IP Intelligence API

Real-time IP threat scoring, geolocation and network intelligence.
Free tier with 1,000 requests/day — auto-provisioned on first use.

Checking status...

Get started in 60 seconds

  1. Create an API key in the WAYSCloud dashboard (Account → API keys).
  2. Send the key in the X-API-Key header:
# Full IP summary: geolocation, network, threat score and detection flags
curl https://api.wayscloud.services/v1/ip/8.8.8.8 \
  -H "X-API-Key: wayscloud_ipintel_YOUR_KEY"

# Threat assessment only
curl https://api.wayscloud.services/v1/ip/8.8.8.8/threat \
  -H "X-API-Key: wayscloud_ipintel_YOUR_KEY"

The free tier is activated automatically the first time your key calls the IP Intelligence API — no separate signup and no credit card. Higher quotas and plans are available in the dashboard.

No API key? Use the public lookup endpoints.
Quick keyless lookups on this site (no signup, fair use): curl ip.wayscloud.services/json (your own IP), /json/8.8.8.8, /geo/8.8.8.8, /country/8.8.8.8, /reverse/8.8.8.8.
The full API adds threat scoring with categories, ASN and country intelligence, live feeds, abuse reporting and delisting.

API endpoints

Base URL https://api.wayscloud.services — all endpoints use the X-API-Key header.

EndpointDescription
GET /v1/ip/{ip}Full summary: geolocation, network identity, threat assessment and detection flags.
GET /v1/ip/{ip}/geoGeolocation, reverse DNS and ASN information.
GET /v1/ip/{ip}/threatThreat score (0–100), risk level, categories and flags.
GET /v1/ip/threats/liveLive threat feed with the most recently reported IPs.
GET /v1/ip/countries/{code}Country-level threat summary and top categories.
GET /v1/ip/asn/{asn}Network-level threat summary for an autonomous system.
POST /v1/ip/reportSubmit an abuse report (fail2ban, honeypot, IDS or manual).
POST /v1/ip/reporters/registerRegister your service as an abuse reporter.
POST /v1/ip/reporters/verifyVerify your domain with a DNS TXT record (trust score 1.0).
POST /v1/ip/delistRequest review or removal of an IP from the threat lists.

Example response

Response from GET /v1/ip/8.8.8.8

{
  "ip": "8.8.8.8",
  "ip_version": 4,
  "hostname": "dns.google",
  "geo": {
    "country": "US",
    "country_name": "United States",
    "city": "Mountain View",
    "region": "California",
    "latitude": 37.386,
    "longitude": -122.0838,
    "timezone": "America/Los_Angeles"
  },
  "network": {
    "asn": 15169,
    "isp": "Google LLC",
    "org": "Google LLC",
    "connection_type": "datacenter"
  },
  "threat": {
    "score": 0,
    "level": "clean",
    "is_clean": true
  },
  "flags": {
    "vpn": false,
    "proxy": false,
    "tor": false,
    "datacenter": true,
    "botnet": false
  }
}

Free tier & contributing

Contribute to the network
Share what you see
  • Register as an abuse reporter
  • Trust score 0.4 → 1.0 with DNS verification
  • Report from fail2ban, honeypots or an IDS
  • Duplicates (same IP + category within 1h) are merged
  • Request delisting for false positives

Reports are weighted by reporter trust, severity, category and age, so verified contributors strengthen the score for everyone. Reporting counts against your daily quota.

Documentation