# Retrieve risk score rules

Retrieves risk score rules.

Endpoint: GET /risk-score-rules
Version: latest
Security: SecretApiKey, JWT

## Security:

  - `SecretApiKey` (unknown)
    apiKey in header REB-APIKEY

  - `JWT` (unknown)
    http bearer JWT

## Response 200:

  - `200` (unknown)
    Risk score rules retrieved.

## Response 200 fields (application/json):

  - `isProxy` (object | null, required)

  - `isProxy.value` (integer, required)
    Value added to the risk score of the transaction.

  - `paymentInstrumentVelocity` (object | null, required)

  - `paymentInstrumentVelocity.brackets` (array, required)
    Risk factor values range with corresponding risk score increment value.
The first matched bracket is applied.

  - `paymentInstrumentVelocity.brackets.start` (integer | null)
    Minimal risk factor value when condition is applied.

  - `paymentInstrumentVelocity.brackets.end` (integer | null)
    Maximal risk factor value when condition is applied.

  - `paymentInstrumentVelocity.brackets.value` (integer, required)
    Value added to the risk score of the transaction.

  - `paymentInstrumentVelocity.brackets.end` (any)

  - `paymentInstrumentVelocity.brackets.start` (any)

## Response 401:

  - `401` (unknown)
    Unauthorized access.
Invalid credentials used.

## Response 401 fields (application/json):

  - `status` (integer)
    HTTP status code.

  - `type` (string)
    Problem type in the form of a [URI](https://tools.ietf.org/html/rfc3986) reference.
It should provide human-readable documentation for the problem type.
When this member is not present, its value is assumed to be "about:blank".

  - `title` (string)
    Short, human-readable summary of the problem type.
Other than for the purposes of localization, this should not change from occurrence to occurrence of the problem.

  - `detail` (string)
    Human-readable explanation that is specific to this occurrence of the problem.

  - `instance` (string)
    URI reference that identifies the specific occurrence of the problem.
It may or may not yield further information if dereferenced.

## Response 403:

  - `403` (unknown)
    Access forbidden.

## Response 403 fields (application/json):

  - `status` (integer)
    HTTP status code.

  - `type` (string)
    Problem type in the form of a [URI](https://tools.ietf.org/html/rfc3986) reference.
It should provide human-readable documentation for the problem type.
When this member is not present, its value is assumed to be "about:blank".

  - `title` (string)
    Short, human-readable summary of the problem type.
Other than for the purposes of localization, this should not change from occurrence to occurrence of the problem.

  - `detail` (string)
    Human-readable explanation that is specific to this occurrence of the problem.

  - `instance` (string)
    URI reference that identifies the specific occurrence of the problem.
It may or may not yield further information if dereferenced.

