{"uid":"cap_bpTI8y80xhQdjWhcGq1rY","slug":"ip-reputation-check-bulk-3e443aba","name":"ip-reputation-check-bulk","description":"Bulk ip reputation check: up to 20 ips in one call, processed concurrently, results returned in input order with a per-item error field and a count of failures. Same answer per item as the single /ip-reputation endpoint (IP reputation check). Batch enrichment for agents that hold a list. $0.01 per batch.","url":"https://intel.rallylive.ca/bulk/ip-reputation","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","properties":{}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.1","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.1/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_Bn8-DT3Uh5wrCEBdJx5lk","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.1","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks the reputation of up to 20 IP addresses in a single concurrent batch call, returning per-item results in input order with error counts.","exampleAgentPrompt":"Can you check the reputation of these 15 IP addresses all at once and tell me which ones look malicious or suspicious, along with any errors for ones that couldn't be resolved?","exampleUseCases":[{"title":"Flagging risky IPs from server logs","prompt":"I pulled a list of 18 unique IPs from our web server access logs — can you run a bulk reputation check on all of them and tell me which ones are flagged as threats or abusive?"},{"title":"Pre-screening IPs before allowlisting","prompt":"Before I add these 12 IP addresses to our firewall allowlist, can you check their reputation scores all at once so I can see if any of them are known bad actors?"},{"title":"Enriching SIEM alert data with threat intel","prompt":"I have 20 IP addresses that triggered alerts in our SIEM today — can you do a batch reputation check on all of them concurrently and give me the results in the same order, including any failures?"}],"resultDescription":"An ordered array of per-item reputation results matching the input IP list, each containing the same fields as a single /ip-reputation lookup (reputation score, threat classification, abuse indicators, etc.) plus a per-item error field for any that failed, and a top-level count of total failures.","failureModes":["Exceeding the 20-IP batch limit may result in rejection or truncation","Individual IPs that are malformed return per-item errors rather than failing the whole batch","Network timeouts for specific IPs are captured in the per-item error field","Payment failure (x402) blocks the entire batch call","Results for unreachable or private IPs may return null reputation data with an error flag"],"whenToPreferThis":"Use this endpoint when you have a list of 2–20 IP addresses that all need reputation checks, rather than making sequential single-IP calls. It processes all IPs concurrently and returns results in input order, making it significantly faster and cheaper per IP than chaining individual lookups. Prefer this over the single /ip-reputation endpoint whenever you're enriching a batch of log entries, alert data, or candidate IP lists.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T06:42:11.843Z","isFirstParty":false}