Transaction Security
Transaction Security — TRON Raw
POST
/
v2
/
hashdit
/
transaction-security
curl --request POST \
--url https://service.hashdit.io/v2/hashdit/transaction-security \
--header 'Content-Type: application/json' \
--header 'X-API-KEY: YOUR_API_KEY' \
--data '{
"dapp_url": "https://app.example.com",
"tron_transactions": [
{
"visible": false,
"raw_data": {
"contract": [
{
"type": "TriggerSmartContract",
"parameter": {
"type_url": "type.googleapis.com/protocol.TriggerSmartContract",
"value": {
"owner_address": "41aae8e079b632f89a3591a3c2264076a8e1536f57",
"contract_address": "41a614f803b6fd780986a42c78ec9c7f77e6ded13c",
"data": "095ea7b3000000000000000000000000e28b3cfd4e0e909077821478e9fcb86b84be786effffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"
}
}
}
],
"timestamp": 1757999940000,
"fee_limit": 15000000
}
}
]
}'
curl --request POST \
--url https://service.hashdit.io/v2/hashdit/transaction-security \
--header 'Content-Type: application/json' \
--header 'X-API-KEY: YOUR_API_KEY' \
--data '{
"dapp_url": "https://trust-wallet-verify.net",
"tron_transactions": [
{
"raw_data": {
"contract": [
{
"type": "AccountPermissionUpdateContract",
"parameter": {
"value": {
"owner_address": "41aae8e079b632f89a3591a3c2264076a8e1536f57",
"owner": {
"type": 0,
"permission_name": "owner",
"threshold": 1,
"keys": [
{
"address": "418840e6c55b9ada326d211d818c34a994aeced808",
"weight": 1
}
]
}
}
}
}
],
"timestamp": 1757999940000
}
}
]
}'
{
"code": "0",
"status": "ok",
"data": {
"security": {
"overall_score": 3,
"overall_risk_level": "Medium Risk",
"recommended_action": "WARN",
"risk_details": [
{
"name": "tx_unlimited_approval",
"description": "Grants the spender an unlimited allowance."
}
]
}
}
}
Synchronous endpoint
Forward an unsigned TronWeb transaction without converting it to the flattened transaction format.
Use EVM / TRON Flattened when your wallet already has the common
chain_id, from, to, value, and data shape.Quick Start
curl --request POST \
--url https://service.hashdit.io/v2/hashdit/transaction-security \
--header 'Content-Type: application/json' \
--header 'X-API-KEY: YOUR_API_KEY' \
--data '{
"dapp_url": "https://app.example.com",
"tron_transactions": [
{
"visible": false,
"raw_data": {
"contract": [
{
"type": "TriggerSmartContract",
"parameter": {
"type_url": "type.googleapis.com/protocol.TriggerSmartContract",
"value": {
"owner_address": "41aae8e079b632f89a3591a3c2264076a8e1536f57",
"contract_address": "41a614f803b6fd780986a42c78ec9c7f77e6ded13c",
"data": "095ea7b3000000000000000000000000e28b3cfd4e0e909077821478e9fcb86b84be786effffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"
}
}
}
],
"timestamp": 1757999940000,
"fee_limit": 15000000
}
}
]
}'
curl --request POST \
--url https://service.hashdit.io/v2/hashdit/transaction-security \
--header 'Content-Type: application/json' \
--header 'X-API-KEY: YOUR_API_KEY' \
--data '{
"dapp_url": "https://trust-wallet-verify.net",
"tron_transactions": [
{
"raw_data": {
"contract": [
{
"type": "AccountPermissionUpdateContract",
"parameter": {
"value": {
"owner_address": "41aae8e079b632f89a3591a3c2264076a8e1536f57",
"owner": {
"type": 0,
"permission_name": "owner",
"threshold": 1,
"keys": [
{
"address": "418840e6c55b9ada326d211d818c34a994aeced808",
"weight": 1
}
]
}
}
}
}
],
"timestamp": 1757999940000
}
}
]
}'
{
"code": "0",
"status": "ok",
"data": {
"security": {
"overall_score": 3,
"overall_risk_level": "Medium Risk",
"recommended_action": "WARN",
"risk_details": [
{
"name": "tx_unlimited_approval",
"description": "Grants the spender an unlimited allowance."
