |
blob_decrypted | Whether the received blob was successfully decrypted. | true, false, null | Detection Enforcement |
For Further detailsSee Data Exchange: Enhanced Detection and API Source Validation (needs Zendesk authentication).
MICS Verdict (mics_verdict)
mics_verdict)Mobile integrity check results, returned for mobile SDK sessions.
| Field Name | Description | Example Values | Applicable Component |
|---|---|---|---|
mics_response | Overall result of the mobile integrity check. | A string, e.g. SUCCESS | Enforcement |
app_check_account_check | Result of the app account check. | A string, e.g. VALID | Enforcement |
app_check_activity_level | Activity level reported by the app check. | A string, e.g. LEVEL_1 | Enforcement |
app_check_risk_level | Risk level reported by the app check. | A string, e.g. LOW | Enforcement |
app_check_timed_out | Whether the app check timed out. | true, false | Enforcement |
Sample Verify API Responses
The following examples show different Verify API responses. They show the typical values in each field for each type of response. The exact set of top-level objects you receive depends on the products enabled for your account.
{
"session_details": {
"solved": true,
"session": "43217b823752a4848.1388061501",
"session_created": "2026-02-28T21:17:26Z",
"check_answer": "2026-02-28T21:17:36Z",
"verified": "2026-02-28T21:17:47Z",
"attempted": true,
"security_level": 20,
"session_is_legit": true,
"previously_verified": false,
"session_timed_out": false,
"suppress_limited": false,
"theme_arg_invalid": false,
"suppressed": false,
"punishable_actioned": false,
"telltale_user": "g-reputation-hosting",
"telltale_origin": "example-telltale-e-app",
"failed_low_sec_validation": false,
"lowsec_error": null,
"lowsec_level_denied": null,
"ua": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36",
"ip_rep_list": null,
"optional": null,
"game_number_limit_reached": false,
"user_language_shown": "en",
"device_id": null,
"telltale_list": [
"g-reputation-hosting",
"g-reputation-vpn"
],
"challenge_type": "visual",
"stateless_device_id": {
"device_id": "a91cd4e726f8b3051d6e4a7c9f2b8d3e1c5a7f9b2d4e6a8c0f1b3d5e7a9c2b4",
"device_id_version": "2.0",
"device_id_previous": "3f5a7c9e1b2d4f6a8c0e2b4d6f8a1c3e5b7d9f1a3c5e7b9d2f4a6c8e0b1d3f5",
"device_id_previous_version": "1.2"
}
},
"fingerprint": {
"browser_characteristics": {
"browser_name": "Chrome",
"browser_version": "120.0.0.0",
"color_depth": 24,
"session_storage": true,
"indexed_database": true,
"canvas_fingerprint": 1131944312
},
"device_characteristics": {
"operating_system": "OS X",
"operating_system_version": "10.15.7",
"screen_resolution": [
1920,
1080
],
"max_resolution_supported": [
1920,
1055
],
"behavior": false,
"cpu_class": "unknown",
"platform": "MacIntel",
"touch_support": false,
"hardware_concurrency": 8,
"ja4_hash": "t13d1517h2_8daaf6152771_b6f405a00624"
},
"user_preferences": {
"timezone_offset": 360
}
},
"ip_intelligence": {
"user_ip": "18.190.53.157",
"is_proxy": true,
"is_vpn": true,
"is_tor": false,
"proxy_type": "data center",
"country": "US",
"region": "Ohio",
"city": "Columbus",
"isp": "Amazon.com",
"public_access_point": false,
"connection_type": "Data Center",
"latitude": "39.9587",
"longitude": "-82.9987",
"timezone": "America/New_York",
"asn": 55256,
"network_info_rtt": 100
},
"session_risk": {
"risk_category": "BOT-STD",
"risk_band": "LOW",
"global": {
"score": 36,
"telltales": [
{
"name": "g-reputation-hosting",
"weight": 20
},
{
"name": "g-reputation-vpn",
"weight": 20
}
]
},
"custom": {
"score": 0,
"telltales": []
}
},
