canonical: https://jentic.com/apis/sift.com/sift

# Sift API

Sift's fraud detection and prevention API for sending events, retrieving scores, and managing decisions. The API exposes 14 endpoints secured with basic authentication.

## For AI agents

Programmatically send event, get user score. Covers 14 operations with basic authentication.

## Scope

Does not handle payments, communications, or crm - use for developer tools only.

## Capabilities

- Send Event
- Get User Score
- Rescore User
- Apply Decision to User
- Monitor Sift API operational status and events

## Use cases

### Developer Tools Operations

Use the Sift API to perform developer tools operations programmatically. The API provides 14 endpoints covering core functionality including send event, get user score, rescore user.

Example prompt: Call POST /v205/events to send event

### Automated Events Management

Automate events operations by combining multiple Sift API endpoints. Agents can get user score and then rescore user in a single workflow.

Example prompt: Call GET /v205/users/{userId}/score to get user score, then verify the result

### AI Agent Integration via Jentic

AI agents discover and call Sift API endpoints through Jentic without managing credentials directly. An agent searches for the required operation by intent, receives the matching endpoint schema, and executes the call with Jentic-managed authentication. This eliminates the need to read API documentation or handle basic tokens manually.

Example prompt: Search Jentic for 'send event', load the operation schema, and execute with Jentic-managed credentials

## Key endpoints

| Method | Path | Description |
| --- | --- | --- |
| POST | /v205/events | Send Event |
| GET | /v205/users/{userId}/score | Get User Score |
| POST | /v205/users/{userId}/rescore | Rescore User |
| POST | /v3/accounts/{accountId}/users/{userId}/decisions | Apply Decision to User |
| GET | /v3/accounts/{accountId}/users/{userId}/decisions | Get User Decisions |
| POST | /v3/accounts/{accountId}/orders/{orderId}/decisions | Apply Decision to Order |
| GET | /v3/accounts/{accountId}/orders/{orderId}/decisions | Get Order Decisions |
| POST | /v3/accounts/{accountId}/sessions/{sessionId}/decisions | Apply Decision to Session |

## Key resources

- **Events** — Send event data to Sift for fraud detection
- **Scores** — Retrieve and rescore user fraud scores
- **Decisions** — Apply and retrieve decisions on users, orders, and sessions
- **Labels** — Label and unlabel users (deprecated, use Decisions API instead)
- **Verification** — Send, resend, and check user verification codes

## Why Jentic

- **Setup:** Wiring Sift by hand means setting up its basic auth, pointing calls at https://api.sift.com across its v205 and v3 paths, and threading account, user, and order ids through yourself. Through Jentic you install once, import Sift from the API Directory, store the credential once, and your agent calls it.
- **Permission scoping:** Sift puts the user, order, and session ids in the URL path (/v3/accounts/{accountId}/users/{userId}/decisions), so a rule can pin your agent to one user or order: it can read and post decisions for that resource and nothing else. You choose the operations it may call, so anything you do not add stays unavailable to the agent.
- **Credential handling:** Your Sift credential is stored once, encrypted, by your own Jentic One instance and injected at execution time. It never enters the agent's prompt, logs, or context.
- **Discovery method:** Agents search Jentic by intent such as 'send an event' or 'get a user risk score', and Jentic returns the matching Sift operation with its input schema so the agent calls the right endpoint without browsing the reference docs.

## Related APIs

- **Github** — Alternative developer tools API
- **Gitlab** — Alternative developer tools API

## FAQ

### What authentication does the Sift API use?

The Sift API uses HTTP Basic authentication with username and password. Through Jentic, these credentials are stored encrypted in your Jentic One instance and injected at execution time, so raw secrets never enter the agent context.

### Can I send event with the Sift API?

Yes. Use the POST /v205/events endpoint. The API returns structured JSON responses that agents can parse and act on directly.

### What are the rate limits for the Sift API?

Rate limits are not specified in the OpenAPI spec. Check the vendor documentation for current limits. Through Jentic, rate limiting is handled automatically with retry logic built into the execution layer.

### How do I send event through Jentic?

Install the Jentic SDK with pip install jentic, authenticate through Jentic One, the self-hosted execution layer, then search for 'send event'. Jentic returns the matching Sift API operation with its input schema. Load the schema and execute the call - credentials are injected automatically.

### How many endpoints does the Sift API have?

The Sift API exposes 14 endpoints covering events, scores, decisions operations.

### Can I limit what my agent is allowed to do with the Sift API?

Yes. Jentic One runs self-hosted, so your own rules decide which Sift operations and credentials the agent may use. Because Sift carries the user, order, and session ids in the URL path (for example /v3/accounts/{accountId}/users/{userId}/decisions), a rule can pin the agent to a single user or order so it only reads and posts decisions for that resource. You pick the exact operations it can call, such as sending an event or getting a user score, and anything you do not add stays unavailable to it.