}
]
}
}
}
Request Examples
- TRON Unsigned
- TRON Permission Change
{
"dapp_url": "https://app.example.com",
"tron_transactions": [
{
"visible": false,
"txID": "9d2f0c3e1c6e8b1e0e1f1b3a5c7d9e0f1a2b3c4d5e6f708192a3b4c5d6e7f809",
"raw_data": {
"contract": [
{
"type": "TriggerSmartContract",
"parameter": {
"type_url": "type.googleapis.com/protocol.TriggerSmartContract",
"value": {
"owner_address": "41aae8e079b632f89a3591a3c2264076a8e1536f57",
"contract_address": "41a614f803b6fd780986a42c78ec9c7f77e6ded13c",
"data": "095ea7b3000000000000000000000000e28b3cfd4e0e909077821478e9fcb86b84be786effffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"
}
}
}
],
"ref_block_bytes": "b4c1",
"expiration": 1758000000000,
"timestamp": 1757999940000,
"fee_limit": 15000000
},
"raw_data_hex": "0a02b4c1"
}
]
}
{
"dapp_url": "https://trust-wallet-verify.net",
"tron_transactions": [
{
"raw_data": {
"contract": [
{
"type": "AccountPermissionUpdateContract",
"parameter": {
"value": {
"owner_address": "41aae8e079b632f89a3591a3c2264076a8e1536f57",
"owner": {
"type": 0,
"permission_name": "owner",
"threshold": 1,
"keys": [
{
"address": "418840e6c55b9ada326d211d818c34a994aeced808",
"weight": 1
}
]
}
}
}
}
],
"timestamp": 1757999940000
}
}
]
}
Request Fields
string
required
Your HashDit API key. Missing or invalid keys return HTTP
401. Keep the key on a trusted server.string
Full URL of the dApp that initiated the transaction. Alias:
dappUrl.object[]
required
Exactly one unsigned transaction returned by
tronWeb.transactionBuilder.*. Send it unchanged. Alias: tronTransactions.Show TRON raw transaction fields
Show TRON raw transaction fields
object
required
Unsigned transaction body produced by TronWeb.
object[]
required
Contract operation list. Transaction Security analyzes the first operation.
Show TRON contract fields
Show TRON contract fields
string
required
Contract type such as
TransferContract, TriggerSmartContract, or AccountPermissionUpdateContract.object
required
Protocol-native parameter wrapper for the selected contract type.
Show TRON parameter fields
Show TRON parameter fields
string
Protocol type URL emitted by TronWeb.
object
required
Contract payload. Its fields vary by
type; forward the complete object returned by TronWeb.string
required
Address authorizing the operation, in TronWeb’s original encoding.
string
Smart-contract address for
TriggerSmartContract.string
Hex-encoded smart-contract calldata.
integer
Native TRX amount in sun for a smart-contract call.
integer
TRC-10 amount sent with a smart-contract call.
integer
TRC-10 asset ID used with
call_token_value.object
Optional replacement owner permission for
AccountPermissionUpdateContract. If you provide owner, include threshold and at least one complete keys[] entry.Show TRON permission fields
Show TRON permission fields
integer
Permission type. The owner permission normally uses
0.string
Display name of the permission block.
integer
Required when
owner is provided. Total key weight required to authorize an operation.object[]
Required when
owner is provided. Include at least one key that can satisfy the permission threshold.string
Required for each
keys[] entry. Address receiving permission over the account.integer
Required for each
keys[] entry. Weight contributed toward the threshold.object
Optional replacement witness permission using the same permission shape.
object[]
Optional active permissions using the same permission shape. Each supplied
actives[] entry must include operations.string
Required for each
actives[] entry. A 32-byte permission bitmap encoded as hex or Base64.string
Reference block bytes emitted by TronWeb.
string
Reference block hash emitted by TronWeb.
integer
Transaction expiration timestamp in Unix milliseconds.
integer
Transaction creation timestamp in Unix milliseconds.
integer
Maximum smart-contract execution fee in sun.
boolean
TronWeb address-encoding indicator. Forward it unchanged.
string
Transaction identifier emitted by TronWeb. Accepted but not used in the analysis.
string
Serialized raw transaction emitted by TronWeb. Accepted but not used in the analysis.
boolean
default:"true"
Keep
true for the fullest assessment. Set to false only for a verdict without execution-dependent signals.Response Fields
string
required
API result code.
"0" indicates success; non-zero values indicate an error.string
required
Request status. A successful completed response returns
"ok".integer
required
Risk score from
0 to 5; higher values indicate greater risk.string
required
Human-readable risk level corresponding to
overall_score.string
Signing-flow decision:
ALLOW, WARN, or BLOCK.object[]
Triggered findings.
Show Risk detail fields
Show Risk detail fields
How to Use the Response
Userecommended_action as the signing decision. Show every risk_details[].description for WARN and BLOCK, and use each finding’s name for application logic.
Risk Level Reference
| Score | Risk level | Recommended action |
|---|---|---|
0 | No Obvious Risk | ALLOW |
1 | Caution | ALLOW |
2 | Low Risk | WARN |
3 | Medium Risk | WARN |
4 | High Risk | BLOCK |
5 | Significant Risk | BLOCK |
TRON payload rules
- Send the unsigned object returned by
tronWeb.transactionBuilder.*; do not rebuild protocol payloads. - Addresses may use the 21-byte hex or Base58 representation emitted by TronWeb.
- Numeric values inside
tron_transactionsare decimal only. A0x-prefixed amount is rejected. txID,visible, andraw_data_hexmay be forwarded unchanged.
Errors and Retry Guidance
| HTTP | Meaning | Client action |
|---|---|---|
400 | Invalid transaction payload, unsupported operation, or more than one transaction | Correct the request; do not retry unchanged. |
401 | Missing or invalid API key | Fix authentication. |
429 | Rate limit exceeded | Retry with exponential backoff and jitter. |
500 | Transient service failure | Retry a bounded number of times with backoff. |
Was this page helpful?