LayerCall scores a whole signup in one API call.
Most fraud tools answer one question at a time: is this IP a VPN, is this email disposable, is this phone real. LayerCall returns all of them together โ IP, email, phone, domain and device โ plus the relationships between them, which is where most fake signups actually show up. A brand-new domain paired with a datacenter IP and a throwaway mailbox is obvious in combination and unremarkable one field at a time.
Every response carries a 0โ100 risk score, an allow / review / block verdict, and the individual signals behind it, so a decision can be explained rather than just made. Strictness is tunable per request without re-scoring, and when a data source is unavailable the response says so rather than quietly scoring lower.
It also authorizes AI agents. Web Bot Auth signature verification tells you which agent is calling and whether it can prove it, and a policy engine decides what it may do โ a question classical fraud signals cannot answer, because an agent arrives with a real browser, a real fingerprint and a real mailbox.
Built for developers. REST, an MCP server for AI tooling, official Node and Python SDKs, a live demo that needs no signup, and a free tier that needs no card.
Bot Detection
Tor exit nodes, datacenter and residential proxies, headless browsers and unverified AI agents
Email Verification
Disposable and catch-all mailboxes, MX records, and domain age โ not just syntax
Device Fingerprinting
A browser fingerprint ties a device to a signup without relying on a cookie
Risk Scoring
0โ100 score with an allow / review / block verdict, and the signals behind it
Phone Validation
Line type, carrier and country, including premium-rate and VoIP numbers
REST API & Webhooks
14 endpoints, OpenAPI spec, Node and Python SDKs, and an MCP server for AI tools
Most fraud APIs answer one question per call โ is this IP a VPN, is this email disposable, is this phone real. LayerCall returns IP, email, phone, domain and device together, and scores the relationships between them. A brand-new domain paired with a datacenter IP and a throwaway mailbox is obvious in combination and unremarkable one field at a time.
Every response also carries the reasoning: a 0โ100 risk score, an allow / review / block verdict, and the individual signals behind it, so a decision can be explained rather than only made.
It treats AI agents as a first-class case as well. Web Bot Auth signature verification establishes which agent is calling and whether it can prove it, and a policy engine decides what it is allowed to do โ a question classical fraud signals cannot settle, because an agent arrives with a real browser, a real fingerprint and a real mailbox.
Because of what comes back in the response, not what it costs.
Every result carries a 0โ100 risk score, an allow / review / block verdict, and the individual signals behind it โ so a decision can be explained to a customer, a colleague or an auditor rather than only made. Strictness is tunable per request without re-scoring, which means the same integration can be strict at signup and forgiving at login.
Two smaller things tend to matter more in production than they sound. When a data source is unavailable, the response says so instead of quietly scoring lower, so an incomplete answer stays distinguishable from a clean one. And test keys return fixed, fictional data that never bills and never touches live reputation data, so a test suite can assert on exact values without polluting anything.
Beyond that, it is worth comparing directly rather than taking our word for it: the live demo runs the real scoring engine with no signup, and the free tier needs no card.
Developers and small product teams who need a trust decision at signup, login or checkout, and who would rather call one endpoint than integrate several vendors and reconcile their answers by hand.
In practice that means SaaS signups, marketplaces, fintech onboarding, and anyone whose free tier is being farmed by throwaway accounts.
A newer part of the audience is teams who suddenly have to decide what an AI agent may do on their site. That is a different question from classical fraud โ an agent can be entirely legitimate and still need a policy โ which is why agent verification sits in the same API rather than in a separate product.
It started from a specific frustration: the signal that actually catches a fake signup is usually a relationship between fields, and the tools available answered one field at a time.
Blocking disposable email domains stops very little on its own. The signups that matter use real mailboxes, often on domains registered days earlier, arriving from addresses that look entirely ordinary. What gives them away is the domain's age set against the IP's provider set against whether the phone is a VoIP line โ and assembling that meant several vendors, several response shapes, several bills, and writing the correlation by hand anyway.
LayerCall is that correlation as a product: one call, every signal, and the reasoning returned next to the score.
The AI-agent side came later, from the same observation in a new place. An agent has a real browser, a real fingerprint and a real mailbox, so nothing in a classical fraud stack has an opinion about it. What you need to know is which agent it is and whether it can prove it โ a signature problem, not a fraud-signal problem.
TypeScript on Next.js, running on Vercel's Fluid Compute, with Postgres (Supabase) behind accounts, keys and usage.
The scoring path is deliberately boring. No third-party SDK sits in the request path; every external feed is fetched under its own timeout inside a request-wide deadline, so one slow source cannot hold up a response. A feed that fails degrades the result rather than failing the call, and the response names any signal that was unavailable so the caller can tell the difference between a clean answer and an incomplete one.
On the client side: official Node/TypeScript and Python SDKs, Express and Next.js middleware, a published OpenAPI spec, and an MCP server so AI tools can call the API directly.
We have collected here some useful links to help you find out if LayerCall is good.
Check the traffic stats of LayerCall on SimilarWeb. The key metrics to look for are: monthly visits, average visit duration, pages per visit, and traffic by country. Moreoever, check the traffic sources. For example "Direct" traffic is a good sign.
Check the "Domain Rating" of LayerCall on Ahrefs. The domain rating is a measure of the strength of a website's backlink profile on a scale from 0 to 100. It shows the strength of LayerCall's backlink profile compared to the other websites. In most cases a domain rating of 60+ is considered good and 70+ is considered very good.
Check the "Domain Authority" of LayerCall on MOZ. A website's domain authority (DA) is a search engine ranking score that predicts how well a website will rank on search engine result pages (SERPs). It is based on a 100-point logarithmic scale, with higher scores corresponding to a greater likelihood of ranking. This is another useful metric to check if a website is good.
The latest comments about LayerCall on Reddit. This can help you find out how popualr the product is and what people think about it.
Do you know an article comparing LayerCall to other products?
Suggest a link to a post with product alternatives.
Is LayerCall good? This is an informative page that will help you find out. Moreover, you can review and discuss LayerCall here. The primary details have been verified within the last quarter. So they could be considered up to date. If you think we are missing something, please use the means on this page to comment or suggest changes. All reviews and comments are highly encouranged and appreciated as they help everyone in the community to make an informed choice. Please always be kind and objective when evaluating a product and sharing your opinion.