v51

latestOpenAPI 3.0.0raw.githubusercontent.com2026-07-313352,3122.9 MB
plaid

Create a Protect report

Use this endpoint to create a Protect report to document fraud incidents, investigation outcomes, or other risk events. This endpoint allows you to report various types of incidents including account takeovers, identity fraud, unauthorized transactions, and other security events. The reported data helps improve fraud detection models and provides valuable feedback to enhance the overall security of the Plaid network. Reports can be created for confirmed incidents that have been fully investigated, or for suspected incidents that require further review. You can associate reports with specific users, sessions, or transactions to provide comprehensive context about the incident. Each report must include user_id, or an incident_event with at least one supported identifier: link_session_id, idv_session_id, protect_event_id, signal_client_transaction_id, or access_token. Context fields such as internal_reference, time, amount, and bank_account do not satisfy this identifier requirement.

post/protect/report/create

Request body

client_idstring

Your Plaid API client_id. The client_id is required and may be provided either in the PLAID-CLIENT-ID header or as part of a request body.

secretstring

Your Plaid API secret. The secret is required and may be provided either in the PLAID-SECRET header or as part of a request body.

user_idstring

The Plaid User ID associated with the report.

report_confidence'CONFIRMED' | 'SUSPECTED' required

The confidence level of the incident report. CONFIRMED indicates the incident has been verified and definitively occurred.

SUSPECTED indicates the incident is believed to have occurred but has not been fully verified.

report_type'USER_ACCOUNT_TAKEOVER' | 'FALSE_IDENTITY' | 'STOLEN_IDENTITY' | 'SYNTHETIC_IDENTITY' | 'MULTIPLE_USER_ACCOUNTS' | 'SCAM_VICTIM' | 'BANK_ACCOUNT_TAKEOVER' | 'BANK_CONNECTION_REVOKED' | 'CARD_TESTING' | 'UNAUTHORIZED_TRANSACTION' | 'CARD_CHARGEBACK' | 'ACH_RETURN' | 'DISPUTE' | 'FIRST_PARTY_FRAUD' | 'MISSED_PAYMENT' | 'LOAN_STACKING' | 'MONEY_LAUNDERING' | 'NO_FRAUD' | 'OTHER' required

The type of incident being reported.

USER_ACCOUNT_TAKEOVER - Indicates that a legitimate user's account was accessed or controlled by an unauthorized party.

FALSE_IDENTITY - Indicates that a user created an account using stolen or fabricated identity information.

STOLEN_IDENTITY - Indicates that a user created an account using identity information belonging to a real individual without their consent.

SYNTHETIC_IDENTITY - Indicates that a user created an account using a fake or partially fabricated identity (e.g., combining real and fake information to form a new persona).

MULTIPLE_USER_ACCOUNTS - Indicates that the same individual is operating multiple accounts in violation of policy.

SCAM_VICTIM - Indicates that the user was tricked into authorizing or sending funds as part of a scam.

BANK_ACCOUNT_TAKEOVER - Indicates that a user's linked bank account was accessed or misused by an unauthorized party.

BANK_CONNECTION_REVOKED - Indicates that a linked bank account connection was revoked by the financial institution, often due to suspected misuse, fraud, or security concerns.

CARD_TESTING - Indicates that a card was used in small or repeated transactions to test its validity.

UNAUTHORIZED_TRANSACTION - Indicates that a transaction was made without the user's consent or authorization.

CARD_CHARGEBACK - Indicates that a card transaction was reversed via a chargeback claim.

ACH_RETURN - Indicates that an ACH transaction was returned or reversed by the bank.

DISPUTE - Indicates that a user filed a dispute regarding a transaction or account activity.

FIRST_PARTY_FRAUD - Indicates that a user intentionally misrepresented themselves or their actions for financial gain.

MISSED_PAYMENT - Indicates that a user failed to make a required payment on time.

LOAN_STACKING - Indicates that a user applied for or took out multiple loans simultaneously beyond their ability to repay.

MONEY_LAUNDERING - Indicates that funds are being moved through accounts to obscure their illicit origin.

NO_FRAUD - Indicates that an investigation determined no fraudulent activity occurred on user/event (positive label).

OTHER - Indicates that the case involves fraud or financial risk not covered by other report types. Requires notes describing the report.

report_source'INTERNAL_REVIEW' | 'USER_SELF_REPORTED' | 'BANK_FEEDBACK' | 'NETWORK_FEEDBACK' | 'AUTOMATED_SYSTEM' | 'THIRD_PARTY_ALERT' | 'OTHER' required

The source that identified or reported the incident.

INTERNAL_REVIEW - Incident was identified through internal fraud investigations or review processes.

USER_SELF_REPORTED - Incident was reported directly by the affected user.

BANK_FEEDBACK - Incident was identified through bank feedback, including ACH returns and connection revocations.

NETWORK_FEEDBACK - Incident was identified through card network alerts or chargebacks.

AUTOMATED_SYSTEM - Incident was detected by automated systems such as fraud models or rule engines.

THIRD_PARTY_ALERT - Incident was identified through external vendor or consortium alerts.

OTHER - Incident was identified through a source not covered by other categories.

ach_return_codestring nullable

Must be a valid ACH return code (e.g. R01), required if report_type is ACH_RETURN.

notesstring nullable

Additional context or details about the report, required if report_type is OTHER.

Response

OK

report_idstring required

A unique identifier representing the submitted report.

request_idstring required

A unique identifier for the request, which can be used for troubleshooting. This identifier, like all Plaid identifiers, is case sensitive.