Documentation v1.0.0

Parameters

This page lists every Parameter field with its JSON key, default, and where it applies, plus tuning directions for common situations.

Default Rules

A numeric field <= 0 receives its default; BlockTimeMin, BlockTimeMax, and HighRiskCountry have none. Defaults are written back into Config on the first request that uses the field, not in New().

Rates and Tiers

Field JSON key Default Applies to
RateLimitNormal rate_limit_normal 100 Per-IP per-minute limit (every request)
RateLimitSuspicious rate_limit_suspicious 50 Suspicious-tier limit
RateLimitDangerous rate_limit_dangerous 20 Dangerous-tier limit
ScoreSuspicious score_suspicious 50 Suspicious-tier threshold
ScoreDangerous score_dangerous 80 Dangerous-tier threshold
ScoreNormal score_normal - Unused

Correlation Thresholds and Scores

Threshold field JSON key Default Score field JSON key Default
SessionMultiIP session_multi_ip 4 ScoreSessionMultiIP score_session_multi_ip 25
IPMultiDevice ip_multi_device 8 ScoreIPMultiDevice score_ip_multi_device 20
DeviceMultiIP device_multi_ip 4 ScoreDeviceMultiIP score_device_multi_ip 15
LoginFailure login_failure 4 ScoreLoginFailure score_login_failure 15
NotFound404 not_found_404 8 ScoreNotFound404 score_not_found_404 15

Behavior, Fingerprint, and Geo Scores

Field JSON key Default Page
ScoreIntervalRequest score_interval_request 25 Behavior Signals
ScoreFrequencyRequest score_frequency_request 0 (no default) Behavior Signals
ScoreLongConnection score_long_connection 15 Behavior Signals
ScoreFpMultiSession score_fp_multi_session 50 Session and Fingerprint
ScoreGeoHighRisk score_geo_high_risk 30 Geo Detection
ScoreGeoHopping score_geo_hopping 15 Geo Detection
ScoreGeoFrequentSwitch score_geo_frequent_switch 20 Geo Detection
ScoreGeoRapidChange score_geo_rapid_change 25 Geo Detection
HighRiskCountry high_risk_country [] Geo Detection

Blocking

Field JSON key Default Applies to
BlockTimeMin block_time_min none (required) First block duration
BlockTimeMax block_time_max none (required) Cap for repeated blocks
BlockToBan block_to_ban 8 Requests while blocked before escalating to Deny (never runs today)

What 0 does is covered in Temporary Blocking.

Tuning

Situation Suggestion
Large NAT egress (corporate, campus) Raise IPMultiDevice, or allow-list the egress IP
Login endpoint should react faster to brute force Lower LoginFailure to 2–3, or raise ScoreLoginFailure to 25 or more
Public API needs more throughput Raise RateLimitNormal; keep the suspicious and dangerous limits low
Too many false positives Raise ScoreSuspicious / ScoreDangerous first rather than lowering each signal's score
中文