Blog

Account protection, explained

Signup fraud, login risk, multi-accounting, and how to wire a live check into your auth stack — with a score, verdict, and reasons you can enforce.

2026-07-19
GuidesIntegrate account protection with Clerk, Auth0, Better Auth, and Firebase

One pattern for every auth stack: collect in the browser, check with a secret key in your hook, enforce the verdict before createSession / createUser.

7 min
2026-07-18
GuidesEmail risk API for signup and invite flows

When you only have an email — scoring disposable domains, role accounts, and risky patterns before you send the invite.

5 min
2026-07-18
ProductPricing aligned to the public market

Why Pro is $99 for 20k (+ $4/1k) and Scale is $199 for 100k (+ $2/1k) — matching public entry prices and overages, with a verdict instead of just an ID.

4 min
2026-07-18
ProductAbuseGraph vs typical fingerprint and fraud tools

An honest comparison — what AbuseGraph ships for account protection, where specialists still win, and what we will not overclaim.

6 min
2026-07-18
ProductThe account-protection market — and where AbuseGraph fits

An honest map of device-ID tools, account-abuse APIs, network-edge bot bundles, and fraud suites — plus what AbuseGraph ships for signup and login.

5 min
2026-07-17
EngineeringSession risk scoring — bind collect to check

How browser collect and server-side check stay honest: session bind, verdict tokens, and avoiding replayed client payloads.

6 min
2026-07-17
ProductA free fraud prevention API that is actually live

What “free” should mean for account protection: live checks, test keys, and no sales wall — plus what AbuseGraph includes on Free forever.

5 min
2026-07-16
GuidesCredential stuffing defense for login APIs

How velocity, bot-like clients, and breach-aware signals help stop stuffing without locking out real users.

6 min
2026-07-16
ComparisonDevice fingerprint vs account risk API — pick the right job

Device IDs answer identity. Account risk APIs answer allow/deny. Here is how to choose — and when you need both.

6 min
2026-07-15
GuidesPassword reset fraud — the quiet account takeover path

Why password-reset and email-change events need the same risk API as signup — and how to wire them without rewriting your auth stack.

5 min
2026-07-14
ProductMulti-accounting detection without buying an enterprise graph SKU

How linked accounts, shared devices, and shared emails surface multi-accounting — and how Free/Pro keep graph visibility in the product, not an add-on.

6 min
2026-07-13
GuidesAccount takeover detection at sign-in — signals that matter

Practical ATO checks for login: new device, impossible travel, session bind, and when to force step-up instead of a hard block.

6 min
2026-07-12
GuidesSignup fraud prevention API — what to score before the account exists

How to score signup risk with email, device, IP, and velocity signals before you create the user — and what a clean check response should look like.

7 min
2026-07-10
ResearchBrowser tooling and account abuse — without the playbook

Fraud teams care about risky browser tooling. Publishing exact methods helps attackers more than customers.

4 min
2026-07-10
EngineeringWhy account protection belongs close to the request

Low-latency decisions, clearer ownership of data, and a path that stays under your control.

5 min
2026-07-10
EngineeringThe two-call model: browser collects, backend decides

Why splitting client collection from server-side decisions is better for privacy, integrity, and control.

5 min

Try it on your visit

Run a live check on this browser, then put the same API on signup — 1,000 live checks / month on Free.