{"_id":"@codespar/mcp-sift","_rev":"5-49dd6993ad303c8ad89958a472b053a8","name":"@codespar/mcp-sift","dist-tags":{"latest":"0.2.0-alpha.3","alpha":"0.2.0-alpha.2"},"versions":{"0.1.0-alpha.1":{"name":"@codespar/mcp-sift","version":"0.1.0-alpha.1","keywords":["mcp","sift","sift-science","fraud","fraud-detection","risk-scoring","machine-learning","payment-abuse","account-abuse","content-abuse","chargebacks","decisions","global","enterprise"],"license":"MIT","_id":"@codespar/mcp-sift@0.1.0-alpha.1","maintainers":[{"name":"codespar-npm","email":"contact@codespar.dev"}],"bin":{"mcp-sift":"dist/index.js"},"dist":{"shasum":"38d8abc4932e6a5a4c609374ea5996f9a064ba31","tarball":"https://registry.npmjs.org/@codespar/mcp-sift/-/mcp-sift-0.1.0-alpha.1.tgz","fileCount":7,"integrity":"sha512-X5aZizVTeptgfEm43UNtlIXeETg/foAKmC+5l+6vYnSj5fhLcK4roHiWwsPmkgjf7vylAgmH8SIMgRuOAqN7TA==","signatures":[{"sig":"MEUCIQD+LTI1ggNLFJclCvoAJGXpyjl+FEmyHc7V5jbke2TbXwIgbu6gmlgJqfrDVyak81KWgGG3a71Kb/euASdNutDTtjQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":61876},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","gitHead":"8f8994b2acdc8be3a6c666b30ef44974f33752ed","mcpName":"io.github.codespar/mcp-sift","scripts":{"build":"tsc","start":"node dist/index.js"},"_npmUser":{"name":"codespar-npm","email":"contact@codespar.dev"},"_npmVersion":"11.8.0","description":"MCP server for Sift — global enterprise ML-based fraud detection, real-time risk scoring (payment/account/content abuse), decisions workflows, and event ingestion","directories":{},"_nodeVersion":"25.5.0","dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.8.0","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-sift_0.1.0-alpha.1_1776997192457_0.8108681629481327","host":"s3://npm-registry-packages-npm-production"}},"0.2.0-alpha.1":{"name":"@codespar/mcp-sift","version":"0.2.0-alpha.1","keywords":["mcp","sift","sift-science","fraud","fraud-detection","risk-scoring","machine-learning","payment-abuse","account-abuse","content-abuse","chargebacks","decisions","global","enterprise"],"license":"MIT","_id":"@codespar/mcp-sift@0.2.0-alpha.1","maintainers":[{"name":"codespar-npm","email":"contact@codespar.dev"}],"bin":{"mcp-sift":"dist/index.js"},"dist":{"shasum":"08445d566e8e2edb157847a3572d0c01ed019b98","tarball":"https://registry.npmjs.org/@codespar/mcp-sift/-/mcp-sift-0.2.0-alpha.1.tgz","fileCount":7,"integrity":"sha512-Rhgj1pR0RS3+86lL3sQk/7wyGK55HGlAxKFaj9oFHXn8gXyuWwiATLEqCTQQ/1395yxxNDMVfeMsOQB2qBrLQg==","signatures":[{"sig":"MEQCICUptAtQprF6eN589vpqMXsP//GqAkGxfv9ueig0seB0AiBYlWk6B/xeJSvu+xHiAZebC69PBmff2SWmL4MR4wJ1bw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":99591},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","gitHead":"16948c85b03c82fa9da581a7a3e62981ce6e211e","mcpName":"io.github.codespar/mcp-sift","scripts":{"build":"tsc","start":"node dist/index.js"},"_npmUser":{"name":"codespar-npm","email":"contact@codespar.dev"},"_npmVersion":"11.8.0","description":"MCP server for Sift — global enterprise ML-based fraud detection, real-time risk scoring (payment/account/content abuse), decisions workflows, and event ingestion","directories":{},"_nodeVersion":"25.5.0","dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"typescript":"^5.8.0","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-sift_0.2.0-alpha.1_1777117984185_0.7493637409866047","host":"s3://npm-registry-packages-npm-production"}},"0.2.0-alpha.2":{"name":"@codespar/mcp-sift","version":"0.2.0-alpha.2","keywords":["mcp","sift","sift-science","fraud","fraud-detection","risk-scoring","machine-learning","payment-abuse","account-abuse","content-abuse","chargebacks","decisions","global","enterprise"],"license":"MIT","_id":"@codespar/mcp-sift@0.2.0-alpha.2","maintainers":[{"name":"codespar-npm","email":"contact@codespar.dev"}],"bin":{"mcp-sift":"dist/index.js"},"dist":{"shasum":"6c482ad5f16999db81e0357d8943a11bb1b5a3c5","tarball":"https://registry.npmjs.org/@codespar/mcp-sift/-/mcp-sift-0.2.0-alpha.2.tgz","fileCount":7,"integrity":"sha512-kTJjDZMxe99b1K3lhRSjGFK70aqU3hx2PwZjXYgbYN4lDitCi03QDt7yli9P3cfH1asy+BVgQVj5qn1o+S+jhQ==","signatures":[{"sig":"MEQCIFRxQk4bgnyMCKPap9umBq3EBwblqZSY633sSFVbYHvQAiAMfNfICdAO8mOdKcZs+y4UZK4iIrs1NZATegtKuP9mjA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":101024},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","gitHead":"0ab801a863239f0cb986bbda65abbaee3c621b44","mcpName":"io.github.codespar/mcp-sift","scripts":{"build":"tsc","start":"node