About Risk API 1.0

Risk API 1.0 extends the capabilities of Payment Risk Platform (PRP) to any financial technology companies and banks that do not use SoFi Tech Solutions as their card transaction processor to monitor suspicious card transaction behavior (debit, credit, BNPL, prepaid, etc.). To do so, you send transaction data via Risk API 1.0 along with a Risk Service ID (riskServiceID) assigned to you.

For Risk API 1.0 you use a different URL from other SoFi Tech Solutions APIs, and the status codes have a four-digit prefix (1701).

Base URL

For this API use the tenanted URL that SoFi Tech Solutions assigns you: https://risk-{corename}.{env}.gpsrv.com/endpointName, where

  • corename is the name of your core, as assigned by SoFi Tech Solutions.
  • env is the environment: cv for client validation and pd for production.

Authentication

Risk API 1.0 uses the same IP address whitelisting and credential approach as the Program API. You can choose to use your existing credentials or be issued new credentials for use with Risk API 1.0.

Follow the authentication steps for the Program API.

Connectivity

Risk API 1.0 does not have a dedicated connectivity endpoint. Basic credential validation and connectivity can be validated by calling the Get Card Transaction Fraud endpoint and receiving a successful response.

Endpoint responses

Risk API 1.0 requests and responses are conventional and are similar to Program API. Requests are made with form-encoded parameters in HTTP posts. Responses are available as JSON messages with snake_case field names.


© SoFi Technology Solutions, LLC 2026    Privacy Disclosure

All documentation, including but not limited to text, graphics, images, and any other content, are the exclusive property of SoFi Technology Solutions, LLC and are protected by copyright laws. These materials may not be reproduced, distributed, transmitted, displayed, or otherwise used without the prior written permission of SoFi Technology Solutions, LLC. Any unauthorized use or reproduction of these materials are expressly prohibited.