x402 List

x402 Protocol Service Directory

IPIntel.ai IP Lookup & Risk API

Data PAYMENT-READY imported

payment-ready until 2026-09-28

imported from the x402 Bazaar, not submitted by the operator · own this service? claim it · or ask to be removed

Pay-per-call IP intelligence API. Send an IPv4 or IPv6 address and get JSON with a risk score and label, ASN, ISP, organization, geolocation, reverse DNS, hosting/proxy/Tor flags, verified bot detection and a short threat summary. Priced at $0.001 per call in USDC on Base.

Pay from $0.001 per request in USDC on Base, settled onchain via the x402 protocol, no signup, no API key needed.

measured since 2026-06-21 (start of our harvest window) · $4.50 all-time · settled via coinbase

BASE URL https://api.ipintel.ai ENDPOINTS 1 NETWORK Base ASSET USDC MEMBER SINCE 2026-07-20 MONITORED SINCE 2026-07-20

VERDICT

ranking generation 3

solid 84/100 #132 of 299 in Data by measured score

What the score read on this service: status online, 99.9% uptime 30d, 2099ms response p95, x402 compliance 14 of 14, $0.001 price against the category, on-chain traction measured. Each of those is measured, and each is published in full below.

The score comes from our own monitoring, never from reviews, operator claims, or a language model: reliability, x402 compliance, price against the category, a deterministic risk flag, and a small on-chain traction term, weighted by ranking generation 3. It is not placement anyone can buy: the paid verify tier is reported beside it and is not one of its inputs. Every component below stays published and read-only.

It is a score inside Data, and only there: price and speed are scored against the whole category field, every listing in it that carries no danger flag, the scored service included, which here means 299 listings, this one among them. That set is wider than the 299 the position above is counted against, because a listing we have measured too little of to rank still sits in the field the price and the speed are normalized over. The same service in a different field would read differently. The same engine answers GET /api/v1/best, and asked for a different pool (the whole directory, or another filter) it returns a different number for this service under this same ranking generation. Neither is more correct: they answer different questions, and the methodology states which is which.

Bands on the 0 to 100 measured score: strong at 93 and above, solid from 75, mixed from 55, weak below 55. Price and speed are scored against the whole category field, every listing in it that carries no danger flag, the scored service included, so the score places a service in its own field.

ALTERNATIVES IN DATA

Other Data services in this directory, ordered by the same measured score. The figures are ours: 30-day uptime from our own probes, 30-day settlement volume read on-chain (a conservative undercount, and null where we cannot measure it, never a zero).

Ranked alternative x402 services in the same category, with band, measured score, 30-day uptime and 30-day on-chain settlement volume
SERVICE BAND SCORE UPTIME 30D VOL 30D
StableEnrich strong 96 100% $1.9k
glim.sh strong 95 100% $48.83
SniperX•x402 strong 95 100% $367.75
cn402 strong 94 100% $36.89
API Acre solid 92 99.5% $31.95
5 of 298 other ranked services in Data · see the whole category

ASSESSMENT

updated 2h ago

The parts the verdict above is computed from, each with its proof. Click any chip. Measured values stay read-only; unknown is honest, and an unknown is never counted as a zero.

reliability 99.9%
uptime 24h
100%
uptime 7d
100%
uptime 30d
99.9%
uptime 90d
100%
response p95
2099ms
avg response
1213ms
total checks
2,777

Measured on the unpaid 402 handshake, not the paid call. A service can 402 correctly and still fail after payment.

compliance A (14/14)

14 of 14 x402 conformance checks pass. Full checklist below.

jump to compliance checklist

price $0.001 (p10 in Data)
price (min)
$0.001
category percentile (min)
p10 in Data
endpoints / prices
1 / 1
model
flat
stability
100%
risk clean

No deterministic risk flag. Risk fires only on an exact blocklist match, or a reserved-brand name with a mismatched verified payTo. Never from low uptime, a high price, or a model guess.

domain age
-
registrar
-
hosting
custom
domain created
---

Identity facts, not a risk score.

traction $3.44 30d · 29 buyers
volume 30d
$3.44
buyers 30d
29
settlements 30d
411
measured since
2026-06-21 (start of our harvest window)
last settlement
2026-09-20
top buyer share
66% of 30d volume
trend 7d vs 30d
1.48x the 30d daily rate
networks
eip155:8453
volume all-time
$4.50
settlements all-time
788
median settlement 30d
$0.025
max settlement 30d
$0.09
settled via
coinbase ($10.32, 411 tx)

Attributed pro-quota: this payout address is shared, so volume is the operator-level figure divided by the services sharing it, while buyer and transaction counts stay whole. A declared convention, not an individually observed measure, and still a conservative undercount.

