x402 List

x402 Protocol Service Directory

IPIntel.ai IP Lookup & Risk API

Data PAYMENT-READY imported

payment-ready until 2026-08-20

imported from the x402 Bazaar, not submitted by the operator · own this service? claim it · or ask to be removed

Pay-per-call IP intelligence API. Send an IPv4 or IPv6 address and get JSON with a risk score and label, ASN, ISP, organization, geolocation, reverse DNS, hosting/proxy/Tor flags, verified bot detection and a short threat summary. Priced at $0.001 per call in USDC on Base.

Pay from $0.001 per request in USDC on Base, settled onchain via the x402 protocol, no signup, no API key needed.

first settlement 2026-06-21 · $1.06 all-time · settled via coinbase

BASE URL https://api.ipintel.ai ENDPOINTS 1 NETWORK Base ASSET USDC MEMBER SINCE 2026-07-20 MONITORED SINCE 2026-07-20

ASSESSMENT

updated 3h ago

Evidence-backed signals, not a single score. Click any chip for the proof. Measured values stay read-only; unknown is honest.

reliability 100%
uptime 24h
100%
uptime 7d
100%
uptime 30d
100%
uptime 90d
100%
response p95
1635ms
avg response
1017ms
total checks
2,135

Measured on the unpaid 402 handshake, not the paid call. A service can 402 correctly and still fail after payment.

compliance A (14/14)

14 of 14 x402 conformance checks pass. Full checklist below.

jump to compliance checklist

price $0.001 (p9 in Data)
price (min)
$0.001
category percentile (min)
p9 in Data
endpoints / prices
1 / 1
model
flat
stability
100%
risk clean

No deterministic risk flag. Risk fires only on an exact blocklist match, or a reserved-brand name with a mismatched verified payTo. Never from low uptime, a high price, or a model guess.

domain age
-
registrar
-
hosting
custom
domain created
---

Identity facts, not a risk score.

traction $0.0706666667 30d · 25 buyers
volume 30d
$0.0706666667
buyers 30d
25
settlements 30d
51
first settlement
2026-06-21
last settlement
2026-08-13
top buyer share
38% of 30d volume
trend 7d vs 30d
0.55x the 30d daily rate
networks
eip155:8453
volume all-time
$1.06
settlements all-time
371
median settlement 30d
$0.002
max settlement 30d
$0.025
settled via
coinbase ($0.21, 51 tx)

Attributed pro-quota: this payout address is shared, so volume is the operator-level figure divided by the services sharing it, while buyer and transaction counts stay whole. A declared convention, not an individually observed measure, and still a conservative undercount.

Currently sharing this payout address with IPIntel.ai Satellite & GeoRisk API, IPIntel.ai x402 Tools.

Top buyer share is a concentration signal, not part of the ranking score.

WHAT IT DOES

ai-derived

Provides IP address lookup and risk assessment services

category
ip-intelligence
in
body
auth
api key
ip-lookuprisk-assessmentsecurity

AI-generated summary. The measured data is never altered by it.

ENDPOINTS

Service endpoints with HTTP method, path, description, pricing, and network
METHOD PATH DESCRIPTION PRICE NETWORK ASSET 402 CHANNEL
POST /x402v2 $0.001 Base USDC header
1 endpoints

REQUEST / RESPONSE EXAMPLE

An unpaid request to POST /x402v2 returns HTTP 402 with the payment terms. Settle onchain via your facilitator, then retry with the X-Payment header.

