Skip to content

Documentation availability

Paycux is in private beta. Most pages describe roadmap or reference material. The implemented boundary is published at docs/API_CONTRACTS.md in the release source and under What exists today in this documentation.

Sign-in UI

Abuse Checks

How Abuse Checks works in Paycux, what it is for, and the smallest setup that gets it running.

Introduction

Abuse Checks is part of the Paycux platform. This page explains what it does, when to reach for it, and the smallest working setup you can ship.

Everything below applies to both environments. Build and test in staging, then promote the same configuration to production without changing your code — only the API key and client ID differ.

Getting Started

Getting Started applies specifically to Abuse Checks. It behaves the same in both environments, and the values it depends on are visible in the dashboard for the environment you have selected.

If the behaviour you see does not match this description, check which environment your API key belongs to before anything else — a staging key against production data is the most common cause.

Event list

Event list is handled by Abuse Checks rather than by your application code. Paycux exposes it through the same API surface as the rest of the platform, so the client you already configured needs no additional setup.

Configuration lives in the dashboard and is versioned per environment. Change it in staging, confirm the behaviour, then apply the same change to production.

Configuration

Configuration is handled by Abuse Checks rather than by your application code. Paycux exposes it through the same API surface as the rest of the platform, so the client you already configured needs no additional setup.

Configuration lives in the dashboard and is versioned per environment. Change it in staging, confirm the behaviour, then apply the same change to production.

Bot detection

Abuse Checks scores each authentication attempt using device, network and behavioral signals, then applies the action you configured: allow, challenge or block.

Start in monitor mode. Abuse Checks records what it would have done without acting, so you can see the false-positive rate on your own traffic before you enforce.

Brute force

Brute force is handled by Abuse Checks rather than by your application code. Paycux exposes it through the same API surface as the rest of the platform, so the client you already configured needs no additional setup.

Configuration lives in the dashboard and is versioned per environment. Change it in staging, confirm the behaviour, then apply the same change to production.

Impossible travel

Impossible travel is handled by Abuse Checks rather than by your application code. Paycux exposes it through the same API surface as the rest of the platform, so the client you already configured needs no additional setup.

Configuration lives in the dashboard and is versioned per environment. Change it in staging, confirm the behaviour, then apply the same change to production.

Repeat sign up

Repeat sign up is handled by Abuse Checks rather than by your application code. Paycux exposes it through the same API surface as the rest of the platform, so the client you already configured needs no additional setup.

Configuration lives in the dashboard and is versioned per environment. Change it in staging, confirm the behaviour, then apply the same change to production.