KYT event types
All KYT webhook payloads include a top-level
eventId (UUID) that you can use as an idempotency key to safely ignore duplicate deliveries.Alert events
tm.alert.created
Youverify fires this event when the transaction monitoring engine evaluates a transaction and a rule threshold is breached, creating a new alert. This is the primary event to subscribe to for real-time fraud response.
Example payload
Alert payload fields
string
Unique ID of the alert record.
string
Severity of the alert. See alert severity values below.
number
Score assigned by the triggered rule (0–100).
number
Combined weighted risk score across all triggered rules.
string
Recommended action from the rule:
Reject, Warning, or Review.string
Risk category label, for example
Fraud, AML, Structuring.array
IDs of the transactions that triggered this alert.
number
Cumulative transaction value (in minor currency units) that is considered at risk.
string
Current alert status. Starts as
UN_ACTIONED. Updates are delivered via tm.alert.updated.Evaluation events
tm.evaluation.completed
Youverify fires this event when a transaction evaluation run completes — either because all rules finished processing, or because a rule threshold breach was detected.
Example payload
Evaluation payload fields
array
List of rules that fired during this evaluation, each with
tag, ruleScore, ruleId, and ruleAction.number
Total transaction value considered at risk in this evaluation.
string
ISO 4217 currency code of the evaluated transactions.
Alert severity values
Thedata.riskLevel field uses the following severity levels:
Client events
Youverify firestm.client.created and tm.client.updated events whenever a client record in the KYT service is created or modified. These events allow you to keep your own customer records in sync with the Youverify KYT service.
How to triage alerts
When your system receives atm.alert.created event, you have two options for triaging it:
Triage via Dashboard
Open the alert in the Cowork dashboard at cowork.youverify.co, review the transaction details, and record your decision (approve, reject, escalate, or dismiss).
Triage via Cases API
Use the Cases API to programmatically open a case for the alert, assign it to an analyst, and record the triage decision. See the Case Management reference for endpoint details.