Skip to main content

Payload of the wallet.addressScreening.blocked webhook event: a screening verdict blocked by the environment's own policy rather than by the sanctions floor.

Fires once per user-facing boundary decision, not per provider response, including decisions served from the screening cache. A floor block emits wallet.sanctions.blocked instead.

chain is deliberately not required: the column is nullable, so a screen performed without one emits a payload without it.

walletAddress
string
required

Lowercase, normalized address that was blocked.

sanctionsProvider
enum<string>
required
Available options:
trm-wallet-screening,
chainalysis-address-screening,
dynamic-sanctions-screening
sanctionCheckRequestId
string<uuid>
required

Forensic key into the screening audit record.

categories
string[]
required

Vendor-returned categories that triggered the block. May be empty when the decision was served from the screening cache (cached rows do not retain vendor categories).

Example:
origin
enum<string>
required

User-flow surface that triggered the screening which produced this BLOCKED decision. signIn: user login/session verification. walletConnect: external wallet connect. checkoutDestination: a destination address in the checkout flow (checkout create/update or checkout transaction create). checkoutSource: the from-address funding a checkout transaction. flowDestination: flow create destination address. flowSource: the from-address funding a flow. api: direct wallet-sanctions API query. backgroundPrefetch: background cache-warming check (see trigger semantics above). transactionSigning: a decoded transaction destination screened before the MPC signing ceremony for an embedded wallet (hard-enforced server-side). transactionScreenApi: a decoded transaction destination screened for a connected/external wallet via the public screen API (best-effort, client-side). This enum will grow as new screening surfaces are added; consumers should handle unrecognized values gracefully.

Available options:
signIn,
walletConnect,
checkoutDestination,
checkoutSource,
flowDestination,
flowSource,
api,
backgroundPrefetch,
transactionSigning,
transactionScreenApi
keyOwner
enum<string>
required

Who owns the key used for the check. customerProvided if the check ran against a customer-supplied BYOK key; dynamic if it ran against a Dynamic-managed key.

Available options:
dynamic,
customerProvided
screenedAt
string<date-time>
required

ISO 8601 timestamp of when the screening decision landed.

action
enum<string>
required

What the policy decided.

Available options:
blocked
reason
object
required

Why a screening policy reached its verdict: which layer matched, and what it matched on in the vendor's own vocabulary.

Only provider and matched are always present. The rest depend on the vendor and on which leaf actually fired — a floor match on a Chainalysis cluster carries a category and no riskType.

chain
string

Chain identifier (e.g. 'ethereum', 'bitcoin', 'solana'). Canonical value recorded on the screening audit record.

Example:

"ethereum"

txContext
object

The transaction the screen was performed for. Every property is optional and the whole object is omitted when nothing is known, which is the case on sign-in, connect, prefetch and the signing path.

Last modified on October 6, 2026