"aggregations": {
"error": null,
"ip": {
"short_term": {
"interval_minutes": 60,
"count": 2,
"threshold": 360
},
"long_term": {
"interval_minutes": 1440,
"count": 2,
"threshold": 100
}
}
},
"data_exchange": {
"blob_decrypted": null,
"blob_received": null
},
"device_id": {
"arkose_id": "f83be5d914c7a2069e5f8b1d4a3c6e9f2b7d1a4c8e3f5b9d2a6c0e4f7b1d3a8",
"confidence_score": 99.986305,
"device_first_seen": "2025-03-22T08:15:44Z",
"device_last_seen": "2026-01-09T11:37:21Z",
"device_spoofing_detected": false,
"risk_band": "LOW",
"risk_score": 12,
"risk_insights": [
"device_reuse"
],
"stateful_device_id": "8dd4a9dc-81de-4c3d-a685-b8eb546b382b",
"stateful_challenge_bypassed": true,
"stateful_challenges_bypassed": 1,
"stateful_change_reasons": [
"invalid_id",
"invalid_nonce"
],
"stateless_device_id": "a91cd4e726f8b3051d6e4a7c9f2b8d3e1c5a7f9b2d4e6a8c0f1b3d5e7a9c2b4",
"stateless_device_id_version": "2.0",
"stateless_device_id_previous": "3f5a7c9e1b2d4f6a8c0e2b4d6f8a1c3e5b7d9f1a3c5e7b9d2f4a6c8e0b1d3f5",
"stateless_device_id_previous_version": "1.2"
},
"stateful_device_id": {
"stateful_device_id": "8dd4a9dc-81de-4c3d-a685-b8eb546b382b",
"challenge_bypassed": true,
"challenges_bypassed": 1,
"change_reasons": [
"invalid_id",
"invalid_nonce"
]
},
"proof_of_work": {
"challenged": false,
"attempted": false,
"passed": false,
"difficulty_level": null,
"transparent": false
},
"mics_verdict": {
"app_check_account_check": "VALID",
"app_check_activity_level": "LEVEL_1",
"app_check_risk_level": "LOW",
"app_check_timed_out": false,
"mics_response": "SUCCESS"
},
"email_intelligence": {
"email_assessment": {
"email_address": "[email protected]",
"detumbled_email_address": "[email protected]",
"deenumerated_email_address": "[email protected]",
"suggested_action": "email_no_risk",
"email_risk_score": 0,
"email_domain": "gmail.com",
"email_handle_length": 9,
"is_tumbled_email": false,
"is_enumerated_email": false,
"deenumerated_email_handle_length": 9,
"is_invalid_email": false,
"is_role_email": false,
"is_private_relay": false,
"detumbled_email_first_seen": "2026-03-11T01:56:18Z",
"detumbled_email_first_seen_in_days": 0,
"domain_relative_usage_factor": 2,
"domain_enrichment": {
"is_domain_missing": false,
"domain_age": 11168,
"domain_creation_date": "1995-08-13",
"domain_org": "Google LLC",
"domain_name_servers": [
"ns1.google.com",
"ns4.google.com",
"ns3.google.com",
"ns2.google.com"
],
"is_disposable": false,
"domain_registration_country": "us"
},
"is_suspicious_email_handle": false,
"domain_shannon_entropy": 2.95,
"domain_metric_entropy": 0.3277777777777778,
"deenumerated_domain_length": 9,
"anomalous_handle_composition": false,
"is_mx_record_present": true,
"is_mx_valid": true
},
"detumbled_email_stats": {
"handle_length": 9,
"handle_num_alpha_chars": 9,
"handle_num_vowels": 3,
"handle_num_consonants": 6,
"handle_num_numeric_chars": 0,
"handle_num_special_chars": 0,
"handle_qwerty_typing_distance": 31.169465219861685,
"handle_dvorak_typing_distance": 34.39834563766817
},
"total_email_counts": {
"short_term_count": 1,
"short_term_period_minutes": 360,
"long_term_count": 3,
"long_term_period_minutes": 10080
},
"detumbled_email_unique_counts": {
"short_term_count": 1,
"short_term_period_minutes": 1440,
"long_term_count": 1,
"long_term_period_minutes": 21600
},
"deenumerated_email_unique_counts": {
"short_term_count": 1,
"short_term_period_minutes": 360,
"long_term_count": 1,
"long_term_period_minutes": 21600
},
"domain_instance_counts": {
"short_term_count": 1,
"short_term_period_minutes": 360,
"long_term_count": 1,
"long_term_period_minutes": 10080
