Skip to content
Gurdx

Docs / API reference

IP Reputation

Returns only the threat indicators for an IP address: proxy, VPN, Tor, bot, relay, hosting and blacklist status.

Overview#

lookup/ip/threats is the lightweight way to ask "is this address risky?". Unlike IP Lookup it skips geography, timezone and currency and returns just the ip and a threats object. That makes responses small and fast, which suits checks in the hot path of a login or checkout.

When to use it#

  • A quick pass/fail screen before creating an account or starting a payment.
  • Decisions that only depend on anonymization and automation signals.
  • High-volume pipelines where location data is unnecessary.

Reading the result#

  • threats.isProxy indicates anonymizing infrastructure and threats.proxyType names the kind. Many legitimate users use VPNs, so prefer a step-up check (a one-time code, for example) over an outright block.
  • threats.isHosting suggests the traffic comes from a data center rather than a person. Together with threats.isBot it is a good reason to challenge or deny.
  • threats.isTor marks exit nodes of the Tor network; threats.isRelay marks privacy relays, which are usually benign but hide the real location.
  • threats.blacklisted is true when the address matches your own blacklists, and threats.custom_rules_applied lists the custom rules that fired.

A practical policy: allow when everything is false, step up when only isProxy or isRelay is true, and block or review when isTor, isBot or isHosting is combined with another risk signal.

Notes#

  • Counts as one request. Test mode returns fake data, is free and raises no events.
  • Included in every plan.
  • Custom rules in the IP reputation group can test the proxy type, each flag and the country, and can blacklist or whitelist the address.
  • A suspicious_ip event is raised when the risk reaches 50 out of 100 and goes to your webhooks.
  • A missing or invalid address returns error 112 (invalid_ip) with HTTP 200.

Request#

GET https://gurdx.cretip.com/api/lookup/ip/threats
  • Authenticate with the key parameter or an Authorization: Bearer header.
  • Counts as 1 request.
  • Available on: Free trial Standard Premium Pay-as-you-go

Parameters#

NameTypeDescription
ip
required query
string The ip parameter is used to specify the IP address you want to retrieve it's threat intelligence information. Expected values: an IP address (IPv4 or IPv6) Sample value: 1.1.1.1

Every method also accepts format, lang, mode, userID, callback. See Options.

Code samples#

curl -G "https://gurdx.cretip.com/api/lookup/ip/threats" \
  --data-urlencode "key=YOUR_API_KEY" \
  --data-urlencode "ip=1.1.1.1"

Response#

Success#

{
    "status": "success",
    "data": {
        "ip": "12.12.12.12",
        "threats": {
            "isProxy": true,
            "proxyType": "Socks",
            "isTor": false,
            "isBot": false,
            "isRelay": false,
            "isHosting": true,
            "blacklisted": false
        },
        "custom_rules_applied": {
            "total": 0,
            "rules": []
        }
    },
    "executionTime": 90
}

Error#

Errors are delivered with HTTP 200 — always check the status field.

{
    "status": "error",
    "code": 101,
    "type": "invalid_key",
    "description": "The API Key is missing or invalid."
}

Response fields#

NameTypeDescription
data.ip string IP address you're looking up.
data.threats.isProxy boolean Indicates if the IP address is a proxy service.
data.threats.proxyType string Type of proxy used.
data.threats.isTor boolean Indicates if accessed through Tor network.
data.threats.isBot boolean Indicates if the user is a bot.
data.threats.isRelay boolean Indicates if it's a Apple's Private Relay connection.
data.threats.isHosting boolean Indicates if the IP address belong to a hosting provider.
data.threats.blacklisted boolean Indicates if the IP address is blacklisted due to applying custom rules or were found in one of your blacklists.
data.threats.custom_rules_applied.total integer The total number of custom rules applied to this request.
data.threats.custom_rules_applied.rules.id string The rule ID as shown in the dashboard (e.g: CR104).
data.threats.custom_rules_applied.rules.title string The rule title you set when creating the rule.
data.threats.custom_rules_applied.rules object The custom rules applied to this request, learn more.
data.threats.custom_rules_applied object The custom rules applied to this request, learn more.
data.threats object —
data.status string Response status (success/error).
data.executionTime integer Time taken to process the data (in milliseconds).
data object —

Found a mistake? Tell us on the contact page. Contact