Home
Providers
AbuseIPDB
AbuseIPDB
AbuseIPDB is a community-driven project to help system administrators, webmasters, and security analysts check the reputation of IP addresses and report malicious activity. The free APIv2 surface lets developers query a single IP, check a CIDR block, retrieve paginated reports, download a curated blacklist, submit single or bulk abuse reports, and clear their own past reports for an address. AbuseIPDB underpins fail2ban, UFW, Cloudflare WAF, Wazuh, Splunk SOAR, and dozens of other firewall and SIEM integrations across the security community.
AbuseIPDB publishes 4 APIs on the APIs.io network, including Blacklist API, Management API, Reports API, and 1 more. Tagged areas include Anti Malware, Blacklist, Cyber Security, IP Reputation, and Network Security.
The AbuseIPDB catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.
AbuseIPDB’s developer surface includes authentication, documentation, signup flow, pricing, engineering blog, FAQ, support, and 29 more developer resources.
4 APIs
8 Features
6 Use Cases
Anti Malware Blacklist Cyber Security IP Reputation Network Security Public APIs Threat Intelligence
On this page
Kin Score
APIs 4
Postman 1
Open Collections 1
Arazzo 7
Pricing Plans 1
Rate Limits 1
FinOps 1
Features 8
Vocabularies 1
Spectral Rules 2
JSON Schema 3
JSON Structure 3
Examples 6
Security Posture 2
Agentic Access 1
Use Cases 6
Integrations 11
Solutions 4
Resources 36
apis.yml
37 Operational Transparency
Composite quality — 69.1/100 · exemplar
Contract Quality
18.9 / 25
Developer Ergonomics
12.2 / 20
Commercial Clarity
16.8 / 20
Operational Transparency
4.8 / 13
Agent readiness — 34/100 · agent aware
Machine-Readable Contract
18 / 18
Agentic Access Contract
10 / 10
MCP Server
0 / 12
Machine-Readable Auth
10 / 10
Idempotency
0 / 9
Stable Error Semantics
0 / 8
Request/Response Examples
0 / 7
Rate-Limit Signaling
7 / 7
Typed Event Surface
0 / 6
Agent Skills
0 / 5
Well-Known Catalog
0 / 4
Consent & Bot Identity
0 / 3
A2A Agent Card
0 / 8
Dry-Run / Simulate Mode
0 / 4
Individual APIs this provider publishes, each with its own machine-readable definition.
Ready-to-run Postman collections for exercising this provider's APIs.
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
Multi-step API workflows described with the Arazzo specification.
Scroll for all 7
Published pricing tiers and plan structures.
Documented rate limits and quota policies.
Cost, billing, and metering signals for API financial operations.
Notable capabilities this provider offers.
Scroll for all 8
JSON-LD contexts and semantic vocabularies used across these APIs.
Spectral governance rulesets for linting and validating these APIs.
Standalone JSON Schema definitions for this provider's data models.
JSON Structure definitions describing this provider's data shapes.
Example request and response payloads for these APIs.
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Recommended x-agentic-access execution contracts for AI agents.
What developers build with this provider.
Pre-built integrations with other platforms and tools.
Scroll for all 11
Packaged solutions this provider offers.
Get Started 3
Portal, sign-up, and the first successful call
Documentation 1
Reference material describing how the API behaves
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 9
Pagination, idempotency, versioning, errors, and events
Scroll for all 9
Build 8
SDKs, sample code, and the tooling you integrate with
Scroll for all 8
Access & Security 2
Authentication, authorization, and security posture
Operate 4
Status, limits, changes, and where to get help
Commercial 6
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API
Source (apis.yml)
aid: abuseipdb
name: AbuseIPDB
description: AbuseIPDB is a community-driven project to help system administrators, webmasters, and security analysts check
the reputation of IP addresses and report malicious activity. The free APIv2 surface lets developers query a single IP,
check a CIDR block, retrieve paginated reports, download a curated blacklist, submit single or bulk abuse reports, and clear
their own past reports for an address. AbuseIPDB underpins fail2ban, UFW, Cloudflare WAF, Wazuh, Splunk SOAR, and dozens
of other firewall and SIEM integrations across the security community.
