Shield
OpenAPI, Postman, MCP & SDKs
Everything here is generated from, or checked against, the API's own route table, so it cannot describe an endpoint that does not exist.
OpenAPI
The native API (/v1/risk and the /v1/webhooks endpoints Shield alerts use) as an OpenAPI 3 document: verifex-shield.openapi.json. The SanctionScanner-compatible /api paths follow SanctionScanner's own published contract and are in the Postman collection.
Postman
verifex-shield.postman_collection.json — every native and compatible request, grouped by area, with example bodies. Set api_key (and api_key_id for the compatible folders). Simulating a rule stores simulation_id and sending a transaction stores transaction_id for the requests that follow.
MCP server
@verifex/shield-mcp lets an AI assistant (Claude, and other MCP clients) read decisions, cases, rules, customer risk and reports, and simulate a rule change. It runs locally over stdio with your API key and is read-only by default.
{
"mcpServers": {
"verifex-shield": {
"command": "npx",
"args": ["-y", "@verifex/shield-mcp"],
"env": { "VERIFEX_API_KEY": "vfx_your_api_key" }
}
}
}VERIFEX_MCP_ALLOW_WRITES=1adds the tools that change state: deploy a simulated rule change, update a case, adjust a customer's risk score, scan a name, decide a transaction.VERIFEX_API_KEY_IDadds the SanctionScanner-compatible tools.- Deploying needs the completed simulation's id, a rationale and the approver: an assistant cannot put a rule live that nobody simulated.
Warning
Node and Python SDKs
verifex.shield (Node) and client.shield (Python) wrap the native API: decisions, replay, cases, rules with simulate → wait → deploy, customer risk, alarm thresholds, reports and webhook events. Writes that are not idempotent are sent once and never retried automatically.
import { Verifex } from "verifex";
const verifex = new Verifex({ apiKey: process.env.VERIFEX_API_KEY! });
const page = await verifex.shield.listDecisions({ outcome: "block", limit: 25 });
const risk = await verifex.shield.customerRisk("CUST-1001");
const s1 = await verifex.shield.behaviourReport("S1", "2026-09");