# Stop stolen cards before they become chargebacks.

Bots test stolen cards in bulk and some payments get through. Put the session’s verdict on each Stripe payment, so Radar or your team can review or step up the risky ones before you capture.

For merchants and payment teams taking cards through Stripe.

Status: Available with Expose

## A chargeback costs the order, the fee and your standing.

Card testing runs many small checkouts with stolen cards. Each approved one can come back weeks later as a chargeback: you lose the goods, pay a dispute fee, and your dispute rate climbs.

Expose attaches its verdict to the PaymentIntent (da_class, da_score, da_agent). A Radar rule can then send likely bots to review, or ask an agent for 3D Secure. Nothing changes until a rule or a person acts on it.

## Where 10,000 checkout attempts went

- Checkout attempts: 10,000
- Card-testing pattern: 400
- Approved fraudulent payments: 40
- Chargeback cost at stake: $4,200 (Avoided only when your Radar rule or review acts before capture.)

Illustrative example. 4% card-testing pattern; 10% of those approved; $90 average order plus a $15 dispute fee. Hypothetical.

## The same month, with and without the verdict on the payment.

| | Reported | With evidence |
|---|---|---|
| Payments sent to review | 0 | 400 |
| Chargebacks if not reviewed | 40 | 0 |
| Dispute cost | $4,200 | $0 |

Illustrative example.

## Your numbers

At stake = attempts × share card-testing × share approved × (order + dispute fee).

## One payment, before capture.

- PaymentIntent: pi_3Q…8kd
- da_class: bot
- Radar rule: Review if ::da_class:: = 'bot'
- Outcome: Held for review

The card is never charged until someone looks. A real customer’s agent would be asked for 3D Secure instead.

## How it fits

1. **Add a public key.** Tokens need a public key on the snippet; keyless installs cannot sign them.
2. **Get a token at checkout.** Call doubleagent.stripeToken() in the browser before confirming.
3. **Attach on the server.** Verify it and call attachVerdict with @doubleagent-so/node.
4. **Write Radar rules.** Review bots, step up agents on large amounts. Custom rules need Radar for Fraud Teams.

## What your team can do

- **Review likely bots.** Send bot-labelled payments to manual review before capture.
- **Step up agents.** Ask for 3D Secure when an agent pays a large amount.
- **Find card-testing bursts.** Spot runs of small automated checkouts in the Debrief.

## Before you start

### Will agents paying for real customers be blocked?

No. Agents are tagged, not refused. A rule can ask for 3D Secure, so a real cardholder can still pay.

### What if there is no token?

A missing token means unknown, not bot. Don’t write rules that treat it as fraud.

### Does Expose fight or win disputes?

No. It labels the payment; Stripe Radar and your team decide, and disputes stay with your normal process.

### Does Radar update when a session is relabelled?

Not automatically yet. Use the Debrief and call attachVerdict again.

[Install Expose](https://doubleagent.so/docs/stripe/)

- [Stripe guide](https://doubleagent.so/docs/stripe/)
- [Double Agent for e-commerce](https://doubleagent.so/for/ecommerce/)
- [Double Agent for fintech](https://doubleagent.so/for/fintech/)