url: https://docs.abuseipdb.com/
humanURL: https://www.abuseipdb.com/
baseURL: https://api.abuseipdb.com/api/v2/
accessModel:
pricing: paid
onboarding: self-serve
trial: false
try_now: false
public: false
label: Paid · Self-serve signup
confidence: high
source:
- plans
- authentication
generated: '2026-07-22'
method: derived
image: https://www.abuseipdb.com/img/abuseipdb-logo.svg
specificationVersion: '0.20'
type: Index
access: 3rd-Party
created: '2026-05-28'
modified: '2026-05-30'
x-source: public-apis/public-apis
x-category: Anti-Malware
x-tier: 3
x-tier-reason: bulk-registered-from-public-apis
tags:
- Anti Malware
- Blacklist
- Cyber Security
- IP Reputation
- Network Security
- Public APIs
- Threat Intelligence
apis:
- aid: abuseipdb:abuseipdb-blacklist-api
name: AbuseIPDB Blacklist API
description: Endpoints for downloading the community blacklist.
humanURL: https://docs.abuseipdb.com/
baseURL: https://api.abuseipdb.com/api/v2/
tags:
- Blacklist
properties:
- type: OpenAPI
url: openapi/abuseipdb-blacklist-api-openapi.yml
- type: Documentation
url: https://docs.abuseipdb.com/
- type: APIReference
url: https://docs.abuseipdb.com/#check-endpoint
- type: APIReference
url: https://docs.abuseipdb.com/#reports-endpoint
- type: APIReference
url: https://docs.abuseipdb.com/#blacklist-endpoint
- type: APIReference
url: https://docs.abuseipdb.com/#report-endpoint
- type: APIReference
url: https://docs.abuseipdb.com/#bulk-report-endpoint
- type: APIReference
url: https://docs.abuseipdb.com/#check-block-endpoint
- type: APIReference
url: https://docs.abuseipdb.com/#clear-address-endpoint
- type: Authentication
url: https://docs.abuseipdb.com/#authentication
- type: RateLimits
url: https://docs.abuseipdb.com/#rate-limit-headers
- type: ErrorCodes
url: https://docs.abuseipdb.com/#error-handling
- type: CodeExamples
url: https://docs.abuseipdb.com/#api-clients
- type: JSONSchema
url: json-schema/abuseipdb-check-response-schema.json
- type: JSONSchema
url: json-schema/abuseipdb-report-schema.json
- type: JSONSchema
url: json-schema/abuseipdb-blacklist-entry-schema.json
- type: JSONStructure
url: json-structure/abuseipdb-check-response-structure.json
- type: JSONStructure
url: json-structure/abuseipdb-report-structure.json
- type: JSONStructure
url: json-structure/abuseipdb-blacklist-entry-structure.json
- type: JSONLD
url: json-ld/abuseipdb-context.jsonld
- type: Examples
url: examples/abuseipdb-check-example.json
- type: Examples
url: examples/abuseipdb-report-example.json
- type: Examples
url: examples/abuseipdb-blacklist-example.json
- type: Examples
url: examples/abuseipdb-check-block-example.json
- type: Examples
url: examples/abuseipdb-reports-example.json
- type: Examples
url: examples/abuseipdb-bulk-report-example.json
- aid: abuseipdb:abuseipdb-management-api
name: AbuseIPDB Management API
description: Endpoints for managing your own reports.