Currently sharing this payout address with IPIntel.ai Satellite & GeoRisk API, IPIntel.ai x402 Tools.

Top buyer share is a concentration signal, not part of the ranking score.

WHAT IT DOES

ai-derived

Provides IP address lookup and risk assessment services

category
ip-intelligence
in
body
auth
api key
ip-lookuprisk-assessmentsecurity

AI-generated summary. The measured data is never altered by it.

ENDPOINTS

Service endpoints with HTTP method, path, description, pricing, and network
METHOD PATH DESCRIPTION PRICE NETWORK ASSET 402 CHANNEL
POST /x402v2 $0.001 Base USDC header
1 endpoints

REQUEST / RESPONSE EXAMPLE

An unpaid request to POST /x402v2 returns HTTP 402 with the payment terms. Settle onchain via your facilitator, then retry with the X-Payment header.

// request
curl -i -X POST 'https://api.ipintel.ai/x402v2'
// 402 response (captured by monitor) · 1 payload · click to expand
[
  {
    "error": "Payment required",
    "accepts": [
      {
        "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
        "extra": {
          "name": "USD Coin",
          "version": "2"
        },
        "payTo": "0x0550779CFBc832657A8BB46BAC9f359A5ad038B8",
        "amount": "1000",
        "scheme": "exact",
        "network": "eip155:8453",
        "maxTimeoutSeconds": 300
      }
    ],
    "resource": {
      "url": "https://api.ipintel.ai/x402v2",
      "tags": [
        "ip-lookup",
        "ip-intelligence",
        "ip-risk-score",
        "geolocation",
        "proxy-vpn-tor"
      ],
      "iconUrl": "https://api.ipintel.ai/favicon.ico",
      "mimeType": "application/json",
      "description": "Pay-per-call IP lookup and risk intelligence API. Send an IPv4 or IPv6 address and receive JSON with risk score, risk label, ASN, ISP, organization, geolocation, reverse DNS, hosting/proxy/VPN/Tor signals, verified bot detection, scanner/honeypot indicators, and AI-powered subnet behavior analysis via x402 v2 on Base.",
      "serviceName": "IPIntel.ai IP Lookup & Risk API"
    },
    "extensions": {
      "bazaar": {
        "info": {
          "input": {
            "body": {
              "ip": "8.8.8.8"
            },
            "type": "http",
            "method": "POST",
            "bodyType": "json"
          },
          "output": {
            "type": "json",
            "example": {
              "ip": "8.8.8.8",
              "asn": "AS15169",
              "isp": "Google LLC",
              "org": "Google Public DNS",
              "city": "Ashburn",
              "is_tor": false,
              "country": "US",
              "is_proxy": false,
              "confidence": 100,
              "is_hosting": true,
              "risk_label": "Safe",
              "risk_score": 15,
              "reverse_dns": "dns.google",
              "threat_summary": "This IP is considered safe and does not pose a threat. Only minimal and non-threatening activity has been observed.",
              "is_verified_bot": false
            }
          }
        },
        "schema": {
          "type": "object",
          "$schema": "https://json-schema.org/draft/2020-12/schema",
          "required": [
            "input"
          ],
          "properties": {
            "input": {
              "type": "object",
              "required": [
                "type",
                "method",
                "bodyType",
                "body"
              ],
              "properties": {
                "body": {
                  "type": "object",
                  "required": [
                    "ip"
                  ],
                  "properties": {
                    "ip": {
                      "type": "string",
                      "description": "IPv4 or IPv6 address to analyze, passed in the JSON request body"
                    }
                  },
                  "additionalProperties": false
                },
                "type": {
                  "type": "string",
                  "const": "http"
                },
                "method": {
                  "enum": [
                    "POST"
                  ],
                  "type": "string"
                },
                "bodyType": {
                  "enum": [
                    "json",
                    "form-data",
                    "text"
                  ],
                  "type": "string"
                }
              },
              "additionalProperties": false
            },
            "output": {
              "type": "object",
              "required": [
                "type"
              ],
              "properties": {
                "type": {
                  "type": "string"
                },
                "example": {
                  "type": "object",
                  "properties": {
                    "ip": {
                      "type": "string",
                      "description": "Queried IPv4 or IPv6 address"
                    },
                    "asn": {
                      "type": "string",
                      "description": "Autonomous system number"
                    },
                    "isp": {
                      "type": "string",
                      "description": "Internet service provider"
                    },
                    "org": {
                      "type": "string",
                      "description": "Organization name"
                    },
                    "city": {
                      "type": "string",
                      "description": "City, when available"
                    },
                    "is_tor": {
                      "type": "boolean",
                      "description": "Whether the IP appears to be a Tor exit node"
                    },
                    "country": {
                      "type": "string",
                      "description": "Country code or country name"
                    },
                    "is_proxy": {
                      "type": "boolean",
                      "description": "Whether the IP appears to be a proxy"
                    },
                    "confidence": {
                      "type": "number",
                      "description": "Confidence percentage from 0 to 100"
                    },
                    "is_hosting": {
                      "type": "boolean",
                      "description": "Whether the IP appears to belong to hosting/cloud infrastructure"
                    },
                    "risk_label": {
                      "type": "string",
                      "description": "Human-readable risk label"
                    },
                    "risk_score": {
                      "type": "number",
                      "description": "Risk score from 0 to 100"
                    },
                    "reverse_dns": {
                      "type": "string",
                      "description": "Reverse DNS hostname, when available"
                    },
                    "threat_summary": {
                      "type": "string",
                      "description": "Short natural-language threat assessment"
                    },
                    "is_verified_bot": {
                      "type": "boolean",
                      "description": "Whether the IP appears to be a verified known bot"
                    }
                  },
                  "additionalProperties": true
                }
              }
            }
          }
        }
      }
    },
    "x402Version": 2
  }
]

