> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hashdit.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Transaction Security — TRON Raw

<span className="api-lifecycle-source" data-lifecycle="sync">Synchronous endpoint</span>

Forward an unsigned TronWeb transaction without converting it to the flattened transaction format.

<Note>
  Use [EVM / TRON Flattened](/api-reference/endpoint/transaction-security) when your wallet already has the common `chain_id`, `from`, `to`, `value`, and `data` shape.
</Note>

## Quick Start

<RequestExample>
  ```bash TRON Unsigned theme={null}
  curl --request POST \
    --url https://service.hashdit.io/v2/hashdit/transaction-security \
    --header 'Content-Type: application/json' \
    --header 'X-API-KEY: YOUR_API_KEY' \
    --data '{
      "dapp_url": "https://app.example.com",
      "tron_transactions": [
        {
          "visible": false,
          "raw_data": {
            "contract": [
              {
                "type": "TriggerSmartContract",
                "parameter": {
                  "type_url": "type.googleapis.com/protocol.TriggerSmartContract",
                  "value": {
                    "owner_address": "41aae8e079b632f89a3591a3c2264076a8e1536f57",
                    "contract_address": "41a614f803b6fd780986a42c78ec9c7f77e6ded13c",
                    "data": "095ea7b3000000000000000000000000e28b3cfd4e0e909077821478e9fcb86b84be786effffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"
                  }
                }
              }
            ],
            "timestamp": 1757999940000,
            "fee_limit": 15000000
          }
        }
      ]
    }'
  ```

  ```bash TRON Permission Change theme={null}
  curl --request POST \
    --url https://service.hashdit.io/v2/hashdit/transaction-security \
    --header 'Content-Type: application/json' \
    --header 'X-API-KEY: YOUR_API_KEY' \
    --data '{
      "dapp_url": "https://trust-wallet-verify.net",
      "tron_transactions": [
        {
          "raw_data": {
            "contract": [
              {
                "type": "AccountPermissionUpdateContract",
                "parameter": {
                  "value": {
                    "owner_address": "41aae8e079b632f89a3591a3c2264076a8e1536f57",
                    "owner": {
                      "type": 0,
                      "permission_name": "owner",
                      "threshold": 1,
                      "keys": [
                        {
                          "address": "418840e6c55b9ada326d211d818c34a994aeced808",
                          "weight": 1
                        }
                      ]
                    }
                  }
                }
              }
            ],
            "timestamp": 1757999940000
          }
        }
      ]
    }'
  ```
</RequestExample>

<ResponseExample>
  ```json 200 theme={null}
  {
    "code": "0",
    "status": "ok",
    "data": {
      "security": {
        "overall_score": 3,
        "overall_risk_level": "Medium Risk",
        "recommended_action": "WARN",
        "risk_details": [
          {
            "name": "tx_unlimited_approval",
            "description": "Grants the spender an unlimited allowance."
          }
        ]
      }
    }
  }
  ```
</ResponseExample>

### Request Examples

<Tabs>
  <Tab title="TRON Unsigned">
    ```json theme={null}
    {
      "dapp_url": "https://app.example.com",
      "tron_transactions": [
        {
          "visible": false,
          "txID": "9d2f0c3e1c6e8b1e0e1f1b3a5c7d9e0f1a2b3c4d5e6f708192a3b4c5d6e7f809",
          "raw_data": {
            "contract": [
              {
                "type": "TriggerSmartContract",
                "parameter": {
                  "type_url": "type.googleapis.com/protocol.TriggerSmartContract",
                  "value": {
                    "owner_address": "41aae8e079b632f89a3591a3c2264076a8e1536f57",
                    "contract_address": "41a614f803b6fd780986a42c78ec9c7f77e6ded13c",
                    "data": "095ea7b3000000000000000000000000e28b3cfd4e0e909077821478e9fcb86b84be786effffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"
                  }
                }
              }
            ],
            "ref_block_bytes": "b4c1",
            "expiration": 1758000000000,
            "timestamp": 1757999940000,
            "fee_limit": 15000000
          },
          "raw_data_hex": "0a02b4c1"
        }
      ]
    }
    ```
  </Tab>

  <Tab title="TRON Permission Change">
    ```json theme={null}
    {
      "dapp_url": "https://trust-wallet-verify.net",
      "tron_transactions": [
        {
          "raw_data": {
            "contract": [
              {
                "type": "AccountPermissionUpdateContract",
                "parameter": {
                  "value": {
                    "owner_address": "41aae8e079b632f89a3591a3c2264076a8e1536f57",
                    "owner": {
                      "type": 0,
                      "permission_name": "owner",
                      "threshold": 1,
                      "keys": [
                        {
                          "address": "418840e6c55b9ada326d211d818c34a994aeced808",
                          "weight": 1
                        }
                      ]
                    }
                  }
                }
              }
            ],
            "timestamp": 1757999940000
          }
        }
      ]
    }
    ```
  </Tab>
</Tabs>

