Authentication
The IPAbuse API supports two authentication methods depending on what you are building.
API Key (recommended for server-side integrations)
Pass your key in the X-API-Keyrequest header. API keys are scoped to your account and subject to your plan's rate limits.
cURL
curl https://api.ipabuse.org/v1/ip/1.2.3.4/reputation \
-H "X-API-Key: YOUR_API_KEY"Node.js
// Store securely — never expose in client-side code
const IPABUSE_API_KEY = process.env.IPABUSE_API_KEY;
const res = await fetch("https://api.ipabuse.org/v1/ip/8.8.8.8/reputation", {
headers: { "X-API-Key": IPABUSE_API_KEY },
});Security note: Never expose your API key in client-side JavaScript, public repos, or browser network requests. Always call the API from your backend or a Next.js server action / route handler.
Manage keys
Create, rotate, or revoke keys at ipabuse.org/settings. Each key can have a name, expiry, and IP allowlist.
JWT Bearer Token (for user-scoped operations)
Operations that require a specific user identity (submitting reports, managing billing, accessing team data) require a JWT obtained by logging in.
1. Obtain a token
cURL
curl -X POST https://api.ipabuse.org/v1/auth/login \
-H "Content-Type: application/json" \
-d '{"email":"you@example.com","password":"secret"}'On success, the response sets an HttpOnly cookie named token and also returns it in the JSON body as data.token.
2. Use the token
cURL
curl https://api.ipabuse.org/v1/billing/subscription \
-H "Authorization: Bearer eyJhbGci..."Token lifetime
Tokens expire after 7 days by default. Refresh by logging in again, or call POST /v1/auth/refresh within the expiry window.
Summary
| Method | Header | Use case |
|---|---|---|
| API Key | X-API-Key: sk_... | IP lookups, blocklists, plugin calls |
| JWT | Authorization: Bearer ey... | Reporting, billing, team, profile |
Next steps
- Rate Limits — plan quotas and 429 handling.
- API Reference — try authenticated endpoints live.