},
"domain_stats": {
"domain_length": 9,
"domain_num_alpha_chars": 8,
"domain_num_vowels": 3,
"domain_num_consonants": 0,
"domain_num_numeric_chars": 0,
"domain_num_special_chars": 1,
"domain_qwerty_typing_distance": 32.95709432711953,
"domain_dvorak_typing_distance": 40.36356408778201,
"domain_max_consec_consonants": 2,
"domain_max_consec_vowels": 2
},
"detumbled_email_instance_counts": {
"short_term_count": 1,
"short_term_period_minutes": 1440,
"long_term_count": 1,
"long_term_period_minutes": 21600
}
},
"agent_trust": {
"detected": true,
"detection_source": "web_bot_auth",
"agent": {
"name": "ClaudeBot"
},
"web_bot_auth": {
"provided": true,
"agent": "https://www.anthropic.com/",
"key_id": "NzbLsXh8uDCcd-6MNwXF4W_7noWXFZAfHkxZsRGC9Xs",
"signature_verified": true,
"signature_fail_reason": null
}
}
}{
"session_details": {
"solved": false,
"session": "43217b82394172236.2145822401",
"session_created": "2026-02-28T21:17:26Z",
"check_answer": null,
"verified": "2026-02-28T21:17:47Z",
"attempted": false,
"security_level": 30,
"session_is_legit": true,
"previously_verified": false,
"session_timed_out": false,
"suppress_limited": false,
"theme_arg_invalid": false,
"suppressed": false,
"punishable_actioned": false,
"telltale_user": "g-reputation-hosting",
"telltale_origin": "example-telltale-e-app",
"failed_low_sec_validation": false,
"lowsec_error": null,
"lowsec_level_denied": null,
"ua": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36",
"ip_rep_list": null,
"optional": null,
"game_number_limit_reached": true,
"user_language_shown": "en",
"device_id": null,
"telltale_list": [
"g-reputation-hosting",
"g-reputation-vpn"
],
"challenge_type": null,
"stateless_device_id": {
"device_id": "a91cd4e726f8b3051d6e4a7c9f2b8d3e1c5a7f9b2d4e6a8c0f1b3d5e7a9c2b4",
"device_id_version": "2.0",
"device_id_previous": "3f5a7c9e1b2d4f6a8c0e2b4d6f8a1c3e5b7d9f1a3c5e7b9d2f4a6c8e0b1d3f5",
"device_id_previous_version": "1.2"
}
},
"fingerprint": {
"browser_characteristics": {
"browser_name": "Chrome",
"browser_version": "120.0.0.0",
"color_depth": 24,
"session_storage": true,
"indexed_database": true,
"canvas_fingerprint": 1131944312
},
"device_characteristics": {
"operating_system": "OS X",
"operating_system_version": "10.15.7",
"screen_resolution": [
1920,
1080
],
"max_resolution_supported": [
1920,
1055
],
"behavior": false,
"cpu_class": "unknown",
"platform": "MacIntel",
"touch_support": false,
"hardware_concurrency": 8,
"ja4_hash": "t13d1517h2_8daaf6152771_b6f405a00624"
},
"user_preferences": {
"timezone_offset": 360
}
},
"ip_intelligence": {
"user_ip": "18.190.53.157",
"is_proxy": true,
"is_vpn": true,
"is_tor": false,
"proxy_type": "data center",
"country": "US",
"region": "Ohio",
"city": "Columbus",
"isp": "Amazon.com",
"public_access_point": false,
"connection_type": "Data Center",
"latitude": "39.9587",
"longitude": "-82.9987",
"timezone": "America/New_York",
"asn": 55256,
"network_info_rtt": 100
},
"session_risk": {
"risk_category": "BOT-STD",
"risk_band": "LOW",
"global": {
"score": 36,
"telltales": [
{
"name": "g-reputation-hosting",
"weight": 20
},
{
"name": "g-reputation-vpn",
"weight": 20
}
]
},
"custom": {
"score": 0,
"telltales": []
}
},
"aggregations": {
"error": null,
"ip": {
"short_term": {
"interval_minutes": 60,
"count": 3,
"threshold": 360
},
"long_term": {
"interval_minutes": 1440,
"count": 3,
"threshold": 100
}
}
},
"data_exchange": {
"blob_decrypted": null,
"blob_received": null
},
"device_id": {
"arkose_id": "f83be5d914c7a2069e5f8b1d4a3c6e9f2b7d1a4c8e3f5b9d2a6c0e4f7b1d3a8",
"confidence_score": 99.986305,
