Token validation guidelines
User principal assessment
- If available, extract the user information from the
bid.emailclaim, the information may be used as part of advanced fraud detection methods such as validating the address doesn’t correspond to a disposable email address or associated with a disposable email domain, check past transaction history associated with the email address, and other detection method when where the email address is used as the main identifier. - If available, extract the
bid.verifierclaim. - If the
bid.verifieris “Experian”, extract thebid.verification_statusclaim. The “VERIFIED” value may be used as part of a fraud risk score logic to infer a low risk for the transaction - When KYC was applied to validate the user the agent represents, additional information, such as postal address and phone number, may be available in the claim. The additional information may be used in fraud detection engines (methods using phone and address validation) to infer the risk associated with the request.