# Verdict Reference

This is the body of a `200` response from `GET /v1/verdict/{sessionRef}`. How to read the fields is in [Verdicts](/docs/browser/concepts/verdicts/).

```json
{
  "country": "DE",
  "confidence": 0.91,
  "alarm": "none",
  "token": "eyJhbGciOiJFZERTQSIsInR5cCI6Im9jdGV0LWJyb3dzZXItdmVyZGljdCtqd3Q7dj0xIi..."
}
```

## Fields

| Field | Type | Always present | Description |
|---|---|---|---|
| `country` | string | No | ISO 3166-1 alpha-2 code, uppercase. Territories have their own codes, such as `PR` and `GU`. Absent when Octet could not estimate a country. |
| `confidence` | number | Yes | From `0` to `1`. How certain Octet is of `country`. |
| `alarm` | string | Yes | One of `none`, `low`, `medium`, `high`. |
| `token` | string | Yes | The signed copy of `country`, `confidence` and `alarm`. See [Verify the Signed Token](/docs/browser/integration/verify-token/). |

Ignore fields you don't recognise, so that fields added in a later version don't break your code.

## Alarm levels

| Level | Meaning |
|---|---|
| `none` | Nothing contradicts `country`. |
| `low` | A minor inconsistency, for example a traveller. `country` is still the best estimate. |
| `medium` | The connection appears masked, for example by a VPN or proxy. Don't trust `country`. |
| `high` | The connection is masked, and the user appears to be in the returned `country`. It is also `high` when the device itself points to a country under comprehensive sanctions, masked or not. |

## Token claims

The token's claims are listed in [Verify the Signed Token](/docs/browser/integration/verify-token/#claims).
