x402 List

x402 Protocol Service Directory

IPIntel.ai IP Lookup & Risk API

Data PAYMENT-READY imported

payment-ready until 2026-08-20

imported from the x402 Bazaar, not submitted by the operator · own this service? claim it · or ask to be removed

Pay-per-call IP intelligence API. Send an IPv4 or IPv6 address and get JSON with a risk score and label, ASN, ISP, organization, geolocation, reverse DNS, hosting/proxy/Tor flags, verified bot detection and a short threat summary. Priced at $0.001 per call in USDC on Base.

Pay from $0.001 per request in USDC on Base, settled onchain via the x402 protocol, no signup, no API key needed.

first settlement 2026-06-21 · $1.06 all-time · settled via coinbase

BASE URL https://api.ipintel.ai ENDPOINTS 1 NETWORK Base ASSET USDC MEMBER SINCE 2026-07-20 MONITORED SINCE 2026-07-20

ASSESSMENT

updated 4h ago

Evidence-backed signals, not a single score. Click any chip for the proof. Measured values stay read-only; unknown is honest.

reliability 100%
uptime 24h
100%
uptime 7d
100%
uptime 30d
100%
uptime 90d
100%
response p95
1635ms
avg response
1017ms
total checks
2,135

Measured on the unpaid 402 handshake, not the paid call. A service can 402 correctly and still fail after payment.

compliance A (14/14)

14 of 14 x402 conformance checks pass. Full checklist below.

jump to compliance checklist

price $0.001 (p9 in Data)
price (min)
$0.001
category percentile (min)
p9 in Data
endpoints / prices
1 / 1
model
flat
stability
100%
risk clean

No deterministic risk flag. Risk fires only on an exact blocklist match, or a reserved-brand name with a mismatched verified payTo. Never from low uptime, a high price, or a model guess.

domain age
-
registrar
-
hosting
custom
domain created
---

Identity facts, not a risk score.

traction $0.0706666667 30d · 25 buyers
volume 30d
$0.0706666667
buyers 30d
25
settlements 30d
51
first settlement
2026-06-21
last settlement
2026-08-13
top buyer share
38% of 30d volume
trend 7d vs 30d
0.55x the 30d daily rate
networks
eip155:8453
volume all-time
$1.06
settlements all-time
371
median settlement 30d
$0.002
max settlement 30d
$0.025
settled via
coinbase ($0.21, 51 tx)

Attributed pro-quota: this payout address is shared, so volume is the operator-level figure divided by the services sharing it, while buyer and transaction counts stay whole. A declared convention, not an individually observed measure, and still a conservative undercount.

Currently sharing this payout address with IPIntel.ai Satellite & GeoRisk API, IPIntel.ai x402 Tools.

Top buyer share is a concentration signal, not part of the ranking score.

WHAT IT DOES

ai-derived

Provides IP address lookup and risk assessment services

category
ip-intelligence
in
body
auth
api key
ip-lookuprisk-assessmentsecurity

AI-generated summary. The measured data is never altered by it.

ENDPOINTS

Service endpoints with HTTP method, path, description, pricing, and network
METHOD PATH DESCRIPTION PRICE NETWORK ASSET 402 CHANNEL
POST /x402v2 $0.001 Base USDC header
1 endpoints

REQUEST / RESPONSE EXAMPLE

An unpaid request to POST /x402v2 returns HTTP 402 with the payment terms. Settle onchain via your facilitator, then retry with the X-Payment header.