// request
curl -i -X POST 'https://api.ipintel.ai/x402v2'
// 402 response (captured by monitor) · 1 payload · click to expand
[
  {
    "error": "Payment required",
    "accepts": [
      {
        "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
        "extra": {
          "name": "USD Coin",
          "version": "2"
        },
        "payTo": "0x0550779CFBc832657A8BB46BAC9f359A5ad038B8",
        "amount": "1000",
        "scheme": "exact",
        "network": "eip155:8453",
        "maxTimeoutSeconds": 300
      }
    ],
    "resource": {
      "url": "https://api.ipintel.ai/x402v2",
      "tags": [
        "ip-lookup",
        "ip-intelligence",
        "ip-risk-score",
        "geolocation",
        "proxy-vpn-tor"
      ],
      "iconUrl": "https://api.ipintel.ai/favicon.ico",
      "mimeType": "application/json",
      "description": "Pay-per-call IP lookup and risk intelligence API. Send an IPv4 or IPv6 address and receive JSON with risk score, risk label, ASN, ISP, organization, geolocation, reverse DNS, hosting/proxy/VPN/Tor signals, verified bot detection, scanner/honeypot indicators, and AI-powered subnet behavior analysis via x402 v2 on Base.",
      "serviceName": "IPIntel.ai IP Lookup & Risk API"
    },
    "extensions": {
      "bazaar": {
        "info": {
          "input": {
            "body": {
              "ip": "8.8.8.8"
            },
            "type": "http",
            "method": "POST",
            "bodyType": "json"
          },
          "output": {
            "type": "json",
            "example": {
              "ip": "8.8.8.8",
              "asn": "AS15169",
              "isp": "Google LLC",
              "org": "Google Public DNS",
              "city": "Ashburn",
              "is_tor": false,
              "country": "US",
              "is_proxy": false,
              "confidence": 100,
              "is_hosting": true,
              "risk_label": "Safe",
              "risk_score": 15,
              "reverse_dns": "dns.google",
              "threat_summary": "This IP is considered safe and does not pose a threat. Only minimal and non-threatening activity has been observed.",
              "is_verified_bot": false
            }
          }
        },
        "schema": {
          "type": "object",
          "$schema": "https://json-schema.org/draft/2020-12/schema",
          "required": [
            "input"
          ],
          "properties": {
            "input": {
              "type": "object",
              "required": [
                "type",
                "method",
                "bodyType",
                "body"
              ],
              "properties": {
                "body": {
                  "type": "object",
                  "required": [
                    "ip"
                  ],
                  "properties": {
                    "ip": {
                      "type": "string",
                      "description": "IPv4 or IPv6 address to analyze, passed in the JSON request body"
                    }
                  },
                  "additionalProperties": false
                },
                "type": {
                  "type": "string",
                  "const": "http"
                },
                "method": {
                  "enum": [
                    "POST"
                  ],
                  "type": "string"
                },
                "bodyType": {
                  "enum": [
                    "json",
                    "form-data",
                    "text"
                  ],
                  "type": "string"
                }
              },
              "additionalProperties": false
            },
            "output": {
              "type": "object",
              "required": [
                "type"
              ],
              "properties": {
                "type": {
                  "type": "string"
                },
                "example": {
                  "type": "object",
                  "properties": {
                    "ip": {
                      "type": "string",
                      "description": "Queried IPv4 or IPv6 address"
                    },
                    "asn": {
                      "type": "string",
                      "description": "Autonomous system number"
                    },
                    "isp": {
                      "type": "string",
                      "description": "Internet service provider"
                    },
                    "org": {
                      "type": "string",
                      "description": "Organization name"
                    },
                    "city": {
                      "type": "string",
                      "description": "City, when available"
                    },
                    "is_tor": {
                      "type": "boolean",
                      "description": "Whether the IP appears to be a Tor exit node"
                    },
                    "country": {
                      "type": "string",
                      "description": "Country code or country name"
                    },
                    "is_proxy": {
                      "type": "boolean",
                      "description": "Whether the IP appears to be a proxy"
                    },
                    "confidence": {
                      "type": "number",
                      "description": "Confidence percentage from 0 to 100"
                    },
                    "is_hosting": {
                      "type": "boolean",
                      "description": "Whether the IP appears to belong to hosting/cloud infrastructure"
                    },
                    "risk_label": {
                      "type": "string",
                      "description": "Human-readable risk label"
                    },
                    "risk_score": {
                      "type": "number",
                      "description": "Risk score from 0 to 100"
                    },
                    "reverse_dns": {
                      "type": "string",
                      "description": "Reverse DNS hostname, when available"
                    },
                    "threat_summary": {
                      "type": "string",
                      "description": "Short natural-language threat assessment"
                    },
                    "is_verified_bot": {
                      "type": "boolean",
                      "description": "Whether the IP appears to be a verified known bot"
                    }
                  },
                  "additionalProperties": true
                }
              }
            }
          }
        }
      }
    },
    "x402Version": 2
  }
]

OVER TIME

All charts use the 30d selector; each series spans only the dates it has data for. Every series is also served as JSON at /api/v1/services/ipintel-ai-ip-lookup-risk-api/price, /scores, /volume and /buyers. On-chain volume and distinct buyers are measured over the service's settlement address and are a conservative undercount (only settlements that reach a measured facilitator are counted). The on-chain series roll up hourly, so the latest day can be up to about an hour behind; distinct buyers are counted per payout address, so a service that settles to more than one address is an upper bound.