humanURL: https://docs.abuseipdb.com/
baseURL: https://api.abuseipdb.com/api/v2/
tags:
- Management
properties:
- type: OpenAPI
url: openapi/abuseipdb-management-api-openapi.yml
- type: Documentation
url: https://docs.abuseipdb.com/
- type: APIReference
url: https://docs.abuseipdb.com/#check-endpoint
- type: APIReference
url: https://docs.abuseipdb.com/#reports-endpoint
- type: APIReference
url: https://docs.abuseipdb.com/#blacklist-endpoint
- type: APIReference
url: https://docs.abuseipdb.com/#report-endpoint
- type: APIReference
url: https://docs.abuseipdb.com/#bulk-report-endpoint
- type: APIReference
url: https://docs.abuseipdb.com/#check-block-endpoint
- type: APIReference
url: https://docs.abuseipdb.com/#clear-address-endpoint
- type: Authentication
url: https://docs.abuseipdb.com/#authentication
- type: RateLimits
url: https://docs.abuseipdb.com/#rate-limit-headers
- type: ErrorCodes
url: https://docs.abuseipdb.com/#error-handling
- type: CodeExamples
url: https://docs.abuseipdb.com/#api-clients
- type: JSONSchema
url: json-schema/abuseipdb-check-response-schema.json
- type: JSONSchema
url: json-schema/abuseipdb-report-schema.json
- type: JSONSchema
url: json-schema/abuseipdb-blacklist-entry-schema.json
- type: JSONStructure
url: json-structure/abuseipdb-check-response-structure.json
- type: JSONStructure
url: json-structure/abuseipdb-report-structure.json
- type: JSONStructure
url: json-structure/abuseipdb-blacklist-entry-structure.json
- type: JSONLD
url: json-ld/abuseipdb-context.jsonld
- type: Examples
url: examples/abuseipdb-check-example.json
- type: Examples
url: examples/abuseipdb-report-example.json
- type: Examples
url: examples/abuseipdb-blacklist-example.json
- type: Examples
url: examples/abuseipdb-check-block-example.json
- type: Examples
url: examples/abuseipdb-reports-example.json
- type: Examples
url: examples/abuseipdb-bulk-report-example.json
- aid: abuseipdb:abuseipdb-reports-api
name: AbuseIPDB Reports API
description: Endpoints for submitting and retrieving abuse reports.
humanURL: https://docs.abuseipdb.com/
baseURL: https://api.abuseipdb.com/api/v2/
tags:
- Reports
properties:
- type: OpenAPI
url: openapi/abuseipdb-reports-api-openapi.yml
- type: Documentation
url: https://docs.abuseipdb.com/
- type: APIReference
url: https://docs.abuseipdb.com/#check-endpoint
- type: APIReference
url: https://docs.abuseipdb.com/#reports-endpoint
- type: APIReference
url: https://docs.abuseipdb.com/#blacklist-endpoint
- type: APIReference
url: https://docs.abuseipdb.com/#report-endpoint
- type: APIReference
url: https://docs.abuseipdb.com/#bulk-report-endpoint
- type: APIReference
url: https://docs.abuseipdb.com/#check-block-endpoint
- type: APIReference
url: https://docs.abuseipdb.com/#clear-address-endpoint
- type: Authentication
url: https://docs.abuseipdb.com/#authentication
- type: RateLimits
url: https://docs.abuseipdb.com/#rate-limit-headers
- type: ErrorCodes
url: https://docs.abuseipdb.com/#error-handling
- type: CodeExamples
url: https://docs.abuseipdb.com/#api-clients
- type: JSONSchema
url: json-schema/abuseipdb-check-response-schema.json
- type: JSONSchema
url: json-schema/abuseipdb-report-schema.json
- type: JSONSchema
url: json-schema/abuseipdb-blacklist-entry-schema.json
- type: JSONStructure
url: json-structure/abuseipdb-check-response-structure.json
- type: JSONStructure
url: json-structure/abuseipdb-report-structure.json
- type: JSONStructure
url: json-structure/abuseipdb-blacklist-entry-structure.json
- type: JSONLD
url: json-ld/abuseipdb-context.jsonld
- type: Examples
url: examples/abuseipdb-check-example.json
- type: Examples
url: examples/abuseipdb-report-example.json
- type: Examples
url: examples/abuseipdb-blacklist-example.json
- type: Examples
url: examples/abuseipdb-check-block-example.json
- type: Examples
url: examples/abuseipdb-reports-example.json
- type: Examples
url: examples/abuseipdb-bulk-report-example.json
- aid: abuseipdb:abuseipdb-reputation-api
name: AbuseIPDB Reputation API
description: Endpoints for looking up the abuse data of an IP or CIDR network.
