IP Intelligence API
Real-time IP threat scoring, geolocation and network intelligence.
Free tier with 1,000 requests/day — auto-provisioned on first use.
Checking status...
Get started in 60 seconds
- Create an API key in the WAYSCloud dashboard (Account → API keys).
- Send the key in the
X-API-Keyheader:
# Full IP summary: geolocation, network, threat score and detection flags curl https://api.wayscloud.services/v1/ip/8.8.8.8 \ -H "X-API-Key: wayscloud_ipintel_YOUR_KEY" # Threat assessment only curl https://api.wayscloud.services/v1/ip/8.8.8.8/threat \ -H "X-API-Key: wayscloud_ipintel_YOUR_KEY"
The free tier is activated automatically the first time your key calls the IP Intelligence API — no separate signup and no credit card. Higher quotas and plans are available in the dashboard.
No API key? Use the public lookup endpoints.
Quick keyless lookups on this site (no signup, fair use):
The full API adds threat scoring with categories, ASN and country intelligence, live feeds, abuse reporting and delisting.
Quick keyless lookups on this site (no signup, fair use):
curl ip.wayscloud.services/json (your own IP),
/json/8.8.8.8, /geo/8.8.8.8, /country/8.8.8.8,
/reverse/8.8.8.8.The full API adds threat scoring with categories, ASN and country intelligence, live feeds, abuse reporting and delisting.
API endpoints
Base URL https://api.wayscloud.services — all endpoints use the X-API-Key header.
| Endpoint | Description |
|---|---|
GET /v1/ip/{ip} | Full summary: geolocation, network identity, threat assessment and detection flags. |
GET /v1/ip/{ip}/geo | Geolocation, reverse DNS and ASN information. |
GET /v1/ip/{ip}/threat | Threat score (0–100), risk level, categories and flags. |
GET /v1/ip/threats/live | Live threat feed with the most recently reported IPs. |
GET /v1/ip/countries/{code} | Country-level threat summary and top categories. |
GET /v1/ip/asn/{asn} | Network-level threat summary for an autonomous system. |
POST /v1/ip/report | Submit an abuse report (fail2ban, honeypot, IDS or manual). |
POST /v1/ip/reporters/register | Register your service as an abuse reporter. |
POST /v1/ip/reporters/verify | Verify your domain with a DNS TXT record (trust score 1.0). |
POST /v1/ip/delist | Request review or removal of an IP from the threat lists. |
Example response
Response from GET /v1/ip/8.8.8.8
{
"ip": "8.8.8.8",
"ip_version": 4,
"hostname": "dns.google",
"geo": {
"country": "US",
"country_name": "United States",
"city": "Mountain View",
"region": "California",
"latitude": 37.386,
"longitude": -122.0838,
"timezone": "America/Los_Angeles"
},
"network": {
"asn": 15169,
"isp": "Google LLC",
"org": "Google LLC",
"connection_type": "datacenter"
},
"threat": {
"score": 0,
"level": "clean",
"is_clean": true
},
"flags": {
"vpn": false,
"proxy": false,
"tor": false,
"datacenter": true,
"botnet": false
}
}
Free tier & contributing
Free tier
1,000 requests/day
- Auto-provisioned on first use
- All IP Intelligence endpoints
- No credit card
- Higher quotas via the dashboard
Contribute to the network
Share what you see
- Register as an abuse reporter
- Trust score 0.4 → 1.0 with DNS verification
- Report from fail2ban, honeypots or an IDS
- Duplicates (same IP + category within 1h) are merged
- Request delisting for false positives
Reports are weighted by reporter trust, severity, category and age, so verified contributors strengthen the score for everyone. Reporting counts against your daily quota.