Developer documentation

A single contract for trust decisions.

The alpha API provides a provider-neutral event model, normalized evidence and PII-minimized operational traces.

Production requests use X-API-Key. The API fails closed when a production key is not configured.

Decision events

EventEndpointUse
onboardingPOST /api/v1/decisions/onboardingAccount opening and merchant onboarding
payoutPOST /api/v1/decisions/payoutWithdrawals, settlement and beneficiary changes
account_changePOST /api/v1/decisions/account-changeCredential, contact or ownership changes

Request example

curl -X POST https://api.gridzen.ai/api/v1/decisions/onboarding \
  -H "X-API-Key: $API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "event": "onboarding",
    "subject": {"email": "person@example.com"},
    "context": {"country": "MX", "consent_reference": "consent-123"}
  }'

Response shape

{
  "trace_id": "uuid",
  "decision": "review",
  "risk_score": 45,
  "reason_codes": ["country_context_mismatch"],
  "evidence": [],
  "providers_used": ["local-baseline"]
}
Safety boundary

The local-baseline provider is development-only. It does not verify a person, call a third party or establish a regulatory conclusion. Production needs tenant authorization, encrypted audit storage, retention controls and approved provider contracts.

Read the full API contract in the repository.