Dataset Downloads

The four datasets behind the risks categories in the REST API are also available as complete database files for offline or on-premises usage. When you subscribe to one or more datasets, every release during the subscription period is yours to download or to pipe straight into your stack through a permalink. Note that the downloable datasets only contain the risk categories (implicit by each dataset) plus subcategories depending on the file format — no network or location information is included in the downloads, this is only available via the real-time REST API.

The datasets

DatasetSlugWhat it contains
Detected Botsdetected_botsIP ranges of malicious, stealthy or unannounced bots, obtained via live traffic analysis powered by Opticks.
ReputationreputationIP ranges confirmed to have been used recently for spam, form abuse or attacks.
Known Botsknown_botsVerified IP ranges for bots, crawlers and LLMs (Claude, ChatGPT…) from major third-party vendors such as GoogleBot.
AnonymizersanonymizersIP ranges of datacenters, proxies and Tor exit nodes, including residential VPNs discovered by Opticks.

The slugs are the same identifiers GET /ip/{ip} uses as the keys of its risks object. The datasets are billed as individual subscription add-ons, so you can subscribe to the ones of your interest. You can manage them from the Subscription center in the dashboard. On the dashboard you can see each dataset's current release and the number of entries (IP address subnets) it contains, as well as a download button to see the instructions, for those datasets you are currently subscribed to.

Formats

Each dataset is available in different file formats, so you can choose the one more suited to your needs.

FormatContents
csvA simple CSV file with a single IP subnet as in CIDR notation
csv_plusA CSV file with two columns: the IP subnet, and the subcategory within the dataset category that flags that subnet.
mmdbA MaxMind binary database binary file, for library integration. Each IP subnet also contains a "subcategory" string record.

Permalinks

Every subscribed dataset has a stable download URL per format:

https://files.ipraccoon.com/download/<slug>?authorization=<token>&format=<format>

The URL never changes between releases — point your pipeline at it and every new release lands automatically, no re-integration. The board's Get Permalink dialog composes these URLs for you.

Treat a permalink as a secret. It embeds your API key, so anyone holding the URL can download on your behalf — and rotating the key invalidates every permalink which includes with the old one.

Verifying a download

You can see the file checksums for the most recent dataset downloads at api.ipraccoon.com/datasets in a JSON format — authenticated the same way as every other REST call, with your API key in the Authorization header. Alternatively you can directly access a checksum by adding .{algorithm} (e.g. .sha256) to the end of the file in the permalink URL.

Here's an example how to download a specific dataset (reputation) in a specific format (mmdb) and then verifying its integrity, assuming the "sha256sum" executable is available on the system:

curl -so reputation.mmdb "https://files.ipraccoon.com/download/reputation.mmdb?authorization=$IP_RACCOON_API_KEY"

expected=$(curl -s "https://files.ipraccoon.com/download/reputation.mmdb.sha256?authorization=$IP_RACCOON_API_KEY")

echo "$expected  reputation.mmdb" | sha256sum -c -

Limits and errors

  • A permalink responds with a redirect (303) to the actual file, hosted on a cloud platform. That target URL is temporary and scoped to a specific dataset version — don't cache or reuse it; keep pointing your pipeline at the permalink itself.
  • 400 Bad Request — Invalid dataset name, version, or file format.
  • 401 Unauthorized — API key not provided, or invalid/revoked.
  • 402 Payment Required — The account is not subscribed to that dataset.