# Verdict Reference

This is the body of a `200` response from `GET /v1/verdict/{sessionRef}`. [Verdicts](/docs/browser/concepts/verdicts/) explains how to read them.

```json
{
  "country": "DE",
  "confidence": 0.91,
  "alarm": "none",
  "token": "eyJhbGciOiJFZERTQSIsInR5cCI6Im9jdGV0LWJyb3dzZXItdmVyZGljdCtqd3Q7dj0xIi..."
}
```

## Fields

| Field | Type | Always present | Description |
|---|---|---|---|
| `country` | string | No | ISO 3166-1 alpha-2 code, uppercase. Territories have their own codes, such as `PR` and `GU`. Absent when Octet could not determine a country. |
| `confidence` | number | Yes | From `0` to `1`. How certain Octet is of `country`. |
| `alarm` | string | Yes | One of `none`, `low`, `medium`, `high`. |
| `token` | string | Yes | The signed copy of `country`, `confidence` and `alarm`. See [Verify the Signed Token](/docs/browser/integration/verify-token/). |

Ignore fields you don't recognise, so that fields added in a later version don't break your code.

## Alarm levels

| Level | Meaning |
|---|---|
| `none` | Nothing contradicts `country`. |
| `low` | A minor inconsistency, for example a traveller. Use `country` as returned. |
| `medium` | The connection appears masked, for example by a VPN or proxy. Don't trust `country`. |
| `high` | The connection is masked. `country` is still the country the user is in. It is also `high` when Octet determines the device is being used in a country under comprehensive sanctions, masked or not. Octet does not reliably detect sanctioned regions inside a country, such as Crimea. See [Sanctioned regions](/docs/browser/concepts/verdicts/#sanctioned-regions). |

## Token claims

The token's claims are listed in [Verify the Signed Token](/docs/browser/integration/verify-token/#claims).
