Automation mode · demo
ReturnShield
Return-fraud and chargeback workflow automation. Enthernet Services, Bring Back Automation Before AI, Campaign Build #1.
How it works · Public API · Demo access · Dashboard · Read the LinkedIn post ↗
Pipeline
- Signed webhook intake: HMAC, timestamp, event type and replay checks
- Idempotent case creation
- Evidence collection, stored immutable and SHA-256 hashed
- Identity resolution across email, address and card fingerprint
- Deterministic risk rules, each factor explained and evidence-cited
- Routing: auto-process, manual review or escalate
- Role-gated human approval with required reasons
- Append-only, hash-chained audit log
Intake endpoint
POST /webhooks/shopify/<merchant_id>
Requires X-Shopify-Hmac-Sha256, X-Shopify-Topic and X-Shopify-Webhook-Id. Unsigned or replayed requests are rejected.
Rules the code enforces
- Tenant isolation is enforced at the data store
- AI is advisory only and is never a routing input
- Refunds require an authorization record
- Customer free text is stored, never interpreted
How it works
A real run of the engine on this server, against the synthetic merchant M-DEMO (“DemoStore”). Everything below is loaded live from the public API.
Loading the demo case…
Public API (read-only, synthetic data)
Open to anyone, no key needed. Only the demo merchant M-DEMO is exposed. Rate-limited.
| Method | Path | Returns |
|---|---|---|
GET | /api/cases/M-DEMO | All cases with score, level, route, status |
GET | /api/cases/M-DEMO/<case_id> | One case with risk factors, evidence (with SHA-256 hashes) and its audit trail |
POST | /webhooks/shopify/M-DEMO | Signed return-request intake (Shopify-style HMAC). Unsigned or replayed requests are rejected. |
Try it
curl https://returnshield.enthernetservice.com/api/cases/M-DEMO
curl https://returnshield.enthernetservice.com/api/cases/M-DEMO/RS-…
Webhook signing: X-Shopify-Hmac-Sha256 = base64(HMAC-SHA256(secret, raw_body)), plus X-Shopify-Topic: returns/request and a unique X-Shopify-Webhook-Id. A repeated webhook ID returns duplicate_ignored and creates nothing.
Demo access
The case dashboard is password-protected to show how a merchant would see it. These are demo credentials for synthetic data only.
- Dashboard
- returnshield.enthernetservice.com/dashboard/
- Username
admin- Password
DJ60swFuFBYDrItQkf5e- Merchant
M-DEMO(DemoStore, fictional)