Pay-per-call IP intelligence API. Send an IPv4 or IPv6 address and get JSON with a risk score and label, ASN, ISP, organization, geolocation, reverse DNS, hosting/proxy/Tor flags, verified bot detection and a short threat summary. Priced at $0.001 per call in USDC on Base.
Pay from $0.001 per request in USDC on Base, settled onchain via the x402 protocol, no signup, no API key needed.
ASSESSMENT
updated 5h agoEvidence-backed signals, not a single score. Click any chip for the proof. Measured values stay read-only; unknown is honest.
reliability 100%
- uptime 24h
- 100%
- uptime 7d
- 100%
- uptime 30d
- 100%
- uptime 90d
- 100%
- response p95
- 1214ms
- avg response
- 801ms
- total checks
- 47
compliance A (11/11)
11 of 11 x402 conformance checks pass. Full checklist below.
price $0.001 (p15 in Data)
- price (min)
- $0.001
- category percentile (min)
- p15 in Data
- endpoints / prices
- 1 / 1
- model
- flat
- stability
- 100%
risk clean
No deterministic risk flag. Risk fires only on an exact blocklist match, or a reserved-brand name with a mismatched verified payTo. Never from low uptime, a high price, or a model guess.
traction $1.05 30d · 35 buyers
- volume 30d
- $1.05
- buyers 30d
- 35
- settlements 30d
- 114
- last settlement
- 2026-07-18
- top buyer share
- 80% of 30d volume
- trend 7d vs 30d
- 0.25x the 30d daily rate
- networks
- eip155:8453
Attributed pro-quota: this payout address is shared, so volume and buyers are the operator-level figure divided by the services sharing it. A declared convention, not an individually observed measure, and still a conservative undercount.
Top buyer share is a concentration signal, not part of the ranking score.
WHAT IT DOES
ai-derivedProvides IP address lookup and risk assessment services
- category
- ip-risk
- in
- body
AI-generated summary. The measured data is never altered by it.
ENDPOINTS
| METHOD | PATH | DESCRIPTION | PRICE | NETWORK | ASSET |
|---|---|---|---|---|---|
| POST | /x402v2 | $0.001 | Base | USDC |
REQUEST / RESPONSE EXAMPLE
An unpaid request to POST /x402v2 returns HTTP 402 with the payment terms. Settle onchain via your facilitator, then retry with the X-Payment header.
curl -i -X POST 'https://api.ipintel.ai/x402v2'
// 402 response (captured by monitor) · 1 payload · click to expand
[
{
"error": "Payment required",
"accepts": [
{
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"extra": {
"name": "USD Coin",
"version": "2"
},
"payTo": "0x0550779CFBc832657A8BB46BAC9f359A5ad038B8",
"amount": "1000",
"scheme": "exact",
"network": "eip155:8453",
"maxTimeoutSeconds": 300
}
],
"resource": {
"url": "https://api.ipintel.ai/x402v2",
"tags": [
"ip-lookup",
"ip-intelligence",
"ip-risk-score",
"geolocation",
"proxy-vpn-tor"
],
"iconUrl": "https://api.ipintel.ai/favicon.ico",
"mimeType": "application/json",
"description": "Pay-per-call IP lookup and risk intelligence API. Send an IPv4 or IPv6 address and receive JSON with risk score, risk label, ASN, ISP, organization, geolocation, reverse DNS, hosting/proxy/VPN/Tor signals, verified bot detection, scanner/honeypot indicators, and AI-powered subnet behavior analysis via x402 v2 on Base.",
"serviceName": "IPIntel.ai IP Lookup & Risk API"
},
"extensions": {
"bazaar": {
"info": {
"input": {
"body": {
"ip": "8.8.8.8"
},
"type": "http",
"method": "POST",
"bodyType": "json"
},
"output": {
"type": "json",
"example": {
"ip": "8.8.8.8",
"asn": "AS15169",
"isp": "Google LLC",
"org": "Google Public DNS",
"city": "Ashburn",
"is_tor": false,
"country": "US",
"is_proxy": false,
"confidence": 100,
"is_hosting": true,
"risk_label": "Safe",
"risk_score": 15,
"reverse_dns": "dns.google",
"threat_summary": "This IP is considered safe and does not pose a threat. Only minimal and non-threatening activity has been observed.",
"is_verified_bot": false
}
}
},
"schema": {
"type": "object",
"$schema": "https://json-schema.org/draft/2020-12/schema",
"required": [
"input"
],
"properties": {
"input": {
"type": "object",
"required": [
"type",
"method",
"bodyType",
"body"
],
"properties": {
"body": {
"type": "object",
"required": [
