IP Intelligence & Reputation

Advanced IP Intelligence & Reputation Scoring

Protect your API from malicious traffic, fraud, and abuse with real-time IP reputation analysis and comprehensive threat detection.

Request:
curl "https://bifrost.api-armor.com/v1/ip-reputation-check?ip=164.90.153.190" \
-H "Authorization: Bearer aa_K7mP9xL2nQ5wR8tY4vB6zN1cF3hJ0gD"
Response:
{
"ip": "164.90.153.190",
"country": "United States",
"country_code": "US",
"flag": "🇺🇸",
"region": "CA",
"region_name": "California",
"city": "Santa Clara",
"subdivisions": "Santa Clara",
"connection_type": "Corporate",
"is_anycast": false,
"zip": "95054",
"latitude": 37.3986,
"longitude": -121.964,
"timezone": "America/Los_Angeles",
"isp": "DigitalOcean, LLC",
"organization": "DigitalOcean, LLC",
"asn": "AS14061 DigitalOcean, LLC",
"reputation": {
"risky": true,
"reputation": "suspicious",
"bot": 0,
"probe": 25,
"rate": 0,
"attack": 0,
"crawler": 0,
"sum": 25,
"kind": [
"hosting"
]
}
}

How Our IP Intelligence Works

Enterprise-grade threat detection powered by multiple intelligence sources.

BGP Network Scanning
We continuously scan and analyze the entire BGP (Border Gateway Protocol) routing table to identify suspicious network blocks, unauthorized route announcements, and emerging threat patterns across the global internet infrastructure.
Multi-Source Intelligence
Our platform aggregates data from multiple scanning services working in parallel, providing comprehensive threat coverage. We continuously monitor network behavior, traffic patterns, and threat indicators from diverse sources.
Machine Learning Analysis
Advanced machine learning models continuously analyze IP behavior patterns, connection characteristics, and historical data to provide accurate reputation scores and predict potential threats before they materialize.
Industry Partnerships
We've partnered with leading email vendors and integrated with multiple DNSBL (DNS-based Blackhole List) providers to maintain up-to-date threat intelligence and ensure comprehensive protection for your applications.

Complete IP Intelligence in Every Response

Rich, developer-friendly data that makes integration effortless.

Comprehensive Data Points

Geographic Information
Country, region, city, subdivisions, timezone, latitude/longitude, and postal code with country flag emoji 🇺🇸
Network Details
ISP, organization, ASN (Autonomous System Number), connection type (Corporate, Residential, Mobile)
Reputation Analysis
Risk score (risky boolean), reputation level, bot/probe/attack/crawler scores, threat type classification (hosting, proxy, vpn, tor)
Technical Flags
Anycast detection, hosting provider identification, data center classification

Developer-Friendly Features

Clean JSON Response
Simple, predictable JSON structure with consistent field names. No nested complexity—just straightforward data you can use immediately.
Unicode Flag Emojis
Country flags included as Unicode emojis (🇺🇸 🇬🇧 🇩🇪) ready to display in your UI without any additional lookups or assets.
Actionable Scores
Clear boolean flags (risky: true/false) and numeric scores (0-100) make it easy to build business logic and automated rules.
Threat Classification
The "kind" array tells you exactly what type of IP it is: hosting, vpn, proxy, tor, mobile, residential—no guesswork required.

All this data in a single API call with 50ms average response time worldwide.

View Full API Documentation

Comprehensive IP Analysis

Get detailed insights about every IP connecting to your API.

Reputation Scoring

Real-time reputation scores based on historical behavior, threat intelligence, and network analysis.

Geolocation Data

Accurate geolocation information including country, region, city, and ISP details for every IP.

VPN/Proxy Detection

Identify VPNs, proxies, Tor exit nodes, and other anonymization services used to hide true identity.

Tor Node Identification

Detect connections from Tor network exit nodes to prevent anonymous malicious activity.

Hosting Provider Detection

Identify data centers, cloud hosting, and server IPs commonly used for automated attacks.

Threat Level Assessment

Comprehensive risk scoring with actionable threat levels to help you make informed decisions.

Built for Modern Applications

Protect every aspect of your application with IP intelligence.

Fraud Prevention
Block high-risk IPs at signup, checkout, or authentication to prevent account takeovers, payment fraud, and credential stuffing attacks.
Rate Limiting by Region
Implement intelligent rate limiting based on geolocation data. Apply different rules for different regions or block traffic from specific areas entirely.
Security Compliance
Meet compliance requirements by monitoring and restricting access from high-risk countries, anonymization services, or known malicious networks.
Traffic Analysis
Gain insights into your user base with geolocation analytics. Identify patterns, detect anomalies, and understand where your traffic originates.

Simple REST API Integration

Get started in minutes with our developer-friendly API.

Ready to protect your API?

Start blocking malicious traffic with our free tier. No credit card required.