Docs / API reference
IP Reputation
Returns only the threat indicators for an IP address: proxy, VPN, Tor, bot, relay, hosting and blacklist status.
Overview#
lookup/ip/threats is the lightweight way to ask "is this address risky?". Unlike IP Lookup it skips geography, timezone and currency and returns just the ip and a threats object. That makes responses small and fast, which suits checks in the hot path of a login or checkout.
When to use it#
- A quick pass/fail screen before creating an account or starting a payment.
- Decisions that only depend on anonymization and automation signals.
- High-volume pipelines where location data is unnecessary.
Reading the result#
threats.isProxyindicates anonymizing infrastructure andthreats.proxyTypenames the kind. Many legitimate users use VPNs, so prefer a step-up check (a one-time code, for example) over an outright block.threats.isHostingsuggests the traffic comes from a data center rather than a person. Together withthreats.isBotit is a good reason to challenge or deny.threats.isTormarks exit nodes of the Tor network;threats.isRelaymarks privacy relays, which are usually benign but hide the real location.threats.blacklistedis true when the address matches your own blacklists, andthreats.custom_rules_appliedlists the custom rules that fired.
A practical policy: allow when everything is false, step up when only isProxy or isRelay is true, and block or review when isTor, isBot or isHosting is combined with another risk signal.
Notes#
- Counts as one request. Test mode returns fake data, is free and raises no events.
- Included in every plan.
- Custom rules in the IP reputation group can test the proxy type, each flag and the country, and can blacklist or whitelist the address.
- A
suspicious_ipevent is raised when the risk reaches 50 out of 100 and goes to your webhooks. - A missing or invalid address returns error 112 (
invalid_ip) with HTTP 200.
Request#
https://gurdx.cretip.com/api/lookup/ip/threats
- Authenticate with the key parameter or an Authorization: Bearer header.
- Counts as 1 request.
- Available on: Free trial Standard Premium Pay-as-you-go
Parameters#
| Name | Type | Description |
|---|---|---|
ip
required
query |
string |
The ip parameter is used to specify the IP address you want to retrieve it's threat intelligence information. Expected values: an IP address (IPv4 or IPv6) Sample value: 1.1.1.1
|
Every method also accepts format, lang, mode, userID, callback. See Options.
Code samples#
curl -G "https://gurdx.cretip.com/api/lookup/ip/threats" \
--data-urlencode "key=YOUR_API_KEY" \
--data-urlencode "ip=1.1.1.1"
<?php
$response = file_get_contents('https://gurdx.cretip.com/api/lookup/ip/threats?'.http_build_query(['key' => 'YOUR_API_KEY', 'ip' => '1.1.1.1']));
$result = json_decode($response, true);
if ($result['status'] === 'success') {
print_r($result['data']);
} else {
echo $result['code'].': '.$result['description'];
}
const params = new URLSearchParams({"key":"YOUR_API_KEY","ip":"1.1.1.1"});
const res = await fetch(`https://gurdx.cretip.com/api/lookup/ip/threats?${params}`);
const result = await res.json();
if (result.status === 'success') {
console.log(result.data);
} else {
console.error(result.code, result.description);
}
import requests
res = requests.get("https://gurdx.cretip.com/api/lookup/ip/threats", params={"key": "YOUR_API_KEY", "ip": "1.1.1.1"})
result = res.json()
if result["status"] == "success":
print(result["data"])
else:
print(result["code"], result["description"])
Response#
Success#
{
"status": "success",
"data": {
"ip": "12.12.12.12",
"threats": {
"isProxy": true,
"proxyType": "Socks",
"isTor": false,
"isBot": false,
"isRelay": false,
"isHosting": true,
"blacklisted": false
},
"custom_rules_applied": {
"total": 0,
"rules": []
}
},
"executionTime": 90
}Error#
Errors are delivered with HTTP 200 — always check the status field.
{
"status": "error",
"code": 101,
"type": "invalid_key",
"description": "The API Key is missing or invalid."
}Response fields#
| Name | Type | Description |
|---|---|---|
data.ip |
string |
IP address you're looking up. |
data.threats.isProxy |
boolean |
Indicates if the IP address is a proxy service. |
data.threats.proxyType |
string |
Type of proxy used. |
data.threats.isTor |
boolean |
Indicates if accessed through Tor network. |
data.threats.isBot |
boolean |
Indicates if the user is a bot. |
data.threats.isRelay |
boolean |
Indicates if it's a Apple's Private Relay connection. |
data.threats.isHosting |
boolean |
Indicates if the IP address belong to a hosting provider. |
data.threats.blacklisted |
boolean |
Indicates if the IP address is blacklisted due to applying custom rules or were found in one of your blacklists. |
data.threats.custom_rules_applied.total |
integer |
The total number of custom rules applied to this request. |
data.threats.custom_rules_applied.rules.id |
string |
The rule ID as shown in the dashboard (e.g: CR104).
|
data.threats.custom_rules_applied.rules.title |
string |
The rule title you set when creating the rule. |
data.threats.custom_rules_applied.rules |
object |
The custom rules applied to this request, learn more. |
data.threats.custom_rules_applied |
object |
The custom rules applied to this request, learn more. |
data.threats |
object |
— |
data.status |
string |
Response status (success/error). |
data.executionTime |
integer |
Time taken to process the data (in milliseconds). |
data |
object |
— |
Found a mistake? Tell us on the contact page. Contact