Download the PHP package preverus/preverus-php without Composer
On this page you can find all versions of the php package preverus/preverus-php. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download preverus/preverus-php
More information about preverus/preverus-php
Files in preverus/preverus-php
Package preverus-php
Short Description Framework-agnostic PHP client for Preverus fraud decisions, events, lookups, and webhooks.
License MIT
Homepage https://preverus.com
Informations about the package preverus-php
Preverus PHP
Framework-agnostic PHP client for Preverus backend enforcement.
Website: https://preverus.com
Documentation: https://preverus.com/docs
Use this package when your application already loads the hosted Preverus browser script and your backend needs to make trusted server-side calls with a private server key.
Install
Requires PHP 8.1+ and ext-json.
Browser And Server Flow
For server-rendered or non-JS-build sites, load the hosted script in your HTML:
Before submit, the script attaches:
Your backend sends those fields to Preverus with your private server key before approving sensitive actions.
Never put your server key in browser code.
Quick Start
Prefer risk_session_token when available. It references the stored browser session collected by the hosted script. The token lets Preverus use the full browser/device context without your backend handling raw browser feature vectors.
Configuration
Default retry behavior is intentionally conservative for web requests. The client retries transient network failures and these statuses:
The client does not retry validation or authentication errors such as 400, 401, 403, or 422.
For POST calls, pass an idempotency key when the operation may be retried:
Decisions
Recommended production behavior:
Events
Use events for fraud-relevant activity that does not need a synchronous decision.
Visitor Lookup
Metadata Lookup
Use metadata lookup for values such as email, phone, username, and payment address when you want to understand reuse across users or visitors.
Webhook Verification
Reject webhook requests when:
- The signature is missing or invalid.
- The timestamp is older than 5 minutes.
- The webhook ID has already been processed.
Webhook delivery is at-least-once, so store X-Fraud-Webhook-Id or payload id as an idempotency key.
You can also verify, parse, and dispatch events in one flow:
Error Handling
The core client throws exceptions for API and network failures:
If you want built-in fail-open/fail-review/fail-closed fallback decisions, use preverus/preverus-laravel or implement the same policy in your framework.
Production Checklist
- Use a browser key only in HTML or frontend code.
- Use a server key only on your backend.
- Prefer
risk_session_tokenfor decisions when present. - Include
X-Visitor-IDwhen available. - Send your real customer account ID as
user_id. - Include request IP and useful metadata such as email, phone, username, and payment address.
- Use idempotency keys for retried POST requests.
- Treat
reviewas step-up/manual review, not as an automatic allow.
All versions of preverus-php with dependencies
ext-json Version *