// request
curl -i -X POST 'https://api.ipintel.ai/x402v2'
// 402 response (captured by monitor) · 1 payload · click to expand
[
  {
    "error": "Payment required",
    "accepts": [
      {
        "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
        "extra": {
          "name": "USD Coin",
          "version": "2"
        },
        "payTo": "0x0550779CFBc832657A8BB46BAC9f359A5ad038B8",
        "amount": "1000",
        "scheme": "exact",
        "network": "eip155:8453",
        "maxTimeoutSeconds": 300
      }
    ],
    "resource": {
      "url": "https://api.ipintel.ai/x402v2",
      "tags": [
        "ip-lookup",
        "ip-intelligence",
        "ip-risk-score",
        "geolocation",
        "proxy-vpn-tor"
      ],
      "iconUrl": "https://api.ipintel.ai/favicon.ico",
      "mimeType": "application/json",
      "description": "Pay-per-call IP lookup and risk intelligence API. Send an IPv4 or IPv6 address and receive JSON with risk score, risk label, ASN, ISP, organization, geolocation, reverse DNS, hosting/proxy/VPN/Tor signals, verified bot detection, scanner/honeypot indicators, and AI-powered subnet behavior analysis via x402 v2 on Base.",
      "serviceName": "IPIntel.ai IP Lookup & Risk API"
    },
    "extensions": {
      "bazaar": {
        "info": {
          "input": {
            "body": {
              "ip": "8.8.8.8"
            },
            "type": "http",
            "method": "POST",
            "bodyType": "json"
          },
          "output": {
            "type": "json",
            "example": {
              "ip": "8.8.8.8",
              "asn": "AS15169",
              "isp": "Google LLC",
              "org": "Google Public DNS",
              "city": "Ashburn",
              "is_tor": false,
              "country": "US",
              "is_proxy": false,
              "confidence": 100,
              "is_hosting": true,
              "risk_label": "Safe",
              "risk_score": 15,
              "reverse_dns": "dns.google",
              "threat_summary": "This IP is considered safe and does not pose a threat. Only minimal and non-threatening activity has been observed.",
              "is_verified_bot": false
            }
          }
        },
        "schema": {
          "type": "object",
          "$schema": "https://json-schema.org/draft/2020-12/schema",
          "required": [
            "input"
          ],
          "properties": {
            "input": {
              "type": "object",
              "required": [
                "type",
                "method",
                "bodyType",
                "body"
              ],
              "properties": {
                "body": {
                  "type": "object",
                  "required": [
                    "ip"
                  ],
                  "properties": {
                    "ip": {
                      "type": "string",
                      "description": "IPv4 or IPv6 address to analyze, passed in the JSON request body"
                    }
                  },
                  "additionalProperties": false
                },
                "type": {
                  "type": "string",
                  "const": "http"
                },
                "method": {
                  "enum": [
                    "POST"
                  ],
                  "type": "string"
                },
                "bodyType": {
                  "enum": [
                    "json",
                    "form-data",
                    "text"
                  ],
                  "type": "string"
                }
              },
              "additionalProperties": false
            },
            "output": {
              "type": "object",
              "required": [
                "type"
              ],
              "properties": {
                "type": {
                  "type": "string"
                },
                "example": {
                  "type": "object",
                  "properties": {
                    "ip": {
                      "type": "string",
                      "description": "Queried IPv4 or IPv6 address"
                    },
                    "asn": {
                      "type": "string",
                      "description": "Autonomous system number"
                    },
                    "isp": {
                      "type": "string",
                      "description": "Internet service provider"
                    },
                    "org": {
                      "type": "string",
                      "description": "Organization name"
                    },
                    "city": {
                      "type": "string",
                      "description": "City, when available"
                    },
                    "is_tor": {
                      "type": "boolean",
                      "description": "Whether the IP appears to be a Tor exit node"
                    },
                    "country": {
                      "type": "string",
                      "description": "Country code or country name"
                    },
                    "is_proxy": {
                      "type": "boolean",
                      "description": "Whether the IP appears to be a proxy"
                    },
                    "confidence": {
                      "type": "number",
                      "description": "Confidence percentage from 0 to 100"
                    },
                    "is_hosting": {
                      "type": "boolean",
                      "description": "Whether the IP appears to belong to hosting/cloud infrastructure"
                    },
                    "risk_label": {
                      "type": "string",
                      "description": "Human-readable risk label"
                    },
                    "risk_score": {
                      "type": "number",
                      "description": "Risk score from 0 to 100"
                    },
                    "reverse_dns": {
                      "type": "string",
                      "description": "Reverse DNS hostname, when available"
                    },
                    "threat_summary": {
                      "type": "string",
                      "description": "Short natural-language threat assessment"
                    },
                    "is_verified_bot": {
                      "type": "boolean",
                      "description": "Whether the IP appears to be a verified known bot"
                    }
                  },
                  "additionalProperties": true
                }
              }
            }
          }
        }
      }
    },
    "x402Version": 2
  }
]

OVER TIME

All charts use the 24h selector; each series spans only the dates it has data for. Every series is also served as JSON at /api/v1/services/ipintel-ai-ip-lookup-risk-api/price, /scores, /volume and /buyers. On-chain volume and distinct buyers are measured over the service's settlement address and are a conservative undercount (only settlements that reach a measured facilitator are counted). The on-chain series roll up hourly, so the latest day can be up to about an hour behind; distinct buyers are counted per payout address, so a service that settles to more than one address is an upper bound.

