AbuseIPDB · Schema
AbuseIPDB Report
A single abuse report submitted to or returned from the AbuseIPDB API.
Anti MalwareBlacklistCybersecurityIP ReputationNetwork SecurityPublic APIsThreat Intelligence
Properties
| Name | Type | Description |
|---|---|---|
| ip | string | The reported IPv4 or IPv6 address. |
| categories | object | One or more AbuseIPDB category IDs (e.g. 18 for SSH Brute-Force, 22 for DDoS Attack). |
| comment | string | Optional human-readable description and supporting log lines. Strip secrets and PII before sending. |
| timestamp | string | Optional ISO 8601 timestamp of when the abuse occurred. Defaults to the moment of submission. |
| reporterId | integer | Identifier of the reporting account (response only). |
| reporterCountryCode | string | ISO 3166-1 alpha-2 country code of the reporter (response only). |
| reporterCountryName | string | Country name of the reporter (response only). |
JSON Schema
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"$id": "https://raw.githubusercontent.com/api-evangelist/abuseipdb/main/json-schema/abuseipdb-report-schema.json",
"title": "AbuseIPDB Report",
"description": "A single abuse report submitted to or returned from the AbuseIPDB API.",
"type": "object",
"required": ["ip", "categories"],
"properties": {
"ip": { "type": "string", "description": "The reported IPv4 or IPv6 address." },
"categories": {
"oneOf": [
{ "type": "string", "description": "Comma-separated list of category IDs (submission form)." },
{ "type": "array", "items": { "type": "integer" }, "description": "Array of category IDs (response form)." }
],
"description": "One or more AbuseIPDB category IDs (e.g. 18 for SSH Brute-Force, 22 for DDoS Attack)."
},
"comment": {
"type": "string",
"description": "Optional human-readable description and supporting log lines. Strip secrets and PII before sending."
},
"timestamp": {
"type": "string",
"format": "date-time",
"description": "Optional ISO 8601 timestamp of when the abuse occurred. Defaults to the moment of submission."
},
"reporterId": { "type": "integer", "description": "Identifier of the reporting account (response only)." },
"reporterCountryCode": { "type": "string", "description": "ISO 3166-1 alpha-2 country code of the reporter (response only)." },
"reporterCountryName": { "type": "string", "description": "Country name of the reporter (response only)." }
}
}
Work with this as data
Every JSON Schema here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for schemas
4 MCP tools reach this
find_json_schemasBrowse and filter every JSON Schema in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This JSON Schema
curl "https://apis.io/api/v1/json-schemas/abuseipdb-report"
All schemas
curl "https://apis.io/api/v1/json-schemas?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.