## Request Fields

<ParamField header="X-API-KEY" type="string" required>
  Your HashDit API key. Missing or invalid keys return HTTP `401`. Keep the key on a trusted server.
</ParamField>

<ParamField body="dapp_url" type="string">
  Full URL of the dApp that initiated the transaction. Alias: `dappUrl`.
</ParamField>

<ParamField body="tron_transactions" type="object[]" required>
  Exactly one unsigned transaction returned by `tronWeb.transactionBuilder.*`. Send it unchanged. Alias: `tronTransactions`.
</ParamField>

<Expandable title="TRON raw transaction fields">
  <ParamField body="tron_transactions[].raw_data" type="object" required>
    Unsigned transaction body produced by TronWeb.
  </ParamField>

  <ParamField body="tron_transactions[].raw_data.contract[]" type="object[]" required>
    Contract operation list. Transaction Security analyzes the first operation.
  </ParamField>

  <Expandable title="TRON contract fields">
    <ParamField body="tron_transactions[].raw_data.contract[].type" type="string" required>
      Contract type such as `TransferContract`, `TriggerSmartContract`, or `AccountPermissionUpdateContract`.
    </ParamField>

    <ParamField body="tron_transactions[].raw_data.contract[].parameter" type="object" required>
      Protocol-native parameter wrapper for the selected contract type.
    </ParamField>

    <Expandable title="TRON parameter fields">
      <ParamField body="tron_transactions[].raw_data.contract[].parameter.type_url" type="string">
        Protocol type URL emitted by TronWeb.
      </ParamField>

      <ParamField body="tron_transactions[].raw_data.contract[].parameter.value" type="object" required>
        Contract payload. Its fields vary by `type`; forward the complete object returned by TronWeb.
      </ParamField>

      <ParamField body="tron_transactions[].raw_data.contract[].parameter.value.owner_address" type="string" required>
        Address authorizing the operation, in TronWeb's original encoding.
      </ParamField>

      <ParamField body="tron_transactions[].raw_data.contract[].parameter.value.contract_address" type="string">
        Smart-contract address for `TriggerSmartContract`.
      </ParamField>

      <ParamField body="tron_transactions[].raw_data.contract[].parameter.value.data" type="string">
        Hex-encoded smart-contract calldata.
      </ParamField>

      <ParamField body="tron_transactions[].raw_data.contract[].parameter.value.call_value" type="integer">
        Native TRX amount in sun for a smart-contract call.
      </ParamField>

      <ParamField body="tron_transactions[].raw_data.contract[].parameter.value.call_token_value" type="integer">
        TRC-10 amount sent with a smart-contract call.
      </ParamField>

      <ParamField body="tron_transactions[].raw_data.contract[].parameter.value.token_id" type="integer">
        TRC-10 asset ID used with `call_token_value`.
      </ParamField>

      <ParamField body="tron_transactions[].raw_data.contract[].parameter.value.owner" type="object">
        Optional replacement owner permission for `AccountPermissionUpdateContract`. If you provide `owner`, include `threshold` and at least one complete `keys[]` entry.
      </ParamField>

      <Expandable title="TRON permission fields">
        <ParamField body="tron_transactions[].raw_data.contract[].parameter.value.owner.type" type="integer">
          Permission type. The owner permission normally uses `0`.
        </ParamField>

        <ParamField body="tron_transactions[].raw_data.contract[].parameter.value.owner.permission_name" type="string">
          Display name of the permission block.
        </ParamField>

        <ParamField body="tron_transactions[].raw_data.contract[].parameter.value.owner.threshold" type="integer">
          Required when `owner` is provided. Total key weight required to authorize an operation.
        </ParamField>

        <ParamField body="tron_transactions[].raw_data.contract[].parameter.value.owner.keys[]" type="object[]">
          Required when `owner` is provided. Include at least one key that can satisfy the permission threshold.
        </ParamField>

        <ParamField body="tron_transactions[].raw_data.contract[].parameter.value.owner.keys[].address" type="string">
          Required for each `keys[]` entry. Address receiving permission over the account.
        </ParamField>

        <ParamField body="tron_transactions[].raw_data.contract[].parameter.value.owner.keys[].weight" type="integer">
          Required for each `keys[]` entry. Weight contributed toward the threshold.
        </ParamField>