"ip"
],
"properties": {
"ip": {
"type": "string",
"description": "IPv4 or IPv6 address to analyze, passed in the JSON request body"
}
},
"additionalProperties": false
},
"type": {
"type": "string",
"const": "http"
},
"method": {
"enum": [
"POST"
],
"type": "string"
},
"bodyType": {
"enum": [
"json",
"form-data",
"text"
],
"type": "string"
}
},
"additionalProperties": false
},
"output": {
"type": "object",
"required": [
"type"
],
"properties": {
"type": {
"type": "string"
},
"example": {
"type": "object",
"properties": {
"ip": {
"type": "string",
"description": "Queried IPv4 or IPv6 address"
},
"asn": {
"type": "string",
"description": "Autonomous system number"
},
"isp": {
"type": "string",
"description": "Internet service provider"
},
"org": {
"type": "string",
"description": "Organization name"
},
"city": {
"type": "string",
"description": "City, when available"
},
"is_tor": {
"type": "boolean",
"description": "Whether the IP appears to be a Tor exit node"
},
"country": {
"type": "string",
"description": "Country code or country name"
},
"is_proxy": {
"type": "boolean",
"description": "Whether the IP appears to be a proxy"
},
"confidence": {
"type": "number",
"description": "Confidence percentage from 0 to 100"
},
"is_hosting": {
"type": "boolean",
"description": "Whether the IP appears to belong to hosting/cloud infrastructure"
},
"risk_label": {
"type": "string",
"description": "Human-readable risk label"
},
"risk_score": {
"type": "number",
"description": "Risk score from 0 to 100"
},
"reverse_dns": {
"type": "string",
"description": "Reverse DNS hostname, when available"
},
"threat_summary": {
"type": "string",
"description": "Short natural-language threat assessment"
},
"is_verified_bot": {
"type": "boolean",
"description": "Whether the IP appears to be a verified known bot"
}
},
"additionalProperties": true
}
}
}
}
}
}
},
"x402Version": 2
}
] UPTIME
RECENT CHECKS
OVER TIME
All charts share the 90d window selected here. Every series is also served as JSON at /api/v1/services/ipintel-ai-ip-lookup-risk-api/price, /scores, /volume and /buyers. On-chain volume and distinct buyers are measured over the service's settlement address and are a conservative undercount (only settlements that reach a measured facilitator are counted).
Shared payout address (2 other services). These bars are the full shared address (operator-level), so do not sum them across the services that share it. Where a per-service figure is attributed, the assessment block and the ranking, it is the address total divided pro-quota by the 3 services sharing it: a declared convention, not an individually observed measure.
Shared payout address (2 other services). These bars are the full shared address (operator-level), so do not sum them across the services that share it. Where a per-service buyer count is attributed, the assessment block and the ranking, it is divided pro-quota by the 3 services sharing the address and can be fractional: a declared convention, not an individually observed measure.
COMPLIANCE
11/11 checks pass · grade A- 402 payload captured
- accepts[] array present
- payTo address recoverable
- payTo at accepts[0].payTo (conformant shape)
- payTo is a valid on-chain address
- atomic price declared
- atomic price in a sane range
- asset (token) address declared
- network resolves to CAIP-2
- payment scheme declared
- served over HTTPS
EMBED THIS BADGE
<a href="https://x402-list.com/services/ipintel-ai-ip-lookup-risk-api?utm_source=badge&utm_medium=referral&utm_campaign=embed"> <img src="https://x402-list.com/badge/ipintel-ai-ip-lookup-risk-api.svg" alt="IPIntel.ai IP Lookup & Risk API listed on x402-list" height="28"> </a>
[](https://x402-list.com/services/ipintel-ai-ip-lookup-risk-api?utm_source=badge&utm_medium=referral&utm_campaign=embed)
<a href="https://x402-list.com/services/ipintel-ai-ip-lookup-risk-api?utm_source=badge&utm_medium=referral&utm_campaign=embed"> <img src="https://x402-list.com/badge/ipintel-ai-ip-lookup-risk-api.svg?data=uptime" alt="IPIntel.ai IP Lookup & Risk API uptime on x402-list" height="28"> </a>