UPTIME
08-13 · uptime 100.0% · 962ms avg08-1308-13
24h UPTIME 100%
RESPONSE TIME
08-13 · 962ms avg08-13 · 962ms avg08-1308-13
AVG RESP 1017ms
PRICE (captured 402, USD)
08-12 · $0.00108-13 · $0.001$0.00108-1208-13
SUB-SCORES (uptime + x402 compliance)
08-12 uptime: 100.0% compliance: 100% checks08-13 uptime: 100.0% compliance: 100% checksuptimecompliance08-1208-13

checklist grew 11->14 on 2026-07-28; a step here is a metric change, not a regression

PILLARS OVER TIME (measured)

Measured site and economics pillars from the assessment history, so the latest value shown elsewhere on this page reads as a point on a trend rather than a permanent state.

VOLUME (on-chain settlement, USD)
building volume history (1 day so far)

Shared payout address (2 other services). These bars are the full shared address (operator-level), so do not sum them across the services that share it. Where a per-service figure is attributed, the assessment block and the ranking, it is the address total divided pro-quota by the 3 services sharing it: a declared convention, not an individually observed measure.

DISTINCT BUYERS
building buyer history (1 day so far)

Shared payout address (2 other services). These bars are the full shared address (operator-level), so do not sum them across the services that share it. Per-service buyer and transaction counts are shown whole (integers), not divided; only volume is attributed pro-quota. A declared convention, not an individually observed measure.

COMPLIANCE

14/14 checks pass · grade A

last 402 captured 2026-07-20 · last up 2026-08-13

  • 402 payload captured
  • accepts[] array present
  • payTo address recoverable
  • payTo at accepts[0].payTo (conformant shape)
  • payTo is a valid on-chain address
  • atomic price declared
  • atomic price in a sane range
  • asset (token) address declared
  • network resolves to CAIP-2
  • payment scheme declared
  • served over HTTPS
  • declares the current x402 version (2)
  • EIP-712 domain parameters present on every EVM entry
  • x402 v2 envelope delivered in the payment-required header

SITE PILLARS

  • homepage reachable
  • openapi doc
  • pricing page
  • llms.txt
  • robots.txt
  • terms page
recent checks (18) live · click to expand
TIME STATUS RESP CAUSE
● OK 1135ms
● OK 1338ms
● OK 857ms
● OK 665ms
● OK 698ms
● OK 982ms
● OK 1167ms
● OK 1436ms
● OK 806ms
● OK 783ms
● OK 1078ms
● OK 589ms
● SLOW 1626ms
● OK 678ms
● OK 1168ms
● OK 997ms
● OK 1100ms
● OK 1086ms

EMBED THIS BADGE

Show that IPIntel.ai IP Lookup & Risk API is monitored on x402-list. Paste this on your site or README, it links back to this live listing.

IPIntel.ai IP Lookup & Risk API listed on x402-list
status
IPIntel.ai IP Lookup & Risk API uptime on x402-list
live uptime
// HTML
<a href="https://x402-list.com/services/ipintel-ai-ip-lookup-risk-api?utm_source=badge&utm_medium=referral&utm_campaign=embed">
  <img src="https://x402-list.com/badge/ipintel-ai-ip-lookup-risk-api.svg" alt="IPIntel.ai IP Lookup & Risk API listed on x402-list" height="28">
</a>
// Markdown
[![IPIntel.ai IP Lookup & Risk API on x402-list](https://x402-list.com/badge/ipintel-ai-ip-lookup-risk-api.svg)](https://x402-list.com/services/ipintel-ai-ip-lookup-risk-api?utm_source=badge&utm_medium=referral&utm_campaign=embed)
// HTML · live uptime variant
<a href="https://x402-list.com/services/ipintel-ai-ip-lookup-risk-api?utm_source=badge&utm_medium=referral&utm_campaign=embed">
  <img src="https://x402-list.com/badge/ipintel-ai-ip-lookup-risk-api.svg?data=uptime" alt="IPIntel.ai IP Lookup & Risk API uptime on x402-list" height="28">
</a>

RUN THIS SERVICE?

Keep this listing accurate: propose changes to the name, description, website, category or add new endpoints to monitor. Ownership is verified with a domain proof and every change is reviewed manually; measured data stays read-only.

[ update this listing ]

Earn the verified tier: x402list pays a real call to this endpoint and, if it delivers, the service is delivery-verified. The fee covers the cost of the probe, not the badge; there is no refund if the call does not deliver. Agent and API only, no in-browser signing. See /api.

[ verify this service ($0.25) ]

To request delisting, email info@x402-list.com or update your listing at /services/ipintel-ai-ip-lookup-risk-api/update.