humanURL: https://docs.abuseipdb.com/
baseURL: https://api.abuseipdb.com/api/v2/
tags:
- Reputation
properties:
- type: OpenAPI
url: openapi/abuseipdb-reputation-api-openapi.yml
- type: Documentation
url: https://docs.abuseipdb.com/
- type: APIReference
url: https://docs.abuseipdb.com/#check-endpoint
- type: APIReference
url: https://docs.abuseipdb.com/#reports-endpoint
- type: APIReference
url: https://docs.abuseipdb.com/#blacklist-endpoint
- type: APIReference
url: https://docs.abuseipdb.com/#report-endpoint
- type: APIReference
url: https://docs.abuseipdb.com/#bulk-report-endpoint
- type: APIReference
url: https://docs.abuseipdb.com/#check-block-endpoint
- type: APIReference
url: https://docs.abuseipdb.com/#clear-address-endpoint
- type: Authentication
url: https://docs.abuseipdb.com/#authentication
- type: RateLimits
url: https://docs.abuseipdb.com/#rate-limit-headers
- type: ErrorCodes
url: https://docs.abuseipdb.com/#error-handling
- type: CodeExamples
url: https://docs.abuseipdb.com/#api-clients
- type: JSONSchema
url: json-schema/abuseipdb-check-response-schema.json
- type: JSONSchema
url: json-schema/abuseipdb-report-schema.json
- type: JSONSchema
url: json-schema/abuseipdb-blacklist-entry-schema.json
- type: JSONStructure
url: json-structure/abuseipdb-check-response-structure.json
- type: JSONStructure
url: json-structure/abuseipdb-report-structure.json
- type: JSONStructure
url: json-structure/abuseipdb-blacklist-entry-structure.json
- type: JSONLD
url: json-ld/abuseipdb-context.jsonld
- type: Examples
url: examples/abuseipdb-check-example.json
- type: Examples
url: examples/abuseipdb-report-example.json
- type: Examples
url: examples/abuseipdb-blacklist-example.json
- type: Examples
url: examples/abuseipdb-check-block-example.json
- type: Examples
url: examples/abuseipdb-reports-example.json
- type: Examples
url: examples/abuseipdb-bulk-report-example.json
common:
- type: AgenticAccess
url: agentic-access/abuseipdb-agentic-access.yml
- type: DomainSecurity
url: security/abuseipdb-domain-security.yml
- type: Authentication
url: authentication/abuseipdb-authentication.yml
- type: PostmanWorkspace
url: https://www.postman.com/kinlaneapi/abuseipdb/overview
- type: Arazzo
url: arazzo/abuseipdb-blacklist-triage-workflow.yml
name: AbuseIPDB Blacklist Triage
- type: Arazzo
url: arazzo/abuseipdb-block-scan-and-check-workflow.yml
name: AbuseIPDB Block Scan And Check
- type: Arazzo
url: arazzo/abuseipdb-bulk-report-then-verify-workflow.yml
name: AbuseIPDB Bulk Report Then Verify
- type: Arazzo
url: arazzo/abuseipdb-check-then-report-workflow.yml
name: AbuseIPDB Check Then Report
- type: Arazzo
url: arazzo/abuseipdb-clear-false-positive-workflow.yml
name: AbuseIPDB Clear False Positive
- type: Arazzo
url: arazzo/abuseipdb-investigate-ip-workflow.yml
name: AbuseIPDB Investigate IP
- type: Arazzo
url: arazzo/abuseipdb-report-then-verify-workflow.yml
name: AbuseIPDB Report Then Verify
- type: Website
url: https://www.abuseipdb.com/
- type: Documentation
url: https://docs.abuseipdb.com/
- type: Signup
url: https://www.abuseipdb.com/register
- type: Login
url: https://www.abuseipdb.com/login
- type: DeveloperPortal
url: https://www.abuseipdb.com/account/api
name: API Key Dashboard
description: Account-level UI for issuing, rotating, and revoking AbuseIPDB API keys.