"device_first_seen": "2025-03-22T08:15:44Z",
"device_last_seen": "2026-01-09T11:37:21Z",
"device_spoofing_detected": false,
"risk_band": "LOW",
"risk_score": 12,
"risk_insights": [
"device_reuse"
],
"stateful_device_id": "8dd4a9dc-81de-4c3d-a685-b8eb546b382b",
"stateful_challenge_bypassed": true,
"stateful_challenges_bypassed": 1,
"stateful_change_reasons": [
"invalid_id",
"invalid_nonce"
],
"stateless_device_id": "a91cd4e726f8b3051d6e4a7c9f2b8d3e1c5a7f9b2d4e6a8c0f1b3d5e7a9c2b4",
"stateless_device_id_version": "2.0",
"stateless_device_id_previous": "3f5a7c9e1b2d4f6a8c0e2b4d6f8a1c3e5b7d9f1a3c5e7b9d2f4a6c8e0b1d3f5",
"stateless_device_id_previous_version": "1.2"
},
"stateful_device_id": {
"stateful_device_id": "8dd4a9dc-81de-4c3d-a685-b8eb546b382b",
"challenge_bypassed": true,
"challenges_bypassed": 1,
"change_reasons": [
"invalid_id",
"invalid_nonce"
]
},
"proof_of_work": {
"challenged": false,
"attempted": false,
"passed": false,
"difficulty_level": null,
"transparent": false
},
"mics_verdict": {
"app_check_account_check": "VALID",
"app_check_activity_level": "LEVEL_1",
"app_check_risk_level": "LOW",
"app_check_timed_out": false,
"mics_response": "SUCCESS"
},
"email_intelligence": {
"email_assessment": {
"email_address": "[email protected]",
"detumbled_email_address": "[email protected]",
"deenumerated_email_address": "[email protected]",
"suggested_action": "email_no_risk",
"email_risk_score": 0,
"email_domain": "gmail.com",
"email_handle_length": 9,
"is_tumbled_email": false,
"is_enumerated_email": false,
"deenumerated_email_handle_length": 9,
"is_invalid_email": false,
"is_role_email": false,
"is_private_relay": false,
"detumbled_email_first_seen": "2026-03-11T01:56:18Z",
"detumbled_email_first_seen_in_days": 0,
"domain_relative_usage_factor": 2,
"domain_enrichment": {
"is_domain_missing": false,
"domain_age": 11168,
"domain_creation_date": "1995-08-13",
"domain_org": "Google LLC",
"domain_name_servers": [
"ns1.google.com",
"ns4.google.com",
"ns3.google.com",
"ns2.google.com"
],
"is_disposable": false,
"domain_registration_country": "us"
},
"is_suspicious_email_handle": false,
"domain_shannon_entropy": 2.95,
"domain_metric_entropy": 0.3277777777777778,
"deenumerated_domain_length": 9,
"anomalous_handle_composition": false,
"is_mx_record_present": true,
"is_mx_valid": true
},
"detumbled_email_stats": {
"handle_length": 9,
"handle_num_alpha_chars": 9,
"handle_num_vowels": 3,
"handle_num_consonants": 6,
"handle_num_numeric_chars": 0,
"handle_num_special_chars": 0,
"handle_qwerty_typing_distance": 31.169465219861685,
"handle_dvorak_typing_distance": 34.39834563766817
},
"total_email_counts": {
"short_term_count": 1,
"short_term_period_minutes": 360,
"long_term_count": 3,
"long_term_period_minutes": 10080
},
"detumbled_email_unique_counts": {
"short_term_count": 1,
"short_term_period_minutes": 1440,
"long_term_count": 1,
"long_term_period_minutes": 21600
},
"deenumerated_email_unique_counts": {
"short_term_count": 1,
"short_term_period_minutes": 360,
"long_term_count": 1,
"long_term_period_minutes": 21600
},
"domain_instance_counts": {
"short_term_count": 1,
"short_term_period_minutes": 360,
"long_term_count": 1,
"long_term_period_minutes": 10080
},
"domain_stats": {
"domain_length": 9,
"domain_num_alpha_chars": 8,
"domain_num_vowels": 3,
"domain_num_consonants": 0,
"domain_num_numeric_chars": 0,
"domain_num_special_chars": 1,
"domain_qwerty_typing_distance": 32.95709432711953,
"domain_dvorak_typing_distance": 40.36356408778201,
"domain_max_consec_consonants": 2,
"domain_max_consec_vowels": 2
},
