{"uid":"cap_aeBSk-mWXbOjZ7JvB4CFD","slug":"tor-exit-node-bulk-checker-e252f05d","name":"Tor Exit Node Bulk Checker","description":"Bulk tor exit check: up to 20 ips in one call, processed concurrently, results returned in input order with a per-item error field and a count of failures. Same answer per item as the single /ip/is-tor endpoint (Tor exit node check). Batch enrichment for agents that hold a list. $0.01 per batch.","url":"https://intel.rallylive.ca/bulk/ip/is-tor","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","properties":{}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.1","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.1/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_ajRbF0ft6kbUiZpgrOBip","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.1","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks up to 20 IP addresses in one request to determine whether each is a known Tor exit node, returning ordered results with per-item error fields.","exampleAgentPrompt":"Check this list of IP addresses for me and tell me which ones are Tor exit nodes: 198.51.100.1, 203.0.113.5, 192.0.2.42, 198.51.100.77, 203.0.113.200.","exampleUseCases":[{"title":"Fraud screening on user signups","prompt":"I have a batch of 15 IP addresses from new user registrations today — can you check all of them and tell me which ones are Tor exit nodes so I can flag suspicious signups?"},{"title":"Security audit of access logs","prompt":"Here are 20 IPs that accessed our admin panel in the last hour: 198.51.100.1, 203.0.113.5, 192.0.2.10, 198.51.100.77, 203.0.113.200, 198.51.100.33, 192.0.2.55, 203.0.113.88, 198.51.100.9, 203.0.113.3, 192.0.2.22, 198.51.100.44, 203.0.113.11, 192.0.2.66, 198.51.100.55, 203.0.113.99, 192.0.2.77, 198.51.100.66, 203.0.113.7, 192.0.2.88 — which of these are Tor exit nodes?"},{"title":"Content platform anonymous user detection","prompt":"Can you run a Tor exit node check on these IPs from our comment system — I want to know which users might be posting anonymously through Tor so we can apply stricter moderation rules."}],"resultDescription":"An ordered array of results matching the input IP list, where each item contains the IP address, a boolean indicating whether it is a Tor exit node, a per-item error field (null if successful), and a summary count of how many items failed to process.","failureModes":["Exceeding 20 IPs per request returns a validation error","Malformed or non-IP strings cause per-item errors in the response rather than a full request failure","Network timeouts on concurrent lookups may increase the failure count","Payment not attached or insufficient USDC balance results in 402 response","Empty input list returns an error or empty result set"],"whenToPreferThis":"Use this endpoint when you have a list of 2–20 IP addresses that all need Tor exit node checking simultaneously, rather than making individual calls to the single-IP endpoint. It is ideal for batch fraud screening, log analysis, or any agent workflow that accumulates a set of IPs before acting. For a single IP, the sibling /ip/is-tor endpoint is more appropriate.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T07:06:37.091Z","isFirstParty":false}