Blog
Account protection, explained
Signup fraud, login risk, multi-accounting, and how to wire a live check into your auth stack — with a score, verdict, and reasons you can enforce.
One pattern for every auth stack: collect in the browser, check with a secret key in your hook, enforce the verdict before createSession / createUser.
When you only have an email — scoring disposable domains, role accounts, and risky patterns before you send the invite.
Why Pro is $99 for 20k (+ $4/1k) and Scale is $199 for 100k (+ $2/1k) — matching public entry prices and overages, with a verdict instead of just an ID.
An honest comparison — what AbuseGraph ships for account protection, where specialists still win, and what we will not overclaim.
An honest map of device-ID tools, account-abuse APIs, network-edge bot bundles, and fraud suites — plus what AbuseGraph ships for signup and login.
How browser collect and server-side check stay honest: session bind, verdict tokens, and avoiding replayed client payloads.
What “free” should mean for account protection: live checks, test keys, and no sales wall — plus what AbuseGraph includes on Free forever.
How velocity, bot-like clients, and breach-aware signals help stop stuffing without locking out real users.
Device IDs answer identity. Account risk APIs answer allow/deny. Here is how to choose — and when you need both.
Why password-reset and email-change events need the same risk API as signup — and how to wire them without rewriting your auth stack.
How linked accounts, shared devices, and shared emails surface multi-accounting — and how Free/Pro keep graph visibility in the product, not an add-on.
Practical ATO checks for login: new device, impossible travel, session bind, and when to force step-up instead of a hard block.
How to score signup risk with email, device, IP, and velocity signals before you create the user — and what a clean check response should look like.
Fraud teams care about risky browser tooling. Publishing exact methods helps attackers more than customers.
Low-latency decisions, clearer ownership of data, and a path that stays under your control.
Why splitting client collection from server-side decisions is better for privacy, integrity, and control.
Try it on your visit
Run a live check on this browser, then put the same API on signup — 1,000 live checks / month on Free.