- type: Pricing
url: https://www.abuseipdb.com/pricing
description: Four tiers — Individual (free, 1,000 checks/day), Basic ($25/mo or $228/yr, 10,000 checks/day), Premium ($99/mo
or $1,068/yr, 50,000 checks/day), and Enterprise (custom direct-data access).
- type: Plans
url: plans/abuseipdb-plans-pricing.yml
- type: RateLimits
url: rate-limits/abuseipdb-rate-limits.yml
- type: SpectralRules
url: rules/abuseipdb-rules.yml
- type: Vocabulary
url: vocabulary/abuseipdb-vocabulary.yml
- type: FinOps
url: finops/abuseipdb-finops.yml
- type: Plans
url: https://www.abuseipdb.com/account/plans
name: Account Plans
- type: Blog
url: https://www.abuseipdb.com/blog
- type: FAQ
url: https://www.abuseipdb.com/faq.html
- type: Support
url: https://www.abuseipdb.com/contact
- type: Contact
url: https://www.abuseipdb.com/contact
- type: TermsOfService
url: https://www.abuseipdb.com/terms-of-service
- type: PrivacyPolicy
url: https://www.abuseipdb.com/privacy-policy
- type: GitHubOrganization
url: https://github.com/AbuseIPDB
description: Official AbuseIPDB org. Hosts `laravel` (Laravel AbuseIPDB middleware package) and `ip-lib` (forked PHP IPv4/IPv6
range library).
- type: SDKs
url: https://github.com/AbuseIPDB/laravel
name: AbuseIPDB Laravel Package
description: Official Laravel middleware that scores incoming requests against AbuseIPDB.
- type: SDKs
url: https://github.com/nickurt/laravel-abuseipdb
name: laravel-abuseipdb (community)
description: Community Laravel 11.x/12.x/13.x plugin for AbuseIPDB.
- type: SDKs
url: https://github.com/falegk/abuseipdb-rb
name: abuseipdb-rb (Ruby gem)
description: Community Ruby client gem for the AbuseIPDB API.
- type: SDKs
url: https://github.com/meatyite/python-abuseipdb
name: python-abuseipdb
description: Object-oriented Python wrapper for AbuseIPDB v2 API.
- type: SDKs
url: https://github.com/streanger/abuseipdb-wrapper
name: abuseipdb-wrapper (Python)
description: Python wrapper for the AbuseIPDB API.
- type: CLI
url: https://github.com/kristuff/abuseipdb-cli
name: abuseipdb-cli
description: CLI tool to check, report, and download the AbuseIPDB blacklist from the command line.
- type: Integrations
data:
- name: Fail2Ban
description: Pre-packaged AbuseIPDB action ships with fail2ban; reports banned offenders directly to AbuseIPDB.
- name: UFW (Uncomplicated Firewall)
description: Multiple community projects (sefinek/UFW-AbuseIPDB-Reporter, jseutens/ufw-abuseipdb) ingest UFW logs and
report or ingest the AbuseIPDB blacklist.
- name: Cloudflare WAF
description: sefinek/Cloudflare-WAF-To-AbuseIPDB streams Cloudflare WAF events into AbuseIPDB reports.
- name: Splunk SOAR
description: Official splunk-soar-connectors/abuseipdb connector enriches Splunk SOAR playbooks with AbuseIPDB reputation.
