Dataset Downloads
The four datasets behind the risks categories in the REST API are also
available as complete database files for offline or on-premises usage. When
you subscribe to one or more datasets, every release during the subscription
period is yours to download or to pipe straight into your stack through a
permalink.
Note that the downloable datasets only contain the risk categories (implicit
by each dataset) plus subcategories depending on the file format — no network
or location information is included in the downloads, this is only available
via the real-time REST API.
The datasets
| Dataset | Slug | What it contains |
|---|---|---|
| Detected Bots | detected_bots | IP ranges of malicious, stealthy or unannounced bots, obtained via live traffic analysis powered by Opticks. |
| Reputation | reputation | IP ranges confirmed to have been used recently for spam, form abuse or attacks. |
| Known Bots | known_bots | Verified IP ranges for bots, crawlers and LLMs (Claude, ChatGPT…) from major third-party vendors such as GoogleBot. |
| Anonymizers | anonymizers | IP ranges of datacenters, proxies and Tor exit nodes, including residential VPNs discovered by Opticks. |
The slugs are the same identifiers GET /ip/{ip} uses as the keys of
its risks object.
The datasets are billed as individual subscription add-ons, so you can
subscribe to the ones of your interest. You can manage them from the
Subscription center in the dashboard. On the dashboard you can see each
dataset's current release and the number of entries (IP address subnets) it
contains, as well as a download button to see the instructions, for those
datasets you are currently subscribed to.
Formats
Each dataset is available in different file formats, so you can choose the one more suited to your needs.
| Format | Contents |
|---|---|
csv | A simple CSV file with a single IP subnet as in CIDR notation |
csv_plus | A CSV file with two columns: the IP subnet, and the subcategory within the dataset category that flags that subnet. |
mmdb | A MaxMind binary database binary file, for library integration. Each IP subnet also contains a "subcategory" string record. |
Permalinks
Every subscribed dataset has a stable download URL per format:
https://files.ipraccoon.com/download/<slug>?authorization=<token>&format=<format>
The URL never changes between releases — point your pipeline at it and every new release lands automatically, no re-integration. The board's Get Permalink dialog composes these URLs for you.
Treat a permalink as a secret. It embeds your API key, so anyone holding the URL can download on your behalf — and rotating the key invalidates every permalink which includes with the old one.
Verifying a download
You can see the file checksums for the most recent dataset downloads at
api.ipraccoon.com/datasets in a JSON
format — authenticated the same way as every other REST call, with your API
key in the Authorization header.
Alternatively you can directly access a checksum by adding .{algorithm}
(e.g. .sha256) to the end of the file in the permalink URL.
Here's an example how to download a specific dataset (reputation) in a specific format (mmdb) and then verifying its integrity, assuming the "sha256sum" executable is available on the system:
curl -so reputation.mmdb "https://files.ipraccoon.com/download/reputation.mmdb?authorization=$IP_RACCOON_API_KEY"
expected=$(curl -s "https://files.ipraccoon.com/download/reputation.mmdb.sha256?authorization=$IP_RACCOON_API_KEY")
echo "$expected reputation.mmdb" | sha256sum -c -
Limits and errors
- A permalink responds with a redirect (
303) to the actual file, hosted on a cloud platform. That target URL is temporary and scoped to a specific dataset version — don't cache or reuse it; keep pointing your pipeline at the permalink itself. 400 Bad Request— Invalid dataset name, version, or file format.401 Unauthorized— API key not provided, or invalid/revoked.402 Payment Required— The account is not subscribed to that dataset.