Skip to main content

Boolean expression over Chainalysis signals. Exactly one of all, any, not, exists, or a field/op/value comparison.

all
array
Required array length: 1 - 200 elements
any
array
Required array length: 1 - 200 elements
not
any
exists
object

Quantifier over one Chainalysis array. Every qualifier in where binds to the same element. Fields inside where name the element's own properties.

field
enum<string>

Absolute paths compare against the response; bare names compare against the bound element of the enclosing exists — category under addressIdentifications, exposures or triggers; exposureType, direction and value under exposures; percentage and the ruleTriggered fields under triggers. Core fields work here too, and are the only ones a pre-screen rule may use. String fields lowercase both sides before comparing, except exposureType, whose vocabulary is closed. cluster and ruleTriggered are nullable, so a field beneath either is unknown.

Available options:
tx.amountUsd,
tx.asset,
chain,
address,
chainalysis.risk,
chainalysis.riskReason,
chainalysis.cluster.category,
chainalysis.cluster.name,
category,
exposureType,
direction,
value,
percentage,
ruleTriggered.risk,
ruleTriggered.exposureType,
ruleTriggered.direction
op
enum<string>

Comparison to apply. in and nin take a list operand and the rest take a scalar; contains is substring, never regex. Which operators a given field admits is per field, and rejected by the validator rather than here.

Available options:
eq,
neq,
in,
nin,
gte,
lte,
gt,
lt,
contains
value
any

Value to compare against: a scalar, or a list of at most 200 for in and nin. Its type has to match the field's, which the validator checks.

Last modified on October 6, 2026