        <ParamField body="tron_transactions[].raw_data.contract[].parameter.value.witness" type="object">
          Optional replacement witness permission using the same permission shape.
        </ParamField>

        <ParamField body="tron_transactions[].raw_data.contract[].parameter.value.actives[]" type="object[]">
          Optional active permissions using the same permission shape. Each supplied `actives[]` entry must include `operations`.
        </ParamField>

        <ParamField body="tron_transactions[].raw_data.contract[].parameter.value.actives[].operations" type="string">
          Required for each `actives[]` entry. A 32-byte permission bitmap encoded as hex or Base64.
        </ParamField>
      </Expandable>
    </Expandable>
  </Expandable>

  <ParamField body="tron_transactions[].raw_data.ref_block_bytes" type="string">
    Reference block bytes emitted by TronWeb.
  </ParamField>

  <ParamField body="tron_transactions[].raw_data.ref_block_hash" type="string">
    Reference block hash emitted by TronWeb.
  </ParamField>

  <ParamField body="tron_transactions[].raw_data.expiration" type="integer">
    Transaction expiration timestamp in Unix milliseconds.
  </ParamField>

  <ParamField body="tron_transactions[].raw_data.timestamp" type="integer">
    Transaction creation timestamp in Unix milliseconds.
  </ParamField>

  <ParamField body="tron_transactions[].raw_data.fee_limit" type="integer">
    Maximum smart-contract execution fee in sun.
  </ParamField>

  <ParamField body="tron_transactions[].visible" type="boolean">
    TronWeb address-encoding indicator. Forward it unchanged.
  </ParamField>

  <ParamField body="tron_transactions[].txID" type="string">
    Transaction identifier emitted by TronWeb. Accepted but not used in the analysis.
  </ParamField>

  <ParamField body="tron_transactions[].raw_data_hex" type="string">
    Serialized raw transaction emitted by TronWeb. Accepted but not used in the analysis.
  </ParamField>
</Expandable>

<ParamField body="simulate" type="boolean" default="true">
  Keep `true` for the fullest assessment. Set to `false` only for a verdict without execution-dependent signals.
</ParamField>

## Response Fields

<ResponseField name="code" type="string" required>
  API result code. `"0"` indicates success; non-zero values indicate an error.
</ResponseField>

<ResponseField name="status" type="string" required>
  Request status. A successful completed response returns `"ok"`.
</ResponseField>

<ResponseField name="data.security.overall_score" type="integer" required>
  Risk score from `0` to `5`; higher values indicate greater risk.
</ResponseField>

<ResponseField name="data.security.overall_risk_level" type="string" required>
  Human-readable risk level corresponding to `overall_score`.
</ResponseField>

<ResponseField name="data.security.recommended_action" type="string">
  Signing-flow decision: `ALLOW`, `WARN`, or `BLOCK`.
</ResponseField>

<ResponseField name="data.security.risk_details" type="object[]">
  Triggered findings.
</ResponseField>

<Expandable title="Risk detail fields">
  <ResponseField name="data.security.risk_details[].name" type="string" required>
    Stable finding identifier for application logic.
  </ResponseField>

  <ResponseField name="data.security.risk_details[].description" type="string" required>
    Human-readable explanation to show to the user.
  </ResponseField>
</Expandable>

## How to Use the Response

Use `recommended_action` as the signing decision. Show every `risk_details[].description` for `WARN` and `BLOCK`, and use each finding's `name` for application logic.

## Risk Level Reference

| Score | Risk level | Recommended action |
| - | - | - |
| `0` | `No Obvious Risk` | `ALLOW` |
| `1` | `Caution` | `ALLOW` |
| `2` | `Low Risk` | `WARN` |
| `3` | `Medium Risk` | `WARN` |
| `4` | `High Risk` | `BLOCK` |
| `5` | `Significant Risk` | `BLOCK` |

### TRON payload rules

* Send the unsigned object returned by `tronWeb.transactionBuilder.*`; do not rebuild protocol payloads.
* Addresses may use the 21-byte hex or Base58 representation emitted by TronWeb.
* Numeric values inside `tron_transactions` are decimal only. A `0x`-prefixed amount is rejected.
* `txID`, `visible`, and `raw_data_hex` may be forwarded unchanged.

## Errors and Retry Guidance

| HTTP | Meaning | Client action |
| - | - | - |
| `400` | Invalid transaction payload, unsupported operation, or more than one transaction | Correct the request; do not retry unchanged. |
| `401` | Missing or invalid API key | Fix authentication. |
| `429` | Rate limit exceeded | Retry with exponential backoff and jitter. |
| `500` | Transient service failure | Retry a bounded number of times with backoff. |
