risk_signal_details object gives you concrete, named reason codes that explain why a session’s risk scores are elevated. It is returned as a sibling of risk_signals and risk_signal_scores inside the session object on POST /session/authenticate, POST /session/unauthenticated, and GET /session/{session_id}.
How signals relate to scores
Risk signals are consistent with the scores they explain: a session whose proxy and VPN scores read clean will never carry a proxy- or VPN-related signal, and a session whose device risk score reads clean will never carry a probe-based device signal. Some signals are deliberately independent of score levels because they are meaningful on their own: location-consistency signals such astrue_country_mismatch and outside_expected_countries, the network registry signals (new_asn, leased_network, network_registry_location_mismatch, network_operator_changed, network_block_holder_mismatch), and the administrative device-brand signals chinese_sanctioned_device and chinese_device, which describe a factual property of the device rather than risk evidence and are designed to be combined with location or other conditions in rules.
As risk scores increase, sessions typically carry more corroborating signals: a moderately risky session usually shows one or two reasons, while a highly risky session shows several.
Network Signals
Network signals explain theproxy, vpn, and location-related scores. They describe evidence that the session’s network path or claimed location is not what it appears to be. The network registry signals (new_asn through network_block_holder_mismatch) describe the network the IP belongs to, from public internet-registry and routing records; they are refreshed nightly and appear regardless of the session’s proxy and VPN scores.
Device Signals
Device signals explain thedevice_risk score. They describe evidence that the device or browser is tampered with, automated, virtualized, or otherwise not a normal personal device.
