01
Submit a Report
POST /api/v1/abuse/report
Content-Type: application/json
X-Report-Token: ar_YOURTOKEN (optional, no auth required)
{
"ip": "203.0.113.7",
"service": "ssh",
"port": 22,
"count": 5
}
Services
ssh, imap, pop3, smtp-auth, http, ddos, ftp, sip, sqli, webmin, botnet, portscan
Response
{
"success": true,
"deduped": false,
"ip": "203.0.113.7",
"service": "ssh",
"category": "abuse",
"score": 23,
"listingState": "watchlist",
"confidenceLevel": "medium"
}
Rules: public IPs only, 120 reports / 5 min per source IP, deduplication within 10 minutes, whitelist support.
02
Report Tokens & Statistics
Create a token (account required)
POST /api/v1/abuse/tokens
Content-Type: application/json
{ "label": "mail-01.example.com" } (optional)
Response:
{ "success": true, "token": "ar_abc123...", "statsUrl": "/api/v1/abuse/tokens/ar_abc123..." }
Token statistics
GET /api/v1/abuse/tokens/{token}
Response:
{
"success": true,
"metrics": {
"totalReports": 128,
"last7d": 42,
"currentlyListedFromMyReports": 3,
"byService": [{ "service": "ssh", "count": 96 }]
}
}
Public endpoints
| Method | Endpoint | Description |
|---|---|---|
GET | /api/v1/abuse/check?ip=.. | Check an IP with anonymized evidence |
GET | /api/v1/abuse/stats | Public aggregate network statistics |
GET | /api/v1/abuse/fail2ban-config | fail2ban action file download |