# Marketplace scam detection

Marketplace scams rarely show up in a single message. A buyer asks a normal
question, then asks to move to WhatsApp, then offers to pay by wire "plus
shipping", then sends a link to a fake payment page. Keyword filters catch the
last step, if that. SigWise scores the **user**, over everything they have
said and done, so the pattern is visible as it forms.

## What to send

Send each user's activity as events on an object named after your user ID:

- **Messages** between buyers and sellers, with the listing in `metadata`.
- **Actions** that matter for fraud: sign-up, profile and payout changes,
  failed logins, listings created, reports by other users.
- **Context** in `metadata`: account age, country, price, amount.

```json
POST /v1/objects/user-42/events
{
  "object_type": "user",
  "events": [
    { "type": "event", "name": "account.created", "metadata": { "country": "NG" } },
    { "type": "message", "content": "is this still available? I'm abroad, can I pay by wire and my courier picks up?",
      "metadata": { "listing": "bike-221", "price": 450 } },
    { "type": "message", "content": "I sent $950 by mistake, please refund the difference to my cousin" }
  ]
}
```

Ingestion returns `202` right away. Events that arrive within a few seconds of
each other are analyzed together. See [Ingesting events](https://sigwise.ai/docs/guides/ingesting-events.md).

## The signals

Every account starts with `is_scammer`. Make its criteria concrete for your
marketplace. Describing the evidence steers the analyzer much more than words like
"suspicious" do:

```json
PUT /v1/signals/is_scammer
{
  "type": "noul",
  "instructions": "Decide whether this user is trying to defraud other users of the marketplace.",
  "criteria": {
    "true": "asks to pay or talk off-platform, overpays and asks for a refund, sends payment or courier links, pressures for urgency, story does not add up",
    "false": "ordinary questions about the item, price negotiation, arranging pickup on the platform"
  }
}
```

Add narrower signals when you want to act on them differently:

```json
PUT /v1/signals/scam_type
{
  "type": "choice",
  "instructions": "If this user is running a scam, which kind?",
  "criteria": {
    "none": null,
    "off_platform_payment": "moves payment outside the marketplace",
    "overpayment": "pays too much and asks for the difference back",
    "phishing": "sends links to fake payment or login pages",
    "account_takeover": "behaviour changes abruptly after a login from a new place"
  }
}
```

See [Signals](https://sigwise.ai/docs/guide/signals.md) for the three types.

## Acting on the answers

- **Block a message before it is delivered.** Send it with `"wait": true` and
  `"signals": ["is_scammer"]`, and hold it if the probability is high. See
  [Direct moderation](https://sigwise.ai/docs/guides/moderation.md).
- **Review queue.** List the riskiest users first:
  `GET /v1/objects?q=is_scammer >= 80&sort=flagged`. See
  [Search and conditions](https://sigwise.ai/docs/guides/queries.md).
- **Alert your team.** A [rule](https://sigwise.ai/docs/guides/rules.md) posts to Slack when a user
  crosses the line, once, not on every message:

```json
POST /v1/rules
{
  "name": "likely scammer",
  "when": "is_scammer >= 90",
  "action_type": "slack",
  "action_config": { "webhook_url": "https://hooks.slack.com/services/T000/B000/XXXX" }
}
```

- **Automate.** Subscribe a [webhook](https://sigwise.ai/docs/guides/webhooks.md) to
  `analysis.completed` and freeze payouts or hide listings in your own code.

## Cost

Each analysis is billed at its model cost, typically a fraction of a cent. A
short marketplace conversation costs about $0.0001. Bursts of messages are
folded into one analysis, so you pay per conversation turn, not per event.
See [Billing and usage](https://sigwise.ai/docs/guides/billing.md).

## Next steps

- [Quickstart](https://sigwise.ai/docs/guide/quickstart.md): your first signal, event and answer in five minutes.
- [User trust scores](https://sigwise.ai/docs/use-cases/user-trust-scores.md): rank users by trustworthiness, not only flag the worst.
