Shield

OpenAPI, Postman, MCP & SDKs

Everything here is generated from, or checked against, the API's own route table, so it cannot describe an endpoint that does not exist.

PilotShield is in pilot and enabled per account on request. Without it every Shield endpoint answers 404.

OpenAPI

The native API (/v1/risk and the /v1/webhooks endpoints Shield alerts use) as an OpenAPI 3 document: verifex-shield.openapi.json. The SanctionScanner-compatible /api paths follow SanctionScanner's own published contract and are in the Postman collection.

Postman

verifex-shield.postman_collection.json — every native and compatible request, grouped by area, with example bodies. Set api_key (and api_key_id for the compatible folders). Simulating a rule stores simulation_id and sending a transaction stores transaction_id for the requests that follow.

MCP server

@verifex/shield-mcp lets an AI assistant (Claude, and other MCP clients) read decisions, cases, rules, customer risk and reports, and simulate a rule change. It runs locally over stdio with your API key and is read-only by default.

mcp config
{
  "mcpServers": {
    "verifex-shield": {
      "command": "npx",
      "args": ["-y", "@verifex/shield-mcp"],
      "env": { "VERIFEX_API_KEY": "vfx_your_api_key" }
    }
  }
}
  • VERIFEX_MCP_ALLOW_WRITES=1 adds the tools that change state: deploy a simulated rule change, update a case, adjust a customer's risk score, scan a name, decide a transaction.
  • VERIFEX_API_KEY_ID adds the SanctionScanner-compatible tools.
  • Deploying needs the completed simulation's id, a rationale and the approver: an assistant cannot put a rule live that nobody simulated.

Warning

A tool call runs with your key's full rights. Turn writes on only for an assistant a person supervises.

Node and Python SDKs

verifex.shield (Node) and client.shield (Python) wrap the native API: decisions, replay, cases, rules with simulate → wait → deploy, customer risk, alarm thresholds, reports and webhook events. Writes that are not idempotent are sent once and never retried automatically.

import { Verifex } from "verifex";

const verifex = new Verifex({ apiKey: process.env.VERIFEX_API_KEY! });
const page = await verifex.shield.listDecisions({ outcome: "block", limit: 25 });
const risk = await verifex.shield.customerRisk("CUST-1001");
const s1 = await verifex.shield.behaviourReport("S1", "2026-09");