IP Risk That Expires: Trying IP99's Free No-Key Lookup API
Most IP intelligence products hand you a durable label: proxy , VPN , datacenter — as if that fact stays true for weeks. In fraud and abuse work, that assumption is often wrong. An address that was a dial-up egress this morning may be a quiet residential NAT by evening. What you need at decision time is not a permanent brand, but a verifiable, time-aware verdict . IP99 (ThreatHunter) exposes that…
IP99's free API offers a way to assess IP addresses' risk levels in real-time. Unlike traditional IP intelligence products that provide broad categories like proxy, VPN, or datacenter, IP99's verifiable risk score accounts for the actual risk level based on fresh evidence. This score decays over time, ensuring that outdated information does not mislead decision-making.
The API returns a JSON response containing various fields such as the IP address, timestamp of computation, evidence state, risk score, network details, and geographical information. An example response shows an IP address with a score of 0, meaning there is no current verifiable evidence, and therefore, it should not be considered safe.
Teams often misunderstand the meaning of the risk.score field, which is not a measure of the probability of an attacker but rather a reflection of the freshness and strength of the verifiable evidence. The risk.level is derived from the score and categorizes it as none, low, medium, or high.
Before making decisions based solely on a zero score, it is crucial to examine the evidence_state, which indicates whether the evidence is active, stale, or absent. A zero score does not guarantee safety; it merely signifies that no fresh evidence is available. Teams should prioritize checking the evidence_state before considering the risk.score.
In addition to the risk.score, the risk.signals field provides insights into the specific reasons behind the score. These signals can include proxy usage, dial-up pools, or cloud phone services, each requiring distinct handling strategies. Other signals like osint, cloud_service, and benign tags like crawler are also available for policy creation.
When using IP99's API, anonymous calls are limited to a daily allowance. If the need arises to exceed this limit, signing up for a key is necessary. The API documentation, including field definitions, error codes, and an OpenAPI specification, is accessible at ip99.com/api.
For organizations implementing risk assessments, IP99's API can be used alongside other services like Pulse, which offers a more comprehensive risk evaluation with additional features like historical data access and tiered access levels. However, it is important to remember that IP99's API does not detect Tor exit nodes and should not be relied upon for such detection.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.