{"uid":"cap_dteizP4EUmzWxFUXyBwwx","slug":"fraud-ip-reputation-d1e3f51c","name":"fraud-ip-reputation","description":"Reputation of a public IP address for anti-abuse and KYC. Returns ASN, AS-org, country, datacenter/hosting classification, Tor-exit and Spamhaus DROP flags, plus a deterministic risk score with reasons.","url":"https://payai.agentstools.dev/fraud/ip","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"type":"object","required":["ip"],"properties":{"ip":{"type":"string","description":"Public IPv4 address to screen"},"country":{"type":"string","description":"Optional 2-letter country the caller claims the IP is in, for a geo-mismatch check"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.005","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.005/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_yZJc6QhFPG8v8PTjFUl2O","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.005","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns ASN, country, datacenter/hosting classification, Tor-exit and Spamhaus DROP flags, and a deterministic risk score for a public IPv4 address.","exampleAgentPrompt":"Can you check the reputation of IP 198.51.100.42 — I want to know if it's a datacenter, Tor exit node, or on any blocklists, and get a risk score for it?","exampleUseCases":[{"title":"Block high-risk sign-ups at registration","prompt":"Before we create this account, screen the sign-up IP 203.0.113.77 for me — check if it's a Tor exit node, hosted on a datacenter, or on the Spamhaus DROP list, and give me the risk score so we can decide whether to allow the registration."},{"title":"KYC geo-mismatch check during onboarding","prompt":"A user claims to be based in Germany but their IP is 185.220.101.5 — can you check whether that IP's geolocation actually matches Germany and flag any fraud signals like Tor or spam infrastructure?"},{"title":"Investigate suspicious payment attempt","prompt":"We just got a payment from IP 45.33.32.156 — can you pull its ASN, hosting classification, and Spamhaus DROP status, and tell me the risk score so I know if it's likely fraudulent?"}],"resultDescription":"A JSON object containing the IP's ASN number, AS organization name, resolved country, a boolean or label indicating datacenter/hosting classification, Tor-exit flag, Spamhaus DROP flag, a deterministic numeric risk score, and a list of human-readable reasons explaining the score.","failureModes":["Private or reserved IP addresses (RFC1918) are not valid inputs and will return an error","Missing required 'ip' query parameter returns a 400 or similar client error","Malformed IP string (non-IPv4 format) causes a validation error","Payment not completed (x402 flow not followed) results in a 402 Payment Required response","Rate limits or upstream data source unavailability may cause transient 5xx errors"],"whenToPreferThis":"Choose this endpoint when you need a single deterministic, multi-signal reputation score for a public IPv4 address combining ASN enrichment, datacenter classification, Tor-exit detection, and Spamhaus DROP blocklist checks in one call — ideal for KYC pipelines, fraud prevention at sign-up, and anti-abuse workflows where you need explainable risk reasons rather than a black-box ML score.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T19:06:02.923Z","isFirstParty":false}