UPTIME
07-20 · uptime 100.0% · 809ms avg07-21 · uptime 100.0% · 889ms avg07-22 · uptime 100.0% · 790ms avg07-23 · uptime 100.0% · 822ms avg07-24 · uptime 100.0% · 775ms avg07-25 · uptime 100.0% · 805ms avg07-26 · uptime 100.0% · 974ms avg07-27 · uptime 100.0% · 722ms avg07-28 · uptime 100.0% · 922ms avg07-29 · uptime 100.0% · 1118ms avg07-30 · uptime 100.0% · 1155ms avg07-31 · uptime 100.0% · 1116ms avg08-01 · uptime 100.0% · 1204ms avg08-02 · uptime 100.0% · 978ms avg08-03 · uptime 100.0% · 1049ms avg08-04 · uptime 100.0% · 1180ms avg08-05 · uptime 100.0% · 1329ms avg08-06 · uptime 100.0% · 1332ms avg08-07 · uptime 100.0% · 1284ms avg08-08 · uptime 100.0% · 1099ms avg08-09 · uptime 100.0% · 1049ms avg08-10 · uptime 100.0% · 976ms avg08-11 · uptime 100.0% · 1045ms avg08-12 · uptime 100.0% · 843ms avg08-13 · uptime 100.0% · 959ms avg07-2008-13
30d UPTIME 100%
RESPONSE TIME
07-20 · 809ms avg07-20 · 809ms avg07-21 · 889ms avg07-21 · 889ms avg07-22 · 790ms avg07-22 · 790ms avg07-23 · 822ms avg07-23 · 822ms avg07-24 · 775ms avg07-24 · 775ms avg07-25 · 805ms avg07-25 · 805ms avg07-26 · 974ms avg07-26 · 974ms avg07-27 · 722ms avg07-27 · 722ms avg07-28 · 922ms avg07-28 · 922ms avg07-29 · 1118ms avg07-29 · 1118ms avg07-30 · 1155ms avg07-30 · 1155ms avg07-31 · 1116ms avg07-31 · 1116ms avg08-01 · 1204ms avg08-01 · 1204ms avg08-02 · 978ms avg08-02 · 978ms avg08-03 · 1049ms avg08-03 · 1049ms avg08-04 · 1180ms avg08-04 · 1180ms avg08-05 · 1329ms avg08-05 · 1329ms avg08-06 · 1332ms avg08-06 · 1332ms avg08-07 · 1284ms avg08-07 · 1284ms avg08-08 · 1099ms avg08-08 · 1099ms avg08-09 · 1049ms avg08-09 · 1049ms avg08-10 · 976ms avg08-10 · 976ms avg08-11 · 1045ms avg08-11 · 1045ms avg08-12 · 843ms avg08-12 · 843ms avg08-13 · 959ms avg08-13 · 959ms avg07-2008-13
AVG RESP 1017ms
PRICE (captured 402, USD)
07-20 · $0.00108-13 · $0.001$0.00107-2008-13
SUB-SCORES (uptime + x402 compliance)
07-20 compliance: 100% checks07-21 uptime: 100.0% compliance: 100% checks07-22 uptime: 100.0% compliance: 100% checks07-23 uptime: 100.0% compliance: 100% checks07-24 uptime: 100.0% compliance: 100% checks07-25 uptime: 100.0% compliance: 100% checks07-26 uptime: 100.0% compliance: 100% checks07-27 uptime: 100.0% compliance: 100% checks07-28 uptime: 100.0% compliance: 100% checks07-29 uptime: 100.0% compliance: 100% checks07-30 uptime: 100.0% compliance: 100% checks07-31 uptime: 100.0% compliance: 100% checks08-01 uptime: 100.0% compliance: 100% checks08-02 uptime: 100.0% compliance: 100% checks08-03 uptime: 100.0% compliance: 100% checks08-04 uptime: 100.0% compliance: 100% checks08-05 uptime: 100.0% compliance: 100% checks08-06 uptime: 100.0% compliance: 100% checks08-07 uptime: 100.0% compliance: 100% checks08-08 uptime: 100.0% compliance: 100% checks08-09 uptime: 100.0% compliance: 100% checks08-10 uptime: 100.0% compliance: 100% checks08-11 uptime: 100.0% compliance: 100% checks08-12 uptime: 100.0% compliance: 100% checks08-13 uptime: 100.0% compliance: 100% checksuptimecompliance07-2008-13

checklist grew 11->14 on 2026-07-28; a step here is a metric change, not a regression

PILLARS OVER TIME (measured)

Measured site and economics pillars from the assessment history, so the latest value shown elsewhere on this page reads as a point on a trend rather than a permanent state.

