# Parameters

This page lists every `Parameter` field with its JSON key, default, and where it applies, plus tuning directions for common situations.

## Default Rules

A numeric field `<= 0` receives its default; `BlockTimeMin`, `BlockTimeMax`, and `HighRiskCountry` have none. Defaults are written back into `Config` on the first request that uses the field, not in `New()`.

## Rates and Tiers

| Field | JSON key | Default | Applies to |
|---|---|---|---|
| `RateLimitNormal` | `rate_limit_normal` | `100` | Per-IP per-minute limit (every request) |
| `RateLimitSuspicious` | `rate_limit_suspicious` | `50` | Suspicious-tier limit |
| `RateLimitDangerous` | `rate_limit_dangerous` | `20` | Dangerous-tier limit |
| `ScoreSuspicious` | `score_suspicious` | `50` | Suspicious-tier threshold |
| `ScoreDangerous` | `score_dangerous` | `80` | Dangerous-tier threshold |
| `ScoreNormal` | `score_normal` | - | Unused |

## Correlation Thresholds and Scores

| Threshold field | JSON key | Default | Score field | JSON key | Default |
|---|---|---|---|---|---|
| `SessionMultiIP` | `session_multi_ip` | `4` | `ScoreSessionMultiIP` | `score_session_multi_ip` | `25` |
| `IPMultiDevice` | `ip_multi_device` | `8` | `ScoreIPMultiDevice` | `score_ip_multi_device` | `20` |
| `DeviceMultiIP` | `device_multi_ip` | `4` | `ScoreDeviceMultiIP` | `score_device_multi_ip` | `15` |
| `LoginFailure` | `login_failure` | `4` | `ScoreLoginFailure` | `score_login_failure` | `15` |
| `NotFound404` | `not_found_404` | `8` | `ScoreNotFound404` | `score_not_found_404` | `15` |

## Behavior, Fingerprint, and Geo Scores

| Field | JSON key | Default | Page |
|---|---|---|---|
| `ScoreIntervalRequest` | `score_interval_request` | `25` | [Behavior Signals](/behavior-signals) |
| `ScoreFrequencyRequest` | `score_frequency_request` | `0` (no default) | [Behavior Signals](/behavior-signals) |
| `ScoreLongConnection` | `score_long_connection` | `15` | [Behavior Signals](/behavior-signals) |
| `ScoreFpMultiSession` | `score_fp_multi_session` | `50` | [Session and Fingerprint](/session-fingerprint) |
| `ScoreGeoHighRisk` | `score_geo_high_risk` | `30` | [Geo Detection](/geo-detection) |
| `ScoreGeoHopping` | `score_geo_hopping` | `15` | [Geo Detection](/geo-detection) |
| `ScoreGeoFrequentSwitch` | `score_geo_frequent_switch` | `20` | [Geo Detection](/geo-detection) |
| `ScoreGeoRapidChange` | `score_geo_rapid_change` | `25` | [Geo Detection](/geo-detection) |
| `HighRiskCountry` | `high_risk_country` | `[]` | [Geo Detection](/geo-detection) |

## Blocking

| Field | JSON key | Default | Applies to |
|---|---|---|---|
| `BlockTimeMin` | `block_time_min` | none (required) | First block duration |
| `BlockTimeMax` | `block_time_max` | none (required) | Cap for repeated blocks |
| `BlockToBan` | `block_to_ban` | `8` | Requests while blocked before escalating to Deny (never runs today) |

What 0 does is covered in [Temporary Blocking](/blocking).

## Tuning

| Situation | Suggestion |
|---|---|
| Large NAT egress (corporate, campus) | Raise `IPMultiDevice`, or allow-list the egress IP |
| Login endpoint should react faster to brute force | Lower `LoginFailure` to 2–3, or raise `ScoreLoginFailure` to 25 or more |
| Public API needs more throughput | Raise `RateLimitNormal`; keep the suspicious and dangerous limits low |
| Too many false positives | Raise `ScoreSuspicious` / `ScoreDangerous` first rather than lowering each signal's score |
