Download the PHP
package kaidn/kaidn-php without Composer
On this page you can find all versions of the php package
kaidn/kaidn-php. It is possible to download/install
these versions without Composer. Possible dependencies are resolved
automatically.
After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.
Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.
In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories.
In this case some credentials are needed to access such packages.
Please use the auth.json textarea to insert credentials, if a package is coming from a private repository.
You can look here for more information.
Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
To use Composer is sometimes complicated. Especially for beginners.
Composer needs much resources. Sometimes they are not available on a simple webspace.
If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
# kaidn/kaidn-php
Official PHP client for [Kaidn](https://kaidn.io), the fraud and abuse scoring API.
Send one user action, get back `allow`, `review` or `block`, with the reasons attached.
**No Composer dependencies.** This runs in your signup and checkout path, so every package
it pulled in would be one more thing that can break your deploy or appear in your audit.
It uses `ext-curl`, which is on effectively every PHP host including shared cPanel.
**PHP 7.4 and up**, deliberately. 7.4 is long past end of life upstream and it is what a
lot of the rewards and affiliate shops using this actually run: one live site on Kaidn
today is on 7.4.33. A client that refuses to install is worse than one written without
enums and constructor promotion.
Server-side only: it holds your secret key, so never expose it to a browser. The browser
half is [`@kaidn/fp`](https://www.npmjs.com/package/@kaidn/fp) and uses a separate
publishable key.
## Score an event
`event` is the only required key, and the name is yours to choose. Send whatever else you
already collect; the answer sharpens as you send more.
The three cases people actually use:
## Read the evidence
Every verdict shows its work. `key` is the config key you would edit to retune that check.
## Recognise a returning device: rung 1
A browser fingerprint is not a person: on production traffic one iOS Safari fingerprint
covers 2.30 different people. So use `resolved_id`, never `id`, and weigh it with
`collision_risk`.
Better still, stop guessing. Store the token Kaidn returns as a cookie on your own domain
and pass the request's `Cookie` header back next time:
Measured on one browser across two visits, with the IP changed in between:
| | visit 1 | visit 2 |
| --- | --- | --- |
| `resolution` | `probabilistic` | **`deterministic`** |
| `resolution_rung` | 2 | **1** |
| `collision_risk` | 0.12 | **0.01** |
**Your server has to set the cookie, not us.** Browsers judge a cookie by the domain that
sent `Set-Cookie`, so one set from your backend on your own domain is genuinely
first-party and lasts ~400 days. Anything a vendor sets from its own infrastructure is
capped at 7 days on Safari, including the CNAME'd "custom subdomain" setups other vendors
ask you to configure. No DNS record, no proxy.
**It is off until you pass `cookie`, deliberately.** Storing something on a visitor's
device needs consent or a strict-necessity basis under the ePrivacy Directive, and GDPR
legitimate interest does not substitute for it. You are the controller here.
## Dedupe one inbox, not one address
`[email protected]`, `[email protected]` and `[email protected]` are one mailbox.
Store both: mail the address they typed, dedupe on the canonical one.
## Everything the key can reach
If an endpoint takes an API key, it is a method here.
| | |
| --- | --- |
| `score($event)` | score one action |
| `scoreWithCookie($event, $cookieHeader)` | the same, carrying the device identity |
| `checkEmail()` `checkIp()` `checkPhone()` | judge one identifier, no event recorded |
| `batchScore()` `batchCheck()` `batchLists()` | bulk, 1 quota unit per row, 1000 per call |
| `lists()` `listAdd()` `listRemove()` | allow / blocklists |
| `config()` `setConfig()` | your weights and thresholds |
| `label()` | report a real outcome |
| `forget()` `suppressions()` | GDPR erasure and its audit |
| `events()` `stats()` | read your own data |
| `graphSharing()` | opt into the cross-operator graph |
| `health()` | public liveness and intel dataset sizes |
Runnable versions in [`examples/`](examples/).
## Errors
Everything throws `Kaidn\KaidnException`, carrying the API's own message.
Network failures, timeouts, 429s and 5xx are retried automatically (2 extra attempts,
honouring `Retry-After`). A 4xx is not: a bad key fails identically the second time, and
retrying only spends quota and delays the error reaching whoever can fix it.
**Fail open.** A fraud vendor that can take down your signup form is a worse problem than
the fraud:
## Fields we have not named yet
Every response keeps what this version does not recognise, so a signal the API ships next
week reaches code running the release you installed last year.
Requests work the same way: any extra key in the array you pass to `score()` is sent
untouched.
## Configuration
## Links
- [Docs](https://kaidn.io/docs) · [Guides](https://kaidn.io/docs/guides) · [Glossary](https://kaidn.io/glossary)
- [Pricing](https://kaidn.io/pricing): 10,000 events a month free, no card
MIT
Requiresphp Version
>=7.4 ext-curl Version
* ext-json Version
*
Composer command for our command line client (download client)This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free.Standard composer command
The package kaidn/kaidn-php contains the following files
Loading the files please wait ...
Loading please wait ...
Before you can download the PHP files, the dependencies should be resolved. This can take some minutes. Please be patient.