VOLUME (on-chain settlement, USD)
07-15 · $0.0307-16 · $0.0307-17 · $0.0107-18 · $0.0307-24 · $0.0307-26 · $0.0007-29 · $0.0007-30 · $0.0008-04 · $0.0008-10 · $0.0008-11 · $0.0008-12 · $0.0108-13 · $0.01peak $0.0307-1508-13

Shared payout address (2 other services). These bars are the full shared address (operator-level), so do not sum them across the services that share it. Where a per-service figure is attributed, the assessment block and the ranking, it is the address total divided pro-quota by the 3 services sharing it: a declared convention, not an individually observed measure.

DISTINCT BUYERS
07-15 · 8 buyers07-16 · 2 buyers07-17 · 2 buyers07-18 · 2 buyers07-24 · 2 buyers07-26 · 2 buyers07-29 · 2 buyers07-30 · 2 buyers08-04 · 1 buyer08-10 · 1 buyer08-11 · 1 buyer08-12 · 1 buyer08-13 · 1 buyerpeak 8 buyers07-1508-13

Shared payout address (2 other services). These bars are the full shared address (operator-level), so do not sum them across the services that share it. Per-service buyer and transaction counts are shown whole (integers), not divided; only volume is attributed pro-quota. A declared convention, not an individually observed measure.

COMPLIANCE

14/14 checks pass · grade A

last 402 captured 2026-07-20 · last up 2026-08-13

  • 402 payload captured
  • accepts[] array present
  • payTo address recoverable
  • payTo at accepts[0].payTo (conformant shape)
  • payTo is a valid on-chain address
  • atomic price declared
  • atomic price in a sane range
  • asset (token) address declared
  • network resolves to CAIP-2
  • payment scheme declared
  • served over HTTPS
  • declares the current x402 version (2)
  • EIP-712 domain parameters present on every EVM entry
  • x402 v2 envelope delivered in the payment-required header

SITE PILLARS

  • homepage reachable
  • openapi doc
  • pricing page
  • llms.txt
  • robots.txt
  • terms page
recent checks (18) live · click to expand
TIME STATUS RESP CAUSE
● OK 665ms
● OK 698ms
● OK 982ms
● OK 1167ms
● OK 1436ms
● OK 806ms
● OK 783ms
● OK 1078ms
● OK 589ms
● SLOW 1626ms
● OK 678ms
● OK 1168ms
● OK 997ms
● OK 1100ms
● OK 1086ms
● OK 902ms
● SLOW 1536ms
● OK 1465ms

EMBED THIS BADGE

Show that IPIntel.ai IP Lookup & Risk API is monitored on x402-list. Paste this on your site or README, it links back to this live listing.

IPIntel.ai IP Lookup & Risk API listed on x402-list
status
IPIntel.ai IP Lookup & Risk API uptime on x402-list
live uptime
// HTML
<a href="https://x402-list.com/services/ipintel-ai-ip-lookup-risk-api?utm_source=badge&utm_medium=referral&utm_campaign=embed">
  <img src="https://x402-list.com/badge/ipintel-ai-ip-lookup-risk-api.svg" alt="IPIntel.ai IP Lookup & Risk API listed on x402-list" height="28">
</a>
// Markdown
[![IPIntel.ai IP Lookup & Risk API on x402-list](https://x402-list.com/badge/ipintel-ai-ip-lookup-risk-api.svg)](https://x402-list.com/services/ipintel-ai-ip-lookup-risk-api?utm_source=badge&utm_medium=referral&utm_campaign=embed)
// HTML · live uptime variant
<a href="https://x402-list.com/services/ipintel-ai-ip-lookup-risk-api?utm_source=badge&utm_medium=referral&utm_campaign=embed">
  <img src="https://x402-list.com/badge/ipintel-ai-ip-lookup-risk-api.svg?data=uptime" alt="IPIntel.ai IP Lookup & Risk API uptime on x402-list" height="28">
</a>

RUN THIS SERVICE?

Keep this listing accurate: propose changes to the name, description, website, category or add new endpoints to monitor. Ownership is verified with a domain proof and every change is reviewed manually; measured data stays read-only.

[ update this listing ]

Earn the verified tier: x402list pays a real call to this endpoint and, if it delivers, the service is delivery-verified. The fee covers the cost of the probe, not the badge; there is no refund if the call does not deliver. Agent and API only, no in-browser signing. See /api.

[ verify this service ($0.25) ]

To request delisting, email info@x402-list.com or update your listing at /services/ipintel-ai-ip-lookup-risk-api/update.