IP Threat Intelligence
IP and Network IntelligenceIP Threat Intelligence API — real-time risk signals for an IPv4 or IPv6 address. Returns a threat_score from 0 to 100 (higher is riskier) alongside the individual flags behind it: is_tor, is_proxy, is_residential_proxy, is_vpn, is_relay, is_anonymous, is_known_attacker, is_bot, is_spam and is_cloud_provider — plus detected provider names and confidence scores for the proxy and VPN verdicts. ip_address is optional: omit it and the IP that called this API is looked up. Built for login-risk checks, signup fraud screening and payment review. Use the bulk endpoint to screen many addresses in one call.
🌍 Global — Available worldwide
What IP Threat Intelligence Is Used For
Real-time risk scoring
Score an IP from 0 to 100 at signup, login or checkout and act on the number.
Anonymised traffic detection
Identify Tor, proxy, residential proxy, VPN and relay traffic, with provider names and confidence.
Bot and spam filtering
Block known attackers, bots and spam sources before they reach your application.
Cloud traffic policy
Separate cloud provider ranges from residential users and apply different rules to each.
Quick Start
1. Copy your API key from Dashboard → API Keys
2. Send a POST request to /api/v1/ip/threat
3. Pass the key as Authorization: Bearer <key>
4. Read the result from the data object in the JSON response
cURL
curl -X POST https://app.way2api.com/api/v1/ip/threat \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"ip_address":"8.8.8.8"}'