"detumbled_email_instance_counts": {
"short_term_count": 1,
"short_term_period_minutes": 1440,
"long_term_count": 1,
"long_term_period_minutes": 21600
}
},
"agent_trust": {
"detected": true,
"detection_source": "web_bot_auth",
"agent": {
"name": "ClaudeBot"
},
"web_bot_auth": {
"provided": true,
"agent": "https://www.anthropic.com/",
"key_id": "NzbLsXh8uDCcd-6MNwXF4W_7noWXFZAfHkxZsRGC9Xs",
"signature_verified": true,
"signature_fail_reason": null
}
}
}{
"error": "DENIED ACCESS",
"verified": "2026-08-30T22:15:00+00:00"
}{
"session_details": {
"solved": true,
"session": "75517b8243b6f0441.7468814901",
"session_created": "2026-02-28T21:17:26Z",
"check_answer": "2026-02-28T21:17:36Z",
"verified": "2026-02-28T21:17:47Z",
"attempted": true,
"security_level": 50,
"session_is_legit": true,
"previously_verified": false,
"session_timed_out": false,
"suppress_limited": false,
"theme_arg_invalid": false,
"suppressed": false,
"punishable_actioned": false,
"telltale_user": "g-reputation-hosting",
"telltale_origin": "example-telltale-e-app",
"failed_low_sec_validation": false,
"lowsec_error": "user_credits",
"lowsec_level_denied": null,
"ua": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36",
"ip_rep_list": null,
"optional": null,
"game_number_limit_reached": false,
"user_language_shown": "en",
"device_id": "60116465c81ab3f640655106e42bf05994dd2e27b3afafb7e61a5cac0928c2e6",
"telltale_list": [
"g-reputation-hosting",
"g-reputation-vpn"
],
"challenge_type": "visual",
"stateless_device_id": {
"device_id": "a91cd4e726f8b3051d6e4a7c9f2b8d3e1c5a7f9b2d4e6a8c0f1b3d5e7a9c2b4",
"device_id_version": "2.0",
"device_id_previous": "3f5a7c9e1b2d4f6a8c0e2b4d6f8a1c3e5b7d9f1a3c5e7b9d2f4a6c8e0b1d3f5",
"device_id_previous_version": "1.2"
}
},
"fingerprint": {
"browser_characteristics": {
"browser_name": "Chrome",
"browser_version": "120.0.0.0",
"color_depth": 24,
"session_storage": true,
"indexed_database": true,
"canvas_fingerprint": 1131944312
},
"device_characteristics": {
"operating_system": "OS X",
"operating_system_version": "10.15.7",
"screen_resolution": [
1920,
1080
],
"max_resolution_supported": [
1920,
1055
],
"behavior": false,
"cpu_class": "unknown",
"platform": "MacIntel",
"touch_support": false,
"hardware_concurrency": 8,
"ja4_hash": "t13d1517h2_8daaf6152771_b6f405a00624"
},
"user_preferences": {
"timezone_offset": 360
}
},
"ip_intelligence": {
"user_ip": "18.190.53.157",
"is_proxy": true,
"is_vpn": true,
"is_tor": false,
"proxy_type": "data center",
"country": "US",
"region": "Ohio",
"city": "Columbus",
"isp": "Amazon.com",
"public_access_point": false,
"connection_type": "Data Center",
"latitude": "39.9587",
"longitude": "-82.9987",
"timezone": "America/New_York",
"asn": 55256,
"network_info_rtt": 100
},
"session_risk": {
"risk_category": "BOT-STD",
"risk_band": "LOW",
"global": {
"score": 36,
"telltales": [
{
"name": "g-reputation-hosting",
"weight": 20
},
{
"name": "g-reputation-vpn",
"weight": 20
}
]
},
"custom": {
"score": 0,
"telltales": []
}
},
"aggregations": {
"error": null,
"ip": {
"short_term": {
"interval_minutes": 60,
"count": 2,
"threshold": 360
},
"long_term": {
"interval_minutes": 1440,
"count": 2,
"threshold": 100
}
}
},
"data_exchange": {
"blob_decrypted": null,
"blob_received": null
},
"device_id": {
"arkose_id": "f83be5d914c7a2069e5f8b1d4a3c6e9f2b7d1a4c8e3f5b9d2a6c0e4f7b1d3a8",
"confidence_score": 99.986305,
"device_first_seen": "2025-03-22T08:15:44Z",
"device_last_seen": "2026-01-09T11:37:21Z",
"device_spoofing_detected": false,
"risk_band": "LOW",
"risk_score": 12,
"risk_insights": [
"device_reuse"
],
