Guides

View as markdown

Turn IP intelligence into decisions with practical guides for your application.

From a lookup to a decision

Start with the IP API response fields so you can distinguish network ownership from observed behavior. A residential network classification describes the network; provider attribution and anonymization categories describe additional observations about the address. These fields should not be treated as interchangeable.

The risk scoring guide explains the signals behind the score and the limits of reducing them to one number. Use that score alongside evidence from your own application, such as the action being attempted and the session's behavior. Define a review, challenge, or blocking policy appropriate to that action, then evaluate it against legitimate traffic as well as known abuse.

Keep decisions tied to evidence

Read the methodology for coverage considerations, including the changing nature of proxy addresses. An observation is context for an investigation, not a permanent description of every user who shares an address. Keep timestamps with the evidence your system consumes and decide when it should expire.

Use service tags when provider identity matters to a rule. If you need fresh events or bulk analysis, compare Firehose and Feeds. Before rollout, follow the errors reference so an unavailable lookup is handled separately from a response with no observed signals.