Parameters
This page lists every Parameter field with its JSON key, default, and where it applies, plus tuning directions for common situations.
Default Rules
A numeric field <= 0 receives its default; BlockTimeMin, BlockTimeMax, and HighRiskCountry have none. Defaults are written back into Config on the first request that uses the field, not in New().
Rates and Tiers
| Field | JSON key | Default | Applies to |
|---|---|---|---|
RateLimitNormal |
rate_limit_normal |
100 |
Per-IP per-minute limit (every request) |
RateLimitSuspicious |
rate_limit_suspicious |
50 |
Suspicious-tier limit |
RateLimitDangerous |
rate_limit_dangerous |
20 |
Dangerous-tier limit |
ScoreSuspicious |
score_suspicious |
50 |
Suspicious-tier threshold |
ScoreDangerous |
score_dangerous |
80 |
Dangerous-tier threshold |
ScoreNormal |
score_normal |
- | Unused |
Correlation Thresholds and Scores
| Threshold field | JSON key | Default | Score field | JSON key | Default |
|---|---|---|---|---|---|
SessionMultiIP |
session_multi_ip |
4 |
ScoreSessionMultiIP |
score_session_multi_ip |
25 |
IPMultiDevice |
ip_multi_device |
8 |
ScoreIPMultiDevice |
score_ip_multi_device |
20 |
DeviceMultiIP |
device_multi_ip |
4 |
ScoreDeviceMultiIP |
score_device_multi_ip |
15 |
LoginFailure |
login_failure |
4 |
ScoreLoginFailure |
score_login_failure |
15 |
NotFound404 |
not_found_404 |
8 |
ScoreNotFound404 |
score_not_found_404 |
15 |
Behavior, Fingerprint, and Geo Scores
| Field | JSON key | Default | Page |
|---|---|---|---|
ScoreIntervalRequest |
score_interval_request |
25 |
Behavior Signals |
ScoreFrequencyRequest |
score_frequency_request |
0 (no default) |
Behavior Signals |
ScoreLongConnection |
score_long_connection |
15 |
Behavior Signals |
ScoreFpMultiSession |
score_fp_multi_session |
50 |
Session and Fingerprint |
ScoreGeoHighRisk |
score_geo_high_risk |
30 |
Geo Detection |
ScoreGeoHopping |
score_geo_hopping |
15 |
Geo Detection |
ScoreGeoFrequentSwitch |
score_geo_frequent_switch |
20 |
Geo Detection |
ScoreGeoRapidChange |
score_geo_rapid_change |
25 |
Geo Detection |
HighRiskCountry |
high_risk_country |
[] |
Geo Detection |
Blocking
| Field | JSON key | Default | Applies to |
|---|---|---|---|
BlockTimeMin |
block_time_min |
none (required) | First block duration |
BlockTimeMax |
block_time_max |
none (required) | Cap for repeated blocks |
BlockToBan |
block_to_ban |
8 |
Requests while blocked before escalating to Deny (never runs today) |
What 0 does is covered in Temporary Blocking.
Tuning
| Situation | Suggestion |
|---|---|
| Large NAT egress (corporate, campus) | Raise IPMultiDevice, or allow-list the egress IP |
| Login endpoint should react faster to brute force | Lower LoginFailure to 2–3, or raise ScoreLoginFailure to 25 or more |
| Public API needs more throughput | Raise RateLimitNormal; keep the suspicious and dangerous limits low |
| Too many false positives | Raise ScoreSuspicious / ScoreDangerous first rather than lowering each signal's score |