REST API
The main endpoint of the REST API is /ip, which authenticated via an API
key. GET /ip/{ip} takes an IP address and answers with the risk categories
it is flagged in. Alternatively, GET /ip/{ip}/full adds the network and
location intelligence associated to it — the same reading the dashboard
renders as a passport, in addition to the risks.
The query endpoint
curl 'https://api.ipraccoon.com/ip/203.0.113.7' \
-H "Authorization: $IP_RACCOON_TOKEN" \
-H 'Accept: application/json'
| Parameter | In | Description |
|---|---|---|
ip | path | The address to score — Only IPv4 addesses are supported |
Each call consumes API credits from your account balance. The amount of credits consumed depends on which information is information requested:
- Only risks (
/ip/{ip}): 1 API credit - Risks + network/location information (
/ip/{ip}/full): 1.5 API credits
If needed, you can query the GET /me endpoint to check your
current balance, see the REST API Reference section for more details.
The response
Example response
Note that the network and location fields are only included if the
/ip/{ip}/full is used, otherwise they will not be defined.
{
"ip": "203.0.113.7",
"risks": {
"reputation": "blocklist",
"detected_bots": "behavioural"
},
"network": {
"asn": 29465,
"as": "MTN-NIGERIA-AS",
"isp": "MTN Nigeria",
"org": null,
"networkType": "Mobile",
"mcc": "621",
"mnc": "30"
},
"location": {
"country": "NG",
"city": "Lagos",
"latitude": 6.52,
"longitude": 3.38,
"timezone": "Africa/Lagos",
"continent": "AF",
"eu": false
}
}
risks — the flags
An object keyed by the categories the address is currently flagged in, each
value the detection (subcategory) that raised it. Each category has a
different set of possible detections. An empty object means no risks
where associated to that address. Each category is backed by a dataset
you can also subscribe to directly — see the
Dataset Downloads.
| Category | Meaning |
|---|---|
reputation | Threat reputation feeds, spam and form-abuse signals, and IP abuse history |
anonymizers | VPN, proxies, datacenter IP ranges and Tor exit nodes |
detected_bots | Malicious, behavioural and heuristic bot detection patterns from live traffic |
known_bots | Verified bot signatures and known crawler registries, including LLMs such as Claude and ChatGPT |
network — the operator
null when the address is outside coverage. Every field inside is itself
nullable: the record is a form, and a field the sources cannot fill stays
empty rather than guessed.
| Field | Type | Description |
|---|---|---|
asn | integer | Autonomous system number |
as | string | Autonomous system name |
isp | string | The operating ISP |
org | string | The organization the range is allocated to |
networkType | string | Unknown, Mobile or WiFi |
mcc / mnc | string | Mobile country / network code, for mobile ranges |
location — the geography
null when the address is outside coverage — the dashboard reads a response
with network and location both null as No data. Same rule as the
network: every field nullable, nothing guessed.
| Field | Type | Description |
|---|---|---|
country | string | ISO 3166-1 alpha-2 country code |
city | string | The nearest city |
latitude / longitude | number | Coordinates of that city context |
timezone | string | IANA timezone name |
continent | string | Two-letter continent code |
eu | boolean | Whether the country is in the EU |
Geolocation is city-accurate at best — treat the coordinates as continent and city context, never as a street address.
Limits and errors
400 Bad Request— Invalid or unsupported IP address.401 Unauthorized— API key not provided, or invalid/revoked.402 Payment Required— Account has not enough API credits. Consider activating auto-recharge to avoid any interruption of the service.- Error bodies are plain text, not JSON.