"stateful_device_id": "8dd4a9dc-81de-4c3d-a685-b8eb546b382b",
"stateful_challenge_bypassed": true,
"stateful_challenges_bypassed": 1,
"stateful_change_reasons": [
"invalid_id",
"invalid_nonce"
],
"stateless_device_id": "a91cd4e726f8b3051d6e4a7c9f2b8d3e1c5a7f9b2d4e6a8c0f1b3d5e7a9c2b4",
"stateless_device_id_version": "2.0",
"stateless_device_id_previous": "3f5a7c9e1b2d4f6a8c0e2b4d6f8a1c3e5b7d9f1a3c5e7b9d2f4a6c8e0b1d3f5",
"stateless_device_id_previous_version": "1.2"
},
"stateful_device_id": {
"stateful_device_id": "8dd4a9dc-81de-4c3d-a685-b8eb546b382b",
"challenge_bypassed": true,
"challenges_bypassed": 1,
"change_reasons": [
"invalid_id",
"invalid_nonce"
]
},
"proof_of_work": {
"challenged": false,
"attempted": false,
"passed": false,
"difficulty_level": null,
"transparent": false
},
"mics_verdict": {
"app_check_account_check": "VALID",
"app_check_activity_level": "LEVEL_1",
"app_check_risk_level": "LOW",
"app_check_timed_out": false,
"mics_response": "SUCCESS"
},
"email_intelligence": {
"email_assessment": {
"email_address": "[email protected]",
"detumbled_email_address": "[email protected]",
"deenumerated_email_address": "[email protected]",
"suggested_action": "email_no_risk",
"email_risk_score": 0,
"email_domain": "gmail.com",
"email_handle_length": 9,
"is_tumbled_email": false,
"is_enumerated_email": false,
"deenumerated_email_handle_length": 9,
"is_invalid_email": false,
"is_role_email": false,
"is_private_relay": false,
"detumbled_email_first_seen": "2026-03-11T01:56:18Z",
"detumbled_email_first_seen_in_days": 0,
"domain_relative_usage_factor": 2,
"domain_enrichment": {
"is_domain_missing": false,
"domain_age": 11168,
"domain_creation_date": "1995-08-13",
"domain_org": "Google LLC",
"domain_name_servers": [
"ns1.google.com",
"ns4.google.com",
"ns3.google.com",
"ns2.google.com"
],
"is_disposable": false,
"domain_registration_country": "us"
},
"is_suspicious_email_handle": false,
"domain_shannon_entropy": 2.95,
"domain_metric_entropy": 0.3277777777777778,
"deenumerated_domain_length": 9,
"anomalous_handle_composition": false,
"is_mx_record_present": true,
"is_mx_valid": true
},
"detumbled_email_stats": {
"handle_length": 9,
"handle_num_alpha_chars": 9,
"handle_num_vowels": 3,
"handle_num_consonants": 6,
"handle_num_numeric_chars": 0,
"handle_num_special_chars": 0,
"handle_qwerty_typing_distance": 31.169465219861685,
"handle_dvorak_typing_distance": 34.39834563766817
},
"total_email_counts": {
"short_term_count": 1,
"short_term_period_minutes": 360,
"long_term_count": 3,
"long_term_period_minutes": 10080
},
"detumbled_email_unique_counts": {
"short_term_count": 1,
"short_term_period_minutes": 1440,
"long_term_count": 1,
"long_term_period_minutes": 21600
},
"deenumerated_email_unique_counts": {
"short_term_count": 1,
"short_term_period_minutes": 360,
"long_term_count": 1,
"long_term_period_minutes": 21600
},
"domain_instance_counts": {
"short_term_count": 1,
"short_term_period_minutes": 360,
"long_term_count": 1,
"long_term_period_minutes": 10080
},
"domain_stats": {
"domain_length": 9,
"domain_num_alpha_chars": 8,
"domain_num_vowels": 3,
"domain_num_consonants": 0,
"domain_num_numeric_chars": 0,
"domain_num_special_chars": 1,
"domain_qwerty_typing_distance": 32.95709432711953,
"domain_dvorak_typing_distance": 40.36356408778201,
"domain_max_consec_consonants": 2,
"domain_max_consec_vowels": 2
},
"detumbled_email_instance_counts": {
"short_term_count": 1,
"short_term_period_minutes": 1440,
"long_term_count": 1,
"long_term_period_minutes": 21600
}
},
"agent_trust": {
"detected": true,
"detection_source": "web_bot_auth",
