Skip to the operations

Identity verification

CAF in a decision flow.

2 CAF operations a decision flow can call directly, with the credentials your own contract issued. The response is data the rest of the flow reads, branches on, and keeps in the trace.

Category
Identity verification
Type
Integration
Authentication
OAuth 2.0 client credentials
Test environment
Production host only

Who they are

Brazilian identity verification and fraud prevention, formerly Combate à Fraude.

CAF runs document checks, face biometrics, liveness detection and background screening against Brazilian sources, and returns a verdict rather than a pile of evidence. Banks, fintechs and marketplaces use it at onboarding and again at moments where the stakes rise. The company now trades as Certta and its platform is called Trust.

What a flow can call

2 operations, each one a step you can place on the canvas.

  1. POST/v1/transactions

    Run a verification (create a transaction)

    Starts a verification and returns its id. templateId names the set of checks configured in Trust, so the same call performs a document check, a face match or a background screen depending on which template you point it at.

  2. GET/v1/transactions/$data.caf_transaction_id

    Read a verification's result

    The current state and result of a transaction. This is where the verdict lives once processing finishes, together with the individual rule outcomes that produced it — which is what an auditor asks for later, not the headline status.

Where it sits in the decision

Identity verification calls have a natural place in a flow.

An identity check gates everything downstream — a score computed against an unverified identity is a score about nobody. These calls sit near the top of a flow, with the branch for a partial or failed match written explicitly rather than left as an exception.

Whatever CAF returns is part of the run, so it is part of the record. When someone asks months later why an applicant was declined, the answer cites what came back at the time rather than re-fetching from a service whose answer has since changed.

  • 01Add CAF as a connection authenticating with OAuth 2.0 client credentials.
  • 02CAF has one host for both environments, so guard test runs with your own credentials and limits.
  • 03Place a Connection node and pick an operation — “Run a verification (create a transaction)” is usually the first one a flow needs.
  • 04Map the response into the fields your rules read, then test the whole path before it carries live traffic.

Common questions

Using CAF in a flow.

How do I connect CAF to a decision flow?

Add CAF as a connection in your workspace authenticating with OAuth 2.0 client credentials, with the credentials your own contract issued — ArboRule calls the provider as you, and never holds a contract on your behalf. Once the connection exists, any flow in the workspace can place a Connection node and choose one of its operations. The credentials live on the connection, not in the flow, so a policy owner can use CAF in a decision without ever seeing the secret.

Can I test CAF without touching production?

CAF exposes one host for both environments, so there is no separate sandbox to point at. Test runs still execute in Sandbox and are recorded separately in decision history, but the call goes to the same place as production — so guard it with your own test credentials, rate limits, or data.

What can a flow call on CAF?

2 operations: “Run a verification (create a transaction)”, “Read a verification's result”. Each one is a step you place on the canvas and map into the fields your rules read, and most flows start with “Run a verification (create a transaction)”. The list comes from the same manifest the engine uses to make the call, so this page cannot describe an operation the product does not have.

Where in a decision should CAF be called?

An identity check gates everything downstream — a score computed against an unverified identity is a score about nobody. These calls sit near the top of a flow, with the branch for a partial or failed match written explicitly rather than left as an exception.

Ready when you are

Wire CAF into a real decision.

Build the flow in Sandbox, connect your account, and watch the decision pull what it needs before it answers.

Read the docs