Risk controls govern how Flint handles each payment attempt. Merchant-managed rules decide whether an attempt is allowed, blocked, challenged with 3DS, or sent to review; lists hold the values rules match against; reviews queue payments for a manual decision; and fraud warnings record issuer-reported fraud after a payment.
Rules use a strict JSON predicate grammar. Retrieve GET /v1/risk-rules/attributes before authoring rules: risk scoring is not enabled in every environment, and the registry reports which attributes your sandbox or live environment can use. Use POST /v1/risk-previews to validate a candidate rule or an existing rule by ID without changing it.
A review opens only on a payment the bank approved. For a manual-capture payment, approving the review allows a later capture but never captures; for an automatic-capture payment, the money has already been collected and approving only closes the review. Declining cancels an uncaptured payment or refunds a captured one, and may return 202 Accepted while that finishes: poll the review according to Retry-After or subscribe to the review.closed webhook event. Fraud warnings are distinct from the original risk assessment and can later link to a dispute. A payment without risk.score had no score available, not a score of zero.
Reads require the risk.read scope. Review actions require risk.reviews.write. Rule and list changes, and POST /v1/risk-previews, require risk.controls.write.
For predicate examples, lifecycle guidance, error handling, and webhook behavior, see the Risk Controls guide.