OVER TIME

All charts use the 30d selector; each series spans only the dates it has data for. Every series is also served as JSON at /api/v1/services/ipintel-ai-ip-lookup-risk-api/price, /scores, /volume and /buyers. On-chain volume and distinct buyers are measured over the service's settlement address and are a conservative undercount (only settlements that reach a measured facilitator are counted). The on-chain series roll up hourly, so the latest day can be up to about an hour behind; distinct buyers are counted per payout address, so a service that settles to more than one address is an upper bound.

UPTIME
08-23 · uptime 100.0% · 742ms avg08-24 · uptime 100.0% · 1078ms avg08-25 · uptime 100.0% · 1282ms avg08-26 · uptime 100.0% · 1282ms avg08-27 · uptime 100.0% · 1036ms avg08-28 · uptime 100.0% · 1276ms avg08-29 · uptime 100.0% · 1632ms avg08-30 · uptime 100.0% · 1397ms avg08-31 · uptime 100.0% · 1619ms avg09-01 · uptime 100.0% · 1368ms avg09-02 · uptime 100.0% · 1727ms avg09-03 · uptime 100.0% · 1202ms avg09-04 · uptime 100.0% · 1757ms avg09-05 · uptime 100.0% · 1104ms avg09-06 · uptime 100.0% · 1002ms avg09-07 · uptime 100.0% · 1006ms avg09-08 · uptime 98.9% · 1075ms avg09-09 · uptime 100.0% · 1025ms avg09-10 · uptime 100.0% · 987ms avg09-11 · uptime 100.0% · 1142ms avg09-12 · uptime 100.0% · 1210ms avg09-13 · uptime 98.9% · 1497ms avg09-14 · uptime 100.0% · 1359ms avg09-15 · uptime 100.0% · 1362ms avg09-16 · uptime 100.0% · 1377ms avg09-17 · uptime 100.0% · 875ms avg09-18 · uptime 100.0% · 1075ms avg09-19 · uptime 100.0% · 1263ms avg09-20 · uptime 100.0% · 1427ms avg09-21 · uptime 100.0% · 1444ms avg08-2309-21
30d UPTIME 99.9%
RESPONSE TIME
08-23 · 742ms avg08-23 · 742ms avg08-24 · 1078ms avg08-24 · 1078ms avg08-25 · 1282ms avg08-25 · 1282ms avg08-26 · 1282ms avg08-26 · 1282ms avg08-27 · 1036ms avg08-27 · 1036ms avg08-28 · 1276ms avg08-28 · 1276ms avg08-29 · 1632ms avg08-29 · 1632ms avg08-30 · 1397ms avg08-30 · 1397ms avg08-31 · 1619ms avg08-31 · 1619ms avg09-01 · 1368ms avg09-01 · 1368ms avg09-02 · 1727ms avg09-02 · 1727ms avg09-03 · 1202ms avg09-03 · 1202ms avg09-04 · 1757ms avg09-04 · 1757ms avg09-05 · 1104ms avg09-05 · 1104ms avg09-06 · 1002ms avg09-06 · 1002ms avg09-07 · 1006ms avg09-07 · 1006ms avg09-08 · 1075ms avg09-08 · 1075ms avg09-09 · 1025ms avg09-09 · 1025ms avg09-10 · 987ms avg09-10 · 987ms avg09-11 · 1142ms avg09-11 · 1142ms avg09-12 · 1210ms avg09-12 · 1210ms avg09-13 · 1497ms avg09-13 · 1497ms avg09-14 · 1359ms avg09-14 · 1359ms avg09-15 · 1362ms avg09-15 · 1362ms avg09-16 · 1377ms avg09-16 · 1377ms avg09-17 · 875ms avg09-17 · 875ms avg09-18 · 1075ms avg09-18 · 1075ms avg09-19 · 1263ms avg09-19 · 1263ms avg09-20 · 1427ms avg09-20 · 1427ms avg09-21 · 1444ms avg09-21 · 1444ms avg08-2309-21
