All Use Cases

Velocity Checks and Anomaly Detection

A clean email from a clean IP is still a problem when it is the fifth signup from that IP this hour. Send event and user_id with each /validate call and Fidro records it, counts related activity per IP, subnet, email pattern and user, and raises the score when the pattern is wrong. On every plan.

What is Fidro?

Fidro is a fraud detection API that combines email validation, IP intelligence, geolocation analysis, and Stripe chargeback prevention in a single API call. Built for developers at startups and growing companies, Fidro returns a risk score with a clear recommendation, allow, challenge or block, so you can stop fraud without building your own scoring logic. Fidro offers a free plan with 1,000 validations per month, no credit card required.

The Problem

Most signup abuse does not arrive from a Tor exit node with a throwaway address. It arrives from an ordinary residential IP with a plausible address, then another, then another. Each call is clean on its own, and a stateless check forgets every call it has made, so the pattern is only visible in your own database after the accounts already exist.

The Fidro Solution

Fidro keeps the history for you. Each stateful call is stored, counted over the last hour, day and month, and checked against six anomaly rules. Bursts add to the score and the high-severity ones force at least a challenge recommendation, so the third signup from one IP is challenged before the account exists rather than deleted after.

Key Features

Signup Bursts

ip_signup_burst fires at 3 signups from one IP in an hour or 5 in a day; subnet_signup_burst at 5 from one /24. Both include the current call, so the burst is caught on the call that makes it one.

Email Pattern Bursts

Plus-tags, dots and trailing digits are stripped before matching, so sam+1@, s.a.m@ and sam42@ count as one pattern. Three signups on one pattern in a day is email_pattern_burst.

Shared IPs and Impossible Travel

ip_many_users flags 5 or more user_ids behind one IP in a day. new_country_for_user and impossible_travel compare a login against where that user has been, using the user_id you already have.

6
Anomaly rules
2
Optional request fields
All plans
Including Free

Learn more about Fidro

Explore our features, see how we compare, or try Fidro for free.

Frequently Asked Questions

What is velocity checking in fraud detection?
Velocity checking counts how often something happens over a window of time: signups from one IP in an hour, logins for one user from different countries in a day, accounts created on one email pattern in a week. Individual events can be clean while the rate is not. Fidro returns nine velocity counts on every stateful call and fires anomaly rules on the ones that cross a threshold.
How do I turn it on?
Add event to the /validate call you already make: signup, login, checkout, password_reset or custom:name. Add user_id when you have one, so Fidro can follow a person across IPs and countries. Calls without those fields are stateless and behave exactly as before. There is no setting to enable.
Does it cost extra?
No. Velocity and anomaly detection are included on every plan, and a stateful call counts as one validation like any other. Plans differ in event retention: 7 days on Free, 90 on Starter and 365 on Pro and Enterprise. That window is how far back the counts can see.
How is impossible travel detected?
When a user_id is seen from one country and then from a different country within 60 minutes, Fidro returns impossible_travel with high severity and a detail line naming both countries and the gap. A user with three or more prior events from one country who appears from a new one gets new_country_for_user at medium severity. Both need user_id on the login call.
What does Fidro store and for how long?
One row per stateful call: the event type, the lowercased email and its normalised pattern, the IP and its subnet, the country, your user_id and session_id, the score and any anomalies. Events are scoped to your account, never shared across customers, and deleted when they fall outside your plan retention window. Test keys keep a separate history.

Start catching bad signups in the next 5 minutes

Create your account, grab your API key, and send your first request. Free plan with 200 validations/month. No credit card. Cancel anytime.

Start free