# AbuseIPDB

**Canonical:** https://apis.io/providers/abuseipdb/  
**Website:** https://www.abuseipdb.com/  
**APIs profiled:** 4

AbuseIPDB is a community-driven project to help system administrators, webmasters, and security analysts check the reputation of IP addresses and report malicious activity. The free APIv2 surface lets developers query a single IP, check a CIDR block, retrieve paginated reports, download a curated blacklist, submit single or bulk abuse reports, and clear their own past reports for an address. AbuseIPDB underpins fail2ban, UFW, Cloudflare WAF, Wazuh, Splunk SOAR, and dozens of other firewall and SIEM integrations across the security community.

## Kin Score — 56.1 / 100 (strong)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 56.1).

| Facet | Score |
|---|---|
| Discoverability | 81.5 |
| Contract Quality | 71.0 |
| Governance | 25.0 |
| Contract Governance | 25.0 |
| Operational Transparency | 34.2 |
| Developer Ergonomics | 57.1 |
| Commercial Clarity | 56.6 |
| Access Clarity | 56.6 |

## Agent readiness — 32.1 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | verified |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Paid · Self-serve signup — onboarding: self-serve, pricing: paid, trial: no (confidence: high).

## APIs (4)

- **AbuseIPDB Blacklist API** — Endpoints for downloading the community blacklist.
- **AbuseIPDB Management API** — Endpoints for managing your own reports.
- **AbuseIPDB Reports API** — Endpoints for submitting and retrieving abuse reports.
- **AbuseIPDB Reputation API** — Endpoints for looking up the abuse data of an IP or CIDR network.

## Agentic access (1)

- **Abuseipdb Agentic Access** — 7 operations · 3 acting

## Security (2)

- **Abuseipdb Authentication** — apiKey · 1 scheme
- **Abuseipdb Domain Security** — TLSv1.3 · DNSSEC

## Plans (1)

- **Abuseipdb Plans Pricing**

## Use cases (6)

- **SSH / RDP Brute-Force Defence** — Auto-block and report SSH/RDP brute-force sources via fail2ban, UFW, or endlessh integrations.
- **WAF Augmentation** — Enrich Cloudflare / Nginx / custom WAF rulesets with the AbuseIPDB blacklist for IP-based pre-filtering.
- **SIEM / SOC Enrichment** — Add AbuseIPDB context to Splunk SOAR, Wazuh, and TheHive alerts for analyst triage.
- **Bot and Crawler Filtering** — Score request source IPs before serving e-commerce or login pages to block known-abusive infrastructure.
- **Threat Hunting and OSINT** — Combine AbuseIPDB with VirusTotal, Shodan, GreyNoise and similar feeds (e.g. malwoverview) during incident response.
- **Bulk Reporting from Edge Logs** — Convert nightly access logs into CSV bulk reports to feed the AbuseIPDB community blacklist.

## Tags

Anti Malware, Blacklist, Cybersecurity, IP Reputation, Network Security, Public APIs, Threat Intelligence

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/abuseipdb/). Scores are computed from the provider's own public artifacts under a published rubric.