AVG RESP 1230ms
PRICE (captured 402, USD)
08-22 · $0.00109-21 · $0.001$0.00108-2209-21
SUB-SCORES (uptime + x402 compliance)
08-22 uptime: 100.0% compliance: 100% checks08-23 uptime: 100.0% compliance: 100% checks08-24 uptime: 100.0% compliance: 100% checks08-25 uptime: 100.0% compliance: 100% checks08-26 uptime: 100.0% compliance: 100% checks08-27 uptime: 100.0% compliance: 100% checks08-28 uptime: 100.0% compliance: 100% checks08-29 uptime: 100.0% compliance: 100% checks08-30 uptime: 100.0% compliance: 100% checks08-31 uptime: 100.0% compliance: 100% checks09-01 uptime: 100.0% compliance: 100% checks09-02 uptime: 100.0% compliance: 100% checks09-03 uptime: 100.0% compliance: 100% checks09-04 uptime: 100.0% compliance: 100% checks09-05 uptime: 100.0% compliance: 100% checks09-06 uptime: 100.0% compliance: 100% checks09-07 uptime: 100.0% compliance: 100% checks09-08 uptime: 100.0% compliance: 100% checks09-09 uptime: 100.0% compliance: 100% checks09-10 uptime: 100.0% compliance: 100% checks09-11 uptime: 100.0% compliance: 100% checks09-12 uptime: 100.0% compliance: 100% checks09-13 uptime: 99.9% compliance: 100% checks09-14 uptime: 99.9% compliance: 100% checks09-15 uptime: 99.9% compliance: 100% checks09-16 uptime: 99.9% compliance: 100% checks09-17 uptime: 99.9% compliance: 100% checks09-18 uptime: 99.9% compliance: 100% checks09-19 uptime: 99.9% compliance: 100% checks09-20 uptime: 99.9% compliance: 100% checks09-21 uptime: 99.9% compliance: 100% checksuptimecompliance08-2209-21

checklist grew 11->14 on 2026-07-28; a step here is a metric change, not a regression

PILLARS OVER TIME (measured)

Measured site and economics pillars from the assessment history, so the latest value shown elsewhere on this page reads as a point on a trend rather than a permanent state.

VOLUME (on-chain settlement, USD)
08-25 · $0.0008-26 · $0.0108-27 · $0.0009-05 · $0.0009-08 · $0.0009-09 · $109-10 · $309-11 · $109-12 · $0.7009-13 · $0.2309-14 · $0.1109-15 · $0.1309-16 · $0.0809-17 · $0.2509-18 · $109-19 · $0.5509-20 · $1peak $308-2509-20

Shared payout address (2 other services). These bars are the full shared address (operator-level), so do not sum them across the services that share it. Where a per-service figure is attributed, the assessment block and the ranking, it is the address total divided pro-quota by the 3 services sharing it: a declared convention, not an individually observed measure.

