Spam, fraud and abuse checks as one API call
POST a submission and get back deliver, hold or drop, with a probability and the evidence, in about 160 ms. Node SDK, Python, Ruby and Elixir examples, signed webhooks, an MCP server, and a setup guide your coding agent can follow.
Free for 1,000 checks a month. Paid plans from $12. No card required.
Example: Doorman screening post /v1/check, each judged in under half a second and delivered or kept out with the reason.
Sound familiar?
Rolling your own means rules forever
Honeypots, timers and regex lists catch last year's bots and none of this year's humans, and someone has to maintain them.
Captcha libraries tax every real user
They add friction to your conversion path and still let paid spammers through.
Serious fraud tools want a sales call
Enterprise risk platforms mean contracts and integration projects. You wanted an endpoint.
An endpoint, not a project
- One request: form id or kind, the fields you have, optional signals. Response: route, action, p_real, reason, evidence.
- Fails open: the SDK returns hold on timeouts and network errors, so an outage never loses a submission.
- Webhooks: signed with HMAC-SHA256 and retried after 1 minute, 5 minutes, 30 minutes, 2 hours and 12 hours.
- Agents and MCP: /llms.txt, a signup API and a remote MCP server, so Claude Code, Codex or Cursor can wire it up for you.
curl https://withdoorman.com/v1/check \
-H "Authorization: Bearer $DOORMAN_KEY" \
-H "Content-Type: application/json" \
-d '{"form": "f_yourForm", "email": "jess@brightline.co",
"message": "We send 200 invoices a month. Demo?"}'
# {"route": "deliver", "action": "deliver", "p_real": 0.97,
# "reason": null, "evidence": "We send 200 invoices a month.", "latency_ms": 158}Checked, not guessed
Every decision comes from Doorman's models reading the submission, in milliseconds, with the reason attached.
Latency from 104 live checks on our labelled test set. Benchmark: the UCI YouTube Spam Collection, recall 0.980, 8.8% held for a person; questions were not tuned to it.
Questions
What are the rate limits?
600 API requests a minute per account. Hosted form endpoints accept 30 posts a minute per IP per form; beyond that submissions are stored as held rather than rejected.
What happens on a timeout?
The doorman-client SDK returns action hold with reason doorman_unreachable instead of throwing, so the submission is kept for review. With plain HTTP, treat any error the same way.
Which languages are supported?
Anything that can make an HTTPS request. There's a Node SDK with TypeScript types, and ready-made Python, Ruby, Elixir, Express and Next.js snippets from the snippet API.
How much does it cost?
Free for 1,000 checks a month. Pro is $12 a month for 25,000 and Business is $49 a month for 250,000. Every plan gets the same models. See pricing.
Try it on your own forms
Free for your first 1,000 checks every month. Start in watch mode and see every call before you trust it.