dist/index.js"},"_npmUser":{"name":"codespar-npm","email":"contact@codespar.dev"},"_npmVersion":"11.8.0","description":"MCP server for Sift — global enterprise ML-based fraud detection, real-time risk scoring (payment/account/content abuse), decisions workflows, and event ingestion","directories":{},"_nodeVersion":"25.5.0","dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"typescript":"^5.8.0","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-sift_0.2.0-alpha.2_1777123104899_0.43537798821331997","host":"s3://npm-registry-packages-npm-production"}},"0.2.0-alpha.3":{"name":"@codespar/mcp-sift","version":"0.2.0-alpha.3","description":"MCP server for Sift — global enterprise ML-based fraud detection, real-time risk scoring (payment/account/content abuse), decisions workflows, and event ingestion","type":"module","main":"./dist/index.js","bin":{"mcp-sift":"dist/index.js"},"scripts":{"build":"tsc","start":"node dist/index.js"},"dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"devDependencies":{"@types/node":"^25.5.0","typescript":"^5.8.0"},"license":"MIT","keywords":["mcp","sift","sift-science","fraud","fraud-detection","risk-scoring","machine-learning","payment-abuse","account-abuse","content-abuse","chargebacks","decisions","global","enterprise"],"mcpName":"io.github.codespar/mcp-sift","_id":"@codespar/mcp-sift@0.2.0-alpha.3","gitHead":"e8f2ad023876683538fe7b66a2fc88ab8d8ef92f","types":"./dist/index.d.ts","_nodeVersion":"22.22.3","_npmVersion":"10.9.8","dist":{"integrity":"sha512-UhOyeS7AZnV2XcYdJWNOzPOnU9X+vmlQKzVj+/+uQp/i3Rxl5dz5bUtqpna0Pvf9wJ3IYcfvLtcFXbpIOyQf4Q==","shasum":"6ce4b2163754b7a08e253fd06f880e9484f3c7a9","tarball":"https://registry.npmjs.org/@codespar/mcp-sift/-/mcp-sift-0.2.0-alpha.3.tgz","fileCount":7,"unpackedSize":102451,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDecHwe1qVTEEqK/yE2gXLn+A6l5KS9MGPSKldLdbUgwgIhAKGzxr80h7YMrMx0By4qk+E6uDUvMS/lD51vMo1sKkcx"}]},"_npmUser":{"name":"codespar-npm","email":"fabiano@codespar.dev"},"directories":{},"maintainers":[{"name":"codespar-npm","email":"fabiano@codespar.dev"},{"name":"dangazineu","email":"daniel.gazineu@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-sift_0.2.0-alpha.3_1782153680464_0.6828255425939413"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-24T02:19:52.382Z","modified":"2026-06-22T18:41:20.792Z","0.1.0-alpha.1":"2026-04-24T02:19:52.603Z","0.2.0-alpha.1":"2026-04-25T11:53:04.337Z","0.2.0-alpha.2":"2026-04-25T13:18:25.116Z","0.2.0-alpha.3":"2026-06-22T18:41:20.644Z"},"license":"MIT","keywords":["mcp","sift","sift-science","fraud","fraud-detection","risk-scoring","machine-learning","payment-abuse","account-abuse","content-abuse","chargebacks","decisions","global","enterprise"],"description":"MCP server for Sift — global enterprise ML-based fraud detection, real-time risk scoring (payment/account/content abuse), decisions workflows, and event ingestion","maintainers":[{"name":"codespar-npm","email":"fabiano@codespar.dev"},{"name":"dangazineu","email":"daniel.gazineu@gmail.com"}],"readme":"# @codespar/mcp-sift\n\nMCP server for [Sift](https://sift.com) — global enterprise ML-based fraud detection.\n\nThird entry in the CodeSpar `fraud` category after [`@codespar/mcp-clearsale`](../clearsale) and [`@codespar/mcp-konduto`](../konduto). Sift is the global / enterprise counterpart to the two BR-native antifraud servers.