---
title: Fraud
---

[Skip to content](#%5Ftop) 

[API Reference](https://developers.cloudflare.com/api/typescript)

Copy Markdown

Open in **Claude**

Open in **ChatGPT**

Open in **Cursor**

---

**Copy Markdown**

**View as Markdown**

# Fraud

##### [Get Fraud Detection Settings](https://developers.cloudflare.com/api/typescript/resources/fraud/methods/get)

client.fraud.get(FraudGetParams { zone\_id } params, RequestOptionsoptions?): [FraudSettings](https://developers.cloudflare.com/api/typescript/resources/fraud#%28resource%29%20fraud%20%3E%20%28model%29%20fraud%5Fsettings%20%3E%20%28schema%29) { authentication\_settings, user\_profiles, username\_expressions } 

GET/zones/{zone\_id}/fraud\_detection/settings

##### [Update Fraud Detection Settings](https://developers.cloudflare.com/api/typescript/resources/fraud/methods/update)

client.fraud.update(FraudUpdateParams { zone\_id, authentication\_settings, user\_profiles, username\_expressions } params, RequestOptionsoptions?): [FraudSettings](https://developers.cloudflare.com/api/typescript/resources/fraud#%28resource%29%20fraud%20%3E%20%28model%29%20fraud%5Fsettings%20%3E%20%28schema%29) { authentication\_settings, user\_profiles, username\_expressions } 

PUT/zones/{zone\_id}/fraud\_detection/settings

##### ModelsExpand Collapse 

FraudSettings { authentication\_settings, user\_profiles, username\_expressions } 

authentication\_settings?: AuthenticationSettings { failure\_criteria, success\_criteria } 

Configuration for classifying login authentication outcomes based on the origin response. Requires `user_profiles` to be enabled.

* Success and failure criteria are independently updatable — sending only `success_criteria`leaves failure codes untouched, and vice versa.
* Omit `authentication_settings` entirely to leave both unchanged.
* Status codes must not overlap between success and failure criteria.

failure\_criteria?: FailureCriteria { kind, status\_codes } 

Criterion for identifying failed login responses.

kind: "status\_code"

The type of criterion. Currently only `status_code` is supported.

status\_codes?: Array<number\>

HTTP status codes to match against the origin response.

* Maximum of 10 codes per criterion.
* Each code must be a valid HTTP status code (100-599).
* Codes are deduplicated and sorted on save.
* Omit to leave unchanged on update.
* Provide an empty array `[]` to clear codes on update.

success\_criteria?: SuccessCriteria { kind, status\_codes } 

Criterion for identifying successful login responses.

kind: "status\_code"

The type of criterion. Currently only `status_code` is supported.

status\_codes?: Array<number\>

HTTP status codes to match against the origin response.

* Maximum of 10 codes per criterion.
* Each code must be a valid HTTP status code (100-599).
* Codes are deduplicated and sorted on save.
* Omit to leave unchanged on update.
* Provide an empty array `[]` to clear codes on update.

user\_profiles?: "enabled" | "disabled"

Whether Fraud User Profiles is enabled for the zone.

One of the following:

"enabled"

"disabled"

username\_expressions?: Array<string\>

List of expressions to detect usernames in write HTTP requests.

* Maximum of 10 expressions.
* Omit or set to null to leave unchanged on update.
* Provide an empty array `[]` to clear all expressions on update.
* Invalid expressions will result in a 10400 Bad Request with details in the `messages` array.