{"uid":"cap_FXTG1BvFXPvML43wzMG1J","slug":"ip-whois-rdap-bulk-lookup-0b7504fc","name":"IP WHOIS RDAP Bulk Lookup","description":"Bulk ip whois rdap: up to 20 ips in one call, processed concurrently, results returned in input order with a per-item error field and a count of failures. Same answer per item as the single /ip/rdap endpoint (IP WHOIS via RDAP). Batch enrichment for agents that hold a list. $0.01 per batch.","url":"https://intel.rallylive.ca/bulk/ip/rdap","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","properties":{}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.1","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.1/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_w-93KniGeReiCE9bhoIlh","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.1","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Performs concurrent RDAP-based IP WHOIS lookups for up to 20 IP addresses in a single call, returning results in input order with per-item error fields.","exampleAgentPrompt":"I have a list of 15 IP addresses from our server logs — can you look up the WHOIS/RDAP registration data for all of them at once and tell me who owns each one, flagging any that fail?","exampleUseCases":[{"title":"Security log IP attribution","prompt":"I've got these 18 IPs from our firewall logs that triggered alerts — can you batch look up their RDAP WHOIS data so I know which organizations and ASNs they belong to?"},{"title":"Fraud investigation IP enrichment","prompt":"Here are 12 IP addresses from suspicious transactions — run a bulk RDAP lookup on all of them and show me the network owner and abuse contact for each one."},{"title":"Marketing lead geolocation prep","prompt":"I have 20 IP addresses from form submissions and I need the network registration info for each one — can you do a bulk WHOIS RDAP lookup and tell me which fail?"}],"resultDescription":"An ordered array of RDAP WHOIS results matching the input IP list. Each item contains the same fields as a single /ip/rdap lookup (network name, handle, ASN, organization, country, abuse contact, registration dates, etc.) plus a per-item error field if the lookup failed. A top-level failure count indicates how many items errored.","failureModes":["Input list exceeds 20 IPs — request rejected","Invalid IP address format in list — per-item error returned for that entry","RDAP registry unavailable for a specific IP block — per-item error with failure count incremented","Payment not completed — 402 response before processing begins","Empty input list — likely 400 bad request"],"whenToPreferThis":"Choose this endpoint when you have 2–20 IP addresses to enrich simultaneously and want to avoid the latency and cost of sequential single-IP lookups. It processes all IPs concurrently and returns results in the original input order, making it ideal for batch security analysis, log enrichment, or fraud investigation pipelines. For a single IP, prefer the /ip/rdap sibling endpoint instead.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T07:22:02.060Z","isFirstParty":false}