\n\n## Positioning\n\n|                    | ClearSale                 | Konduto                               | Sift                                         |\n|--------------------|---------------------------|---------------------------------------|----------------------------------------------|\n| Geography          | Brazil                    | Brazil                                | Global (US-HQ, ~30 countries)                |\n| Founded            | 2001                      | 2014                                  | 2011                                         |\n| Strength           | Chargeback history db     | Behavioral device intelligence        | Multi-abuse-type ML + workflow decisions     |\n| Shape              | Score + manual review     | API-first, tight surface              | Event stream in, scores + decisions out      |\n| Scope              | Order fraud               | Order fraud                           | Payment, account, content, promotion abuse   |\n\nAlso distinct from [`@codespar/mcp-jumio`](../../kyc/jumio), which is global KYC / identity verification — a different layer than fraud scoring.\n\n## Sift's API shape\n\nSift is built around three APIs that work together:\n\n1. **Events API** (`/v205/events`) — you POST every interesting signal (account creation, login, order, chargeback, ...) as a `$`-prefixed event.\n2. **Score API** (`/v205/users/{user_id}/score`) — you GET the latest ML score for a user, or POST to force a rescore. Scores are floats in `[0, 1]` per abuse type (`payment_abuse`, `account_abuse`, `content_abuse`, `promotion_abuse`).\n3. **Decisions API v3** (`/v3/accounts/{account_id}/...`) — workflows in the Sift console turn scores into Decisions (`block_user_payment_abuse`, `approve_order_payment_abuse`, etc). You can apply a decision directly, read the current decisions on a user/order, or fetch the status of a workflow run.\n\n## Tools (20)\n\n| Tool | Purpose |\n|---|---|\n| `send_event` | Send a fraud signal to Sift's Events API (POST /v205/events). |\n| `get_user_score` | Fetch the latest Sift score(s) for a user (GET /v205/users/{user_id}/score). |\n| `rescore_user` | Force Sift to recompute a user's score right now (POST /v205/users/{user_id}/score). |\n| `label_user` | Label a user as fraud or not-fraud via the legacy Labels API (POST /v205/users/{user_id}/labels). |\n| `unlabel_user` | Remove any existing label on a user (DELETE /v205/users/{user_id}/labels). |\n| `apply_decision_to_user` | Apply a workflow Decision to a user (POST /v3/accounts/{account_id}/users/{user_id}/decisions). |\n| `apply_decision_to_order` | Apply a workflow Decision to a specific order (POST /v3/accounts/{account_id}/users/{user_id}/orders/{order... |\n| `get_user_decisions` | Fetch the decisions currently applied to a user (GET /v3/accounts/{account_id}/users/{user_id}/decisions). |\n| `get_order_decisions` | Fetch the decisions currently applied to an order (GET /v3/accounts/{account_id}/orders/{order_id}/decisions). |\n| `get_workflow_run` | Fetch the status of a Sift Workflow run (GET /v3/accounts/{account_id}/workflows/runs/{run_id}). |\n| `send_chargeback` | Send a $chargeback event to Sift's Events API (POST /v205/events). |\n| `send_login` | Send a $login event to Sift's Events API (POST /v205/events). |\n| `send_logout` | Send a $logout event to Sift's Events API (POST /v205/events). |\n| `send_content_status` | Send a $content_status event to Sift's Events API (POST /v205/events). |\n| `link_session_to_user` | Send a $link_session_to_user event to Sift's Events API (POST /v205/events). |\n| `send_custom_event` | Send a custom (merchant-defined) event to Sift's Events API (POST /v205/events). |\n| `apply_decision_to_session` | Apply a workflow Decision to a session (POST /v3/accounts/{account_id}/users/{user_id}/sessions/{session_id... |\n| `apply_decision_to_content` | Apply a workflow Decision to a content item (POST /v3/accounts/{account_id}/users/{user_id}/content/{conten... |\n| `get_session_decisions` | Fetch the decisions currently applied to a session (GET /v3/accounts/{account_id}/users/{user_id}/sessions/... |\n| `get_content_decisions` | Fetch the decisions currently applied to a content item (GET /v3/accounts/{account_id}/users/{user_id}/cont... |\n\n## Install\n\n```bash\nnpm install @codespar/mcp-sift@alpha\n```\n\n## Environment\n\n```bash\nSIFT_API_KEY=\"...