Angriffsabwehr4 min read4 sections

Reporting API & tokens

POST /api/v1/abuse/report - report attacks from any system. Tokens for personal statistics and reporter reputation. Plus check, stats and export endpoints.

01

Report an attack

POST https://reports.provider.tools/api/v1/abuse/report
Content-Type: application/json
X-Report-Token: ar_YOURTOKEN   (optional)

{ "ip": "203.0.113.7", "service": "ssh", "port": 22, "count": 5 }

Supported services (100+): server access (ssh, rdp, vpn...), mail (imap, smtp-auth...), databases (mysql, postgresql...), web attacks (http, sqli, xss...), DDoS, malware/botnet, game servers and more. Full machine-readable list: GET /api/v1/abuse/report

02

Report tokens

Tokens are created in the Reporting page (free account, one per server) or via API:

POST https://reports.provider.tools/api/v1/abuse/tokens          (account auth required)
{ "label": "mail-01" }

GET https://reports.provider.tools/api/v1/abuse/tokens/{token}   (your token's statistics)

Send the token as X-Report-Token header with every report. Anonymous reports (no token) count exactly the same for listing.

03

Rules

  • Only public IP addresses are accepted (private/reserved ranges are rejected).
  • Rate limit: 120 reports per 5 minutes per source IP.
  • Deduplication: identical (IP, service) reports within 10 minutes are not counted twice.
  • Whitelisted IPs are ignored.
04

Other endpoints

MethodEndpointDescription
GET/api/v1/abuse/check?ip=..Check an IP with anonymized evidence (JSON)
GET/api/v1/abuse/exportPlain-text list of all listed IPs, optional ?service= / ?format=json
GET/api/v1/abuse/statsPublic aggregate network statistics
GET/api/v1/abuse/fail2ban-installInstaller script (?block=0, ?token=, ?block_service=)
GET/api/v1/abuse/fail2ban-configfail2ban action file / jail examples download