{
  "id": 13366513,
  "title": "IP Risk That Expires: Trying IP99's Free No-Key Lookup API",
  "url": "https://urgent.news/2026/10/10/ip-risk-that-expires-trying-ip99s-free-no-key-lookup-api",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-10T08:32:27.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/ip99/ip-risk-that-expires-trying-ip99s-free-no-key-lookup-api-57h3"
  },
  "original_language": "en",
  "account": "IP99's free API offers a way to assess IP addresses' risk levels in real-time. Unlike traditional IP intelligence products that provide broad categories like proxy, VPN, or datacenter, IP99's verifiable risk score accounts for the actual risk level based on fresh evidence. This score decays over time, ensuring that outdated information does not mislead decision-making.\n\nThe API returns a JSON response containing various fields such as the IP address, timestamp of computation, evidence state, risk score, network details, and geographical information. An example response shows an IP address with a score of 0, meaning there is no current verifiable evidence, and therefore, it should not be considered safe.\n\nTeams often misunderstand the meaning of the risk.score field, which is not a measure of the probability of an attacker but rather a reflection of the freshness and strength of the verifiable evidence. The risk.level is derived from the score and categorizes it as none, low, medium, or high.\n\nBefore making decisions based solely on a zero score, it is crucial to examine the evidence_state, which indicates whether the evidence is active, stale, or absent. A zero score does not guarantee safety; it merely signifies that no fresh evidence is available. Teams should prioritize checking the evidence_state before considering the risk.score.\n\nIn addition to the risk.score, the risk.signals field provides insights into the specific reasons behind the score. These signals can include proxy usage, dial-up pools, or cloud phone services, each requiring distinct handling strategies. Other signals like osint, cloud_service, and benign tags like crawler are also available for policy creation.\n\nWhen using IP99's API, anonymous calls are limited to a daily allowance. If the need arises to exceed this limit, signing up for a key is necessary. The API documentation, including field definitions, error codes, and an OpenAPI specification, is accessible at ip99.com/api.\n\nFor organizations implementing risk assessments, IP99's API can be used alongside other services like Pulse, which offers a more comprehensive risk evaluation with additional features like historical data access and tiered access levels. However, it is important to remember that IP99's API does not detect Tor exit nodes and should not be relied upon for such detection.",
  "summary": "Most IP intelligence products hand you a durable label: proxy , VPN , datacenter — as if that fact stays true for weeks. In fraud and abuse work, that assumption is often wrong. An address that was a dial-up egress this morning may be a quiet residential NAT by evening. What you need at decision time is not a permanent brand, but a verifiable, time-aware verdict . IP99 (ThreatHunter) exposes that…",
  "key_points": [
    "IP99's free API assesses IP risk in real-time with a verifiable risk score.",
    "Risk score decays over time to prevent outdated information from misleading decisions."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}