\"         # required, secret\nSIFT_ACCOUNT_ID=\"...\"      # required for all Decisions API v3 calls\nSIFT_BASE_URL=\"...\"        # optional; defaults to https://api.sift.com\n```\n\n## Authentication\n\n- **Events API** — `$api_key` is injected into the JSON body. The server handles this automatically.\n- **Score API + Decisions API v3** — HTTP Basic, API key as username, empty password. The server handles the base64 encoding.\n\nPass the raw key in `SIFT_API_KEY`.\n\n## Typical flow\n\n1. Instrument your app: every signup, login, profile update, order, and chargeback becomes a `send_event` call with the right `$type`.\n2. On high-stakes moments (checkout, withdrawal), call `send_event` with `return_score: true` to get an inline decision.\n3. Or poll `get_user_score` / `get_order_decisions` asynchronously after a workflow run completes.\n4. For manual review outcomes, call `apply_decision_to_user` or `apply_decision_to_order` with a Decision ID configured in the Sift console and `source: \"MANUAL_REVIEW\"`.\n5. When a chargeback is confirmed, send a `$chargeback` event AND either `apply_decision_to_user` with a Block decision or `label_user` with `is_bad: true, abuse_type: \"payment_abuse\"`. Decisions are preferred for new integrations; Labels are kept for backward compatibility.\n\n## Alpha note\n\nShipped as `0.1.0-alpha.1`. All endpoint paths are verified against Sift's official Ruby SDK ([`SiftScience/sift-ruby`](https://github.com/SiftScience/sift-ruby)): `rest_api_path`, `user_score_api_path`, `users_label_api_path`, `user_decisions_api_path`, `order_decisions_api_path`, `workflow_status_path`, and the Decision `ApplyTo` path builder.\n\nScope vs. the original brief:\n\n- **Shipped & verified:** send_event, get_user_score, rescore_user, label_user, unlabel_user, apply_decision_to_user, apply_decision_to_order, get_user_decisions, get_order_decisions, get_workflow_run.\n- **Dropped — not in the public SDK:**\n  - `get_session_score` (`/v205/sessions/{session_id}/score`) — no equivalent helper in the Ruby SDK; session-level scoring in Sift flows through session-level Decisions and Workflow runs, not a dedicated score endpoint.\n  - `list_workflow_runs` (`GET /v3/accounts/{account_id}/workflows/runs`) — only `GET /{run_id}` is implemented in the public SDK. In practice, Sift surfaces run_ids in event responses rather than via a list endpoint.\n  - `get_psychology_score` — no such endpoint in the public SDK.\n\nThe `developers.sift.com` reference pages gate deep-link URLs (403 on several paths), so we used the official SDK as the source of truth. Promote to `0.1.0` once a customer confirms (or denies) the dropped endpoints against the full Decisions / Score API reference in Sift's admin console.\n\n## Run\n\n```bash\n# stdio (default — for Claude Desktop, Cursor, etc)\nnpx @codespar/mcp-sift\n\n# HTTP (for server-to-server testing)\nMCP_HTTP=true MCP_PORT=3000 npx @codespar/mcp-sift\n```\n\n## Category\n\n`fraud` — third entry after ClearSale and Konduto. BR merchants operating internationally commonly pair Sift (global payment/account abuse) with ClearSale or Konduto (BR-specific chargeback history / device intelligence).\n\n## Enterprise\n\nNeed governance, budget limits, and audit trails for agent payments? [CodeSpar Enterprise](https://codespar.dev/enterprise) adds policy engine, payment routing, and compliance templates on top of these MCP servers.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}