Automation mode · demo

ReturnShield

Return-fraud and chargeback workflow automation. Enthernet Services, Bring Back Automation Before AI, Campaign Build #1.

How it works · Public API · Demo access · Dashboard · Read the LinkedIn post ↗

Pipeline

  1. Signed webhook intake: HMAC, timestamp, event type and replay checks
  2. Idempotent case creation
  3. Evidence collection, stored immutable and SHA-256 hashed
  4. Identity resolution across email, address and card fingerprint
  5. Deterministic risk rules, each factor explained and evidence-cited
  6. Routing: auto-process, manual review or escalate
  7. Role-gated human approval with required reasons
  8. Append-only, hash-chained audit log

Intake endpoint

POST /webhooks/shopify/<merchant_id>

Requires X-Shopify-Hmac-Sha256, X-Shopify-Topic and X-Shopify-Webhook-Id. Unsigned or replayed requests are rejected.

Rules the code enforces

How it works

A real run of the engine on this server, against the synthetic merchant M-DEMO (“DemoStore”). Everything below is loaded live from the public API.

All data here is mock-up data. The merchant, customers, orders, emails, addresses, card fingerprints and carrier records are fixtures written for this demo. Nothing comes from a real shop, and no real money moves.

Loading the demo case…

Public API (read-only, synthetic data)

Open to anyone, no key needed. Only the demo merchant M-DEMO is exposed. Rate-limited.

MethodPathReturns
GET/api/cases/M-DEMOAll cases with score, level, route, status
GET/api/cases/M-DEMO/<case_id>One case with risk factors, evidence (with SHA-256 hashes) and its audit trail
POST/webhooks/shopify/M-DEMOSigned return-request intake (Shopify-style HMAC). Unsigned or replayed requests are rejected.

Try it

curl https://returnshield.enthernetservice.com/api/cases/M-DEMO
curl https://returnshield.enthernetservice.com/api/cases/M-DEMO/RS-…

Webhook signing: X-Shopify-Hmac-Sha256 = base64(HMAC-SHA256(secret, raw_body)), plus X-Shopify-Topic: returns/request and a unique X-Shopify-Webhook-Id. A repeated webhook ID returns duplicate_ignored and creates nothing.

Demo access

The case dashboard is password-protected to show how a merchant would see it. These are demo credentials for synthetic data only.

Dashboard
returnshield.enthernetservice.com/dashboard/
Username
admin
Password
DJ60swFuFBYDrItQkf5e
Merchant
M-DEMO (DemoStore, fictional)