"agent": {
"name": "ClaudeBot"
},
"web_bot_auth": {
"provided": true,
"agent": "https://www.anthropic.com/",
"key_id": "NzbLsXh8uDCcd-6MNwXF4W_7noWXFZAfHkxZsRGC9Xs",
"signature_verified": true,
"signature_fail_reason": null
}
}
}{
"session_details": {
"solved": false,
"session": "43217b82394172236.2145822401",
"session_created": "2026-02-28T21:17:26Z",
"check_answer": null,
"verified": "2026-02-28T21:17:47Z",
"attempted": false,
"security_level": 30,
"session_is_legit": true,
"previously_verified": false,
"session_timed_out": false,
"suppress_limited": false,
"theme_arg_invalid": false,
"suppressed": false,
"punishable_actioned": false,
"telltale_user": "g-reputation-hosting",
"telltale_origin": "example-telltale-e-app",
"failed_low_sec_validation": false,
"lowsec_error": null,
"lowsec_level_denied": null,
"ua": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36",
"ip_rep_list": null,
"optional": {
"blob": "BbfYFeKzwEwnGCAU.fCWy85IOHQ2j2SomSW6bf6Mibfgdlqn7MWyoY8JbYkVskPsLbqBqryeAR0EVC1pi5XosVJjPfvWZ4H6EBQgC5XYnHVeKwQ=="
},
"game_number_limit_reached": true,
"user_language_shown": "en",
"device_id": null,
"telltale_list": [
"g-reputation-hosting",
"g-reputation-vpn"
],
"challenge_type": null,
"stateless_device_id": {
"device_id": "a91cd4e726f8b3051d6e4a7c9f2b8d3e1c5a7f9b2d4e6a8c0f1b3d5e7a9c2b4",
"device_id_version": "2.0",
"device_id_previous": "3f5a7c9e1b2d4f6a8c0e2b4d6f8a1c3e5b7d9f1a3c5e7b9d2f4a6c8e0b1d3f5",
"device_id_previous_version": "1.2"
}
},
"fingerprint": {
"browser_characteristics": {
"browser_name": "Chrome",
"browser_version": "120.0.0.0",
"color_depth": 24,
"session_storage": true,
"indexed_database": true,
"canvas_fingerprint": 1131944312
},
"device_characteristics": {
"operating_system": "OS X",
"operating_system_version": "10.15.7",
"screen_resolution": [
1920,
1080
],
"max_resolution_supported": [
1920,
1055
],
"behavior": false,
"cpu_class": "unknown",
"platform": "MacIntel",
"touch_support": false,
"hardware_concurrency": 8,
"ja4_hash": "t13d1517h2_8daaf6152771_b6f405a00624"
},
"user_preferences": {
"timezone_offset": 360
}
},
"ip_intelligence": {
"user_ip": "18.190.53.157",
"is_proxy": true,
"is_vpn": true,
"is_tor": false,
"proxy_type": "data center",
"country": "US",
"region": "Ohio",
"city": "Columbus",
"isp": "Amazon.com",
"public_access_point": false,
"connection_type": "Data Center",
"latitude": "39.9587",
"longitude": "-82.9987",
"timezone": "America/New_York",
"asn": 55256,
"network_info_rtt": 100
},
"session_risk": {
"risk_category": "BOT-STD",
"risk_band": "LOW",
"global": {
"score": 36,
"telltales": [
{
"name": "g-reputation-hosting",
"weight": 20
},
{
"name": "g-reputation-vpn",
"weight": 20
}
]
},
"custom": {
"score": 0,
"telltales": []
}
},
"aggregations": {
"error": null,
"ip": {
"short_term": {
"interval_minutes": 60,
"count": 3,
"threshold": 360
},
"long_term": {
"interval_minutes": 1440,
"count": 3,
"threshold": 100
}
}
},
"data_exchange": {
"blob_decrypted": null,
"blob_received": null
},
"device_id": {
"arkose_id": "f83be5d914c7a2069e5f8b1d4a3c6e9f2b7d1a4c8e3f5b9d2a6c0e4f7b1d3a8",
"confidence_score": 99.986305,
"device_first_seen": "2025-03-22T08:15:44Z",
"device_last_seen": "2026-01-09T11:37:21Z",
"device_spoofing_detected": false,
"risk_band": "LOW",
"risk_score": 12,
"risk_insights": [
"device_reuse"
],
"stateful_device_id": "8dd4a9dc-81de-4c3d-a685-b8eb546b382b",
"stateful_challenge_bypassed": true,
"stateful_challenges_bypassed": 1,
"stateful_change_reasons": [
"invalid_id",
"invalid_nonce"
],
"stateless_device_id": "a91cd4e726f8b3051d6e4a7c9f2b8d3e1c5a7f9b2d4e6a8c0f1b3d5e7a9c2b4",
