> ## Documentation Index
> Fetch the complete documentation index at: https://docs.clausum.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Add blocklist entry



## OpenAPI

````yaml /api-reference/openapi.json post /api/v1/blocklists
openapi: 3.1.0
info:
  title: Clausum API
  version: 1.3.0
  description: >-
    REST API for real-time fraud risk assessment (pay-in and payout), fraud
    reporting, blocklist management, and event ingestion. API version 1.3.0.
    Create Partner API keys (`clm_pub_*`, `clm_sk_*`) in the dashboard under
    Conexiones → Claves API. Webhook ingest uses separate `clm_wh_*` keys
    (Conexiones → Entrada webhooks).
  contact:
    name: Clausum API Support
    email: api@clausum.ai
    url: https://clausum.ai
servers:
  - url: https://sandbox.clausum.ai
    description: Sandbox — integrators and trials
  - url: https://dashboard.clausum.ai
    description: Production dashboard and Partner API
security:
  - apiKeyAuth: []
tags:
  - name: Risk
    description: Real-time risk scoring for pay-in checkout and sessions.
  - name: Payout
    description: Outbound disbursement and treasury transfer assessment.
  - name: Fraud
    description: Report confirmed fraud and trigger the downstream chain.
  - name: Blocklists
    description: Manage dynamic blocklists used during assessment.
  - name: Cases
    description: Manage fraud cases (expedientes) and submit them to regulators.
  - name: Events
    description: Ingest raw events from your payment providers.
  - name: System
    description: Health and status checks.
paths:
  /api/v1/blocklists:
    post:
      tags:
        - Blocklists
      summary: Add blocklist entry
      operationId: createBlocklistEntry
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateBlocklistEntry'
            examples:
              block_email:
                value:
                  list_type: email
                  value: fraudster@example.com
                  severity: block
                  reason: Confirmed chargeback fraud
      responses:
        '201':
          description: Entry created
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/BlocklistEntry'
        '400':
          $ref: '#/components/responses/ValidationError'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '409':
          $ref: '#/components/responses/Conflict'
      security:
        - dashboardAuth: []
components:
  schemas:
    CreateBlocklistEntry:
      type: object
      required:
        - list_type
        - value
      properties:
        list_type:
          $ref: '#/components/schemas/BlocklistType'
        value:
          type: string
        flow_scope:
          $ref: '#/components/schemas/BlocklistFlowScope'
        severity:
          type: string
          enum:
            - block
            - flag
            - review
          default: block
        reason:
          type: string
        source:
          type: string
          enum:
            - manual
            - rule
            - fraud_report
            - chargeback
            - api
          default: manual
        expires_at:
          type: string
          format: date-time
    BlocklistEntry:
      type: object
      properties:
        id:
          type: string
          format: uuid
        organization_id:
          type: string
          format: uuid
        list_type:
          $ref: '#/components/schemas/BlocklistType'
        value:
          type: string
        flow_scope:
          $ref: '#/components/schemas/BlocklistFlowScope'
        severity:
          type: string
          enum:
            - block
            - flag
            - review
        reason:
          type: string
          nullable: true
        source:
          type: string
          enum:
            - manual
            - rule
            - fraud_report
            - chargeback
            - api
        is_active:
          type: boolean
        expires_at:
          type: string
          format: date-time
          nullable: true
        created_at:
          type: string
          format: date-time
    BlocklistType:
      type: string
      enum:
        - email
        - email_domain
        - ip_address
        - ip_range
        - device_fingerprint
        - card_bin
        - card_hash
        - country
        - phone
        - customer_id
        - clabe
        - iban
        - account_hash
        - swift_bic
        - beneficiary_id
    BlocklistFlowScope:
      type: string
      enum:
        - payin
        - payout
        - all
      default: all
    ApiError:
      type: object
      properties:
        error:
          oneOf:
            - type: string
            - type: object
              properties:
                code:
                  type: string
                message:
                  type: string
                details:
                  type: object
                  additionalProperties: true
  responses:
    ValidationError:
      description: Invalid request body or parameters
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
    Unauthorized:
      description: Missing or invalid credentials
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
    Forbidden:
      description: Authenticated but lacking permission
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
    Conflict:
      description: Resource already exists
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
  securitySchemes:
    apiKeyAuth:
      type: http
      scheme: bearer
      description: >-
        Partner secret or publishable key, e.g. `clm_sk_...` or `clm_pub_...`
        (assess only).
      x-default: clm_sk_your_secret_key
    dashboardAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Supabase session JWT for dashboard / management endpoints, obtained
        after user sign-in.

````