REST API

The main endpoint of the REST API is /ip, which authenticated via an API key. GET /ip/{ip} takes an IP address and answers with the risk categories it is flagged in. Alternatively, GET /ip/{ip}/full adds the network and location intelligence associated to it — the same reading the dashboard renders as a passport, in addition to the risks.

The query endpoint

curl 'https://api.ipraccoon.com/ip/203.0.113.7' \
  -H "Authorization: $IP_RACCOON_TOKEN" \
  -H 'Accept: application/json'
ParameterInDescription
ippathThe address to score — Only IPv4 addesses are supported

Each call consumes API credits from your account balance. The amount of credits consumed depends on which information is information requested:

  • Only risks (/ip/{ip}): 1 API credit
  • Risks + network/location information (/ip/{ip}/full): 1.5 API credits

If needed, you can query the GET /me endpoint to check your current balance, see the REST API Reference section for more details.

The response

Example response

Note that the network and location fields are only included if the /ip/{ip}/full is used, otherwise they will not be defined.

{
  "ip": "203.0.113.7",
  "risks": {
    "reputation": "blocklist",
    "detected_bots": "behavioural"
  },
  "network": {
    "asn": 29465,
    "as": "MTN-NIGERIA-AS",
    "isp": "MTN Nigeria",
    "org": null,
    "networkType": "Mobile",
    "mcc": "621",
    "mnc": "30"
  },
  "location": {
    "country": "NG",
    "city": "Lagos",
    "latitude": 6.52,
    "longitude": 3.38,
    "timezone": "Africa/Lagos",
    "continent": "AF",
    "eu": false
  }
}

risks — the flags

An object keyed by the categories the address is currently flagged in, each value the detection (subcategory) that raised it. Each category has a different set of possible detections. An empty object means no risks where associated to that address. Each category is backed by a dataset you can also subscribe to directly — see the Dataset Downloads.

CategoryMeaning
reputationThreat reputation feeds, spam and form-abuse signals, and IP abuse history
anonymizersVPN, proxies, datacenter IP ranges and Tor exit nodes
detected_botsMalicious, behavioural and heuristic bot detection patterns from live traffic
known_botsVerified bot signatures and known crawler registries, including LLMs such as Claude and ChatGPT

network — the operator

null when the address is outside coverage. Every field inside is itself nullable: the record is a form, and a field the sources cannot fill stays empty rather than guessed.

FieldTypeDescription
asnintegerAutonomous system number
asstringAutonomous system name
ispstringThe operating ISP
orgstringThe organization the range is allocated to
networkTypestringUnknown, Mobile or WiFi
mcc / mncstringMobile country / network code, for mobile ranges

location — the geography

null when the address is outside coverage — the dashboard reads a response with network and location both null as No data. Same rule as the network: every field nullable, nothing guessed.

FieldTypeDescription
countrystringISO 3166-1 alpha-2 country code
citystringThe nearest city
latitude / longitudenumberCoordinates of that city context
timezonestringIANA timezone name
continentstringTwo-letter continent code
eubooleanWhether the country is in the EU

Geolocation is city-accurate at best — treat the coordinates as continent and city context, never as a street address.

Limits and errors

  • 400 Bad Request — Invalid or unsupported IP address.
  • 401 Unauthorized — API key not provided, or invalid/revoked.
  • 402 Payment Required — Account has not enough API credits. Consider activating auto-recharge to avoid any interruption of the service.
  • Error bodies are plain text, not JSON.