DISTINCT BUYERS
08-25 · 1 buyer08-26 · 2 buyers08-27 · 1 buyer09-05 · 1 buyer09-08 · 1 buyer09-09 · 11 buyers09-10 · 4 buyers09-11 · 5 buyers09-12 · 1 buyer09-13 · 1 buyer09-14 · 2 buyers09-15 · 2 buyers09-16 · 1 buyer09-17 · 3 buyers09-18 · 2 buyers09-19 · 2 buyers09-20 · 4 buyerspeak 11 buyers08-2509-20

Shared payout address (2 other services). These bars are the full shared address (operator-level), so do not sum them across the services that share it. Per-service buyer and transaction counts are shown whole (integers), not divided; only volume is attributed pro-quota. A declared convention, not an individually observed measure.

COMPLIANCE

14/14 checks pass · grade A

last 402 captured 2026-07-20 · last up 2026-09-21

  • 402 payload captured
  • accepts[] array present
  • payTo address recoverable
  • payTo at accepts[0].payTo (conformant shape)
  • payTo is a valid on-chain address
  • atomic price declared
  • atomic price in a sane range
  • asset (token) address declared
  • network resolves to CAIP-2
  • payment scheme declared
  • served over HTTPS
  • declares the current x402 version (2)
  • EIP-712 domain parameters present on every EVM entry
  • x402 v2 envelope delivered in the payment-required header

SITE PILLARS

  • homepage reachable
  • openapi doc
  • pricing page
  • llms.txt
  • robots.txt
  • terms page
recent checks (18) live · click to expand
TIME STATUS RESP CAUSE
● SLOW 1970ms
● OK 385ms
● SLOW 2641ms
● OK 1180ms
● OK 1170ms
● OK 853ms
● OK 1167ms
● SLOW 1947ms
● OK 1335ms
● OK 1202ms
● SLOW 3169ms
● OK 828ms
● OK 1636ms
● OK 1394ms
● OK 1349ms
● OK 1245ms
● OK 991ms
● OK 1749ms

EMBED THIS BADGE

Show that IPIntel.ai IP Lookup & Risk API is monitored on x402-list. Paste this on your site or README, it links back to this live listing.

IPIntel.ai IP Lookup & Risk API listed on x402-list
status
IPIntel.ai IP Lookup & Risk API uptime on x402-list
live uptime
// HTML
<a href="https://x402-list.com/services/ipintel-ai-ip-lookup-risk-api?utm_source=badge&utm_medium=referral&utm_campaign=embed">
  <img src="https://x402-list.com/badge/ipintel-ai-ip-lookup-risk-api.svg" alt="IPIntel.ai IP Lookup & Risk API listed on x402-list" height="28">
</a>
// Markdown
[![IPIntel.ai IP Lookup & Risk API on x402-list](https://x402-list.com/badge/ipintel-ai-ip-lookup-risk-api.svg)](https://x402-list.com/services/ipintel-ai-ip-lookup-risk-api?utm_source=badge&utm_medium=referral&utm_campaign=embed)
// HTML · live uptime variant
<a href="https://x402-list.com/services/ipintel-ai-ip-lookup-risk-api?utm_source=badge&utm_medium=referral&utm_campaign=embed">
  <img src="https://x402-list.com/badge/ipintel-ai-ip-lookup-risk-api.svg?data=uptime" alt="IPIntel.ai IP Lookup & Risk API uptime on x402-list" height="28">
</a>

RUN THIS SERVICE?

Keep this listing accurate: propose changes to the name, description, website, category or add new endpoints to monitor. Ownership is verified with a domain proof and every change is reviewed manually; measured data stays read-only.

[ update this listing ]

Earn the verified tier: x402list pays a real call to this endpoint and, if it delivers, the service is delivery-verified. The fee covers the cost of the probe, not the badge; there is no refund if the call does not deliver. Agent and API only, no in-browser signing. See /api.

[ verify this service ($0.25) ]

To request delisting, email info@x402-list.com or update your listing at /services/ipintel-ai-ip-lookup-risk-api/update.