- name: Wazuh
description: marciuscosta/abuseipdb-wazuh-integration wires AbuseIPDB enrichment into Wazuh with a local cache and multi-key
support.
- name: CrowdSec
description: goremykin/crowdsec-abuseipdb-blocklist converts CrowdSec data into AbuseIPDB blocklists.
- name: Endlessh
description: elhenro/endlessh-auto-report-abuseipdb auto-reports SSH tarpit visitors to AbuseIPDB.
- name: Nginx
description: tmiland/abuseipdb-php-nginx-blacklist-create generates an Nginx-ready blocklist file from AbuseIPDB.
- name: Zen Cart
description: CcMarc/AbuseIPDB plugs AbuseIPDB into the Zen Cart e-commerce platform.
- name: TheHive
description: AbuseIPDB enrichment is used by SOAR/IR pipelines like malwarekid/SOAR-Flow alongside Wazuh and TheHive.
- name: IPinfo
description: AbuseIPDB sources its IP geolocation, ISP, usage type, and domain data from IPinfo.
- type: Features
data:
- name: IP Reputation Lookups
description: Query any IPv4 or IPv6 address for its abuse confidence score, total reports, distinct reporters, and country/ISP
metadata.
- name: Community-Sourced Blacklist
description: Downloadable daily blacklist of high-confidence abusive IPs, with configurable confidence threshold, country
filters, IP version, and result limit.
- name: Abuse Reporting
description: Submit single or bulk abuse reports tagged with one or more standard category IDs (e.g. SSH Brute-Force,
DDoS, Web App Attack).
- name: CIDR Block Checking
description: Score whole subnets in one call via the CHECK-BLOCK endpoint, with subscriber tiers supporting up to /16
networks.
- name: Categorised Abuse Taxonomy
description: 23 standard report categories (DNS Compromise, Open Proxy, Brute-Force, Phishing, etc.) for consistent classification.
- name: Self-Service Report Clearing
description: Remove your own reports for a given IP via the CLEAR-ADDRESS endpoint if a report was made in error.
- name: Standard Rate-Limit Headers
description: Every response carries X-RateLimit-Limit / Remaining / Reset and Retry-After, simplifying back-off in clients.
- name: Whitelist Awareness
description: Responses include an `isWhitelisted` flag so consumers can avoid blocking known-good infrastructure.
- type: UseCases
data:
- name: SSH / RDP Brute-Force Defence
description: Auto-block and report SSH/RDP brute-force sources via fail2ban, UFW, or endlessh integrations.
- name: WAF Augmentation
description: Enrich Cloudflare / Nginx / custom WAF rulesets with the AbuseIPDB blacklist for IP-based pre-filtering.
- name: SIEM / SOC Enrichment
description: Add AbuseIPDB context to Splunk SOAR, Wazuh, and TheHive alerts for analyst triage.
- name: Bot and Crawler Filtering
description: Score request source IPs before serving e-commerce or login pages to block known-abusive infrastructure.
- name: Threat Hunting and OSINT
description: Combine AbuseIPDB with VirusTotal, Shodan, GreyNoise and similar feeds (e.g. malwoverview) during incident
response.
- name: Bulk Reporting from Edge Logs
description: Convert nightly access logs into CSV bulk reports to feed the AbuseIPDB community blacklist.
- type: Solutions
data:
- name: Individual (Free)
description: 1,000 checks/day, 100 block checks, 5 blacklist downloads. Aimed at hobby admins and home labs.
- name: Basic
description: $25/mo. 10,000 checks/day, 1,000 block checks, 100 bulk reports, customisable blacklist up to 100,000 IPs.
- name: Premium
description: $99/mo. 50,000 checks/day, 5,000 block checks, 500 bulk reports, customisable blacklist up to 500,000 IPs.
- name: Enterprise
description: Custom-priced direct data access for ISPs and large security organisations.
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com