IPAbuse Developers

Authentication

The IPAbuse API supports two authentication methods depending on what you are building.

API Key (recommended for server-side integrations)

Pass your key in the X-API-Keyrequest header. API keys are scoped to your account and subject to your plan's rate limits.

cURL
curl https://api.ipabuse.org/v1/ip/1.2.3.4/reputation \
  -H "X-API-Key: YOUR_API_KEY"
Node.js
// Store securely — never expose in client-side code
const IPABUSE_API_KEY = process.env.IPABUSE_API_KEY;

const res = await fetch("https://api.ipabuse.org/v1/ip/8.8.8.8/reputation", {
  headers: { "X-API-Key": IPABUSE_API_KEY },
});
Security note: Never expose your API key in client-side JavaScript, public repos, or browser network requests. Always call the API from your backend or a Next.js server action / route handler.

Manage keys

Create, rotate, or revoke keys at ipabuse.org/settings. Each key can have a name, expiry, and IP allowlist.

JWT Bearer Token (for user-scoped operations)

Operations that require a specific user identity (submitting reports, managing billing, accessing team data) require a JWT obtained by logging in.

1. Obtain a token

cURL
curl -X POST https://api.ipabuse.org/v1/auth/login \
  -H "Content-Type: application/json" \
  -d '{"email":"you@example.com","password":"secret"}'

On success, the response sets an HttpOnly cookie named token and also returns it in the JSON body as data.token.

2. Use the token

cURL
curl https://api.ipabuse.org/v1/billing/subscription \
  -H "Authorization: Bearer eyJhbGci..."

Token lifetime

Tokens expire after 7 days by default. Refresh by logging in again, or call POST /v1/auth/refresh within the expiry window.

Summary

MethodHeaderUse case
API KeyX-API-Key: sk_...IP lookups, blocklists, plugin calls
JWTAuthorization: Bearer ey...Reporting, billing, team, profile

Next steps