"stateless_device_id_version": "2.0",
"stateless_device_id_previous": "3f5a7c9e1b2d4f6a8c0e2b4d6f8a1c3e5b7d9f1a3c5e7b9d2f4a6c8e0b1d3f5",
"stateless_device_id_previous_version": "1.2"
},
"stateful_device_id": {
"stateful_device_id": "8dd4a9dc-81de-4c3d-a685-b8eb546b382b",
"challenge_bypassed": true,
"challenges_bypassed": 1,
"change_reasons": [
"invalid_id",
"invalid_nonce"
]
},
"proof_of_work": {
"challenged": false,
"attempted": false,
"passed": false,
"difficulty_level": null,
"transparent": false
},
"mics_verdict": {
"app_check_account_check": "VALID",
"app_check_activity_level": "LEVEL_1",
"app_check_risk_level": "LOW",
"app_check_timed_out": false,
"mics_response": "SUCCESS"
},
"email_intelligence": {
"email_assessment": {
"email_address": "[email protected]",
"detumbled_email_address": "[email protected]",
"deenumerated_email_address": "[email protected]",
"suggested_action": "email_no_risk",
"email_risk_score": 0,
"email_domain": "gmail.com",
"email_handle_length": 9,
"is_tumbled_email": false,
"is_enumerated_email": false,
"deenumerated_email_handle_length": 9,
"is_invalid_email": false,
"is_role_email": false,
"is_private_relay": false,
"detumbled_email_first_seen": "2026-03-11T01:56:18Z",
"detumbled_email_first_seen_in_days": 0,
"domain_relative_usage_factor": 2,
"domain_enrichment": {
"is_domain_missing": false,
"domain_age": 11168,
"domain_creation_date": "1995-08-13",
"domain_org": "Google LLC",
"domain_name_servers": [
"ns1.google.com",
"ns4.google.com",
"ns3.google.com",
"ns2.google.com"
],
"is_disposable": false,
"domain_registration_country": "us"
},
"is_suspicious_email_handle": false,
"domain_shannon_entropy": 2.95,
"domain_metric_entropy": 0.3277777777777778,
"deenumerated_domain_length": 9,
"anomalous_handle_composition": false,
"is_mx_record_present": true,
"is_mx_valid": true
},
"detumbled_email_stats": {
"handle_length": 9,
"handle_num_alpha_chars": 9,
"handle_num_vowels": 3,
"handle_num_consonants": 6,
"handle_num_numeric_chars": 0,
"handle_num_special_chars": 0,
"handle_qwerty_typing_distance": 31.169465219861685,
"handle_dvorak_typing_distance": 34.39834563766817
},
"total_email_counts": {
"short_term_count": 1,
"short_term_period_minutes": 360,
"long_term_count": 3,
"long_term_period_minutes": 10080
},
"detumbled_email_unique_counts": {
"short_term_count": 1,
"short_term_period_minutes": 1440,
"long_term_count": 1,
"long_term_period_minutes": 21600
},
"deenumerated_email_unique_counts": {
"short_term_count": 1,
"short_term_period_minutes": 360,
"long_term_count": 1,
"long_term_period_minutes": 21600
},
"domain_instance_counts": {
"short_term_count": 1,
"short_term_period_minutes": 360,
"long_term_count": 1,
"long_term_period_minutes": 10080
},
"domain_stats": {
"domain_length": 9,
"domain_num_alpha_chars": 8,
"domain_num_vowels": 3,
"domain_num_consonants": 0,
"domain_num_numeric_chars": 0,
"domain_num_special_chars": 1,
"domain_qwerty_typing_distance": 32.95709432711953,
"domain_dvorak_typing_distance": 40.36356408778201,
"domain_max_consec_consonants": 2,
"domain_max_consec_vowels": 2
},
"detumbled_email_instance_counts": {
"short_term_count": 1,
"short_term_period_minutes": 1440,
"long_term_count": 1,
"long_term_period_minutes": 21600
}
},
"agent_trust": {
"detected": true,
"detection_source": "web_bot_auth",
"agent": {
"name": "ClaudeBot"
},
"web_bot_auth": {
"provided": true,
"agent": "https://www.anthropic.com/",
"key_id": "NzbLsXh8uDCcd-6MNwXF4W_7noWXFZAfHkxZsRGC9Xs",
"signature_verified": true,
"signature_fail_reason": null
}
}
}Updated 14 days ago