[{"data":1,"prerenderedAt":335},["ShallowReactive",2],{"navLinks":3,"sidebar_docs_navigation_\u002Fthreat-scoring-system":124,"navigation":125,"navLinks_footer":166,"page-\u002Fthreat-scoring-system":196},{"id":4,"extension":5,"links":6,"meta":121,"stem":122,"__hash__":123},"navigationMenu\u002Fnavigation.json","json",[7,57,62,103],{"label":8,"icon":9,"nested":10,"children":11},"API Products","i-lucide-box",true,[12,17,22,27,32,37,42,47,52],{"label":13,"to":14,"description":15,"icon":16},"Full IP Lookup","\u002Ffull-ip-lookup","Enrich any IP with complete intelligence","i-lucide-globe",{"label":18,"to":19,"description":20,"icon":21},"Proxy & VPN Detection","\u002Fproxy-vpn-detection","Identify proxies and VPN networks","i-lucide-shield-alert",{"label":23,"to":24,"description":25,"icon":26},"Tor Exit Nodes","\u002Ftor-exit-nodes","Block Tor anonymity network traffic","i-lucide-eye-off",{"label":28,"to":29,"description":30,"icon":31},"Granular Geolocation","\u002Fgranular-geolocation","Highly accurate location mapping","i-lucide-map-pin",{"label":33,"to":34,"description":35,"icon":36},"Threat Scoring System","\u002Fthreat-scoring-system","Unified traffic risk score","i-lucide-activity",{"label":38,"to":39,"description":40,"icon":41},"ASN & Carrier Data","\u002Fasn-carrier-data","Identify autonomous systems","i-lucide-server",{"label":43,"to":44,"description":45,"icon":46},"Disposable Email Check","\u002Fdisposable-email-check","Detect temporary email domains","i-lucide-mail",{"label":48,"to":49,"description":50,"icon":51},"User Agent Parser","\u002Fuser-agent-bot-parser","Parse messy HTTP headers","i-lucide-bot",{"label":53,"to":54,"description":55,"icon":56},"Verified Bots","\u002Fverified-bots-crawlers","Identify legitimate search engine crawlers","i-lucide-check-circle",{"label":58,"to":59,"icon":60,"nested":61},"Pricing","\u002Fpricing","i-lucide-credit-card",false,{"label":63,"to":64,"icon":65,"nested":10,"children":66},"Docs","\u002Fdocs","i-lucide-book-open",[67,71,76,81,86,91,95,98],{"label":68,"to":64,"description":69,"icon":70},"Getting Started","Learn how to setup and use IP Shield","i-lucide-rocket",{"label":72,"to":73,"description":74,"icon":75},"All Endpoints","\u002Fdocs\u002Fendpoints\u002Femail-domain-check","Reference for all IP Shield REST API endpoints","i-lucide-plug",{"label":77,"to":78,"description":79,"icon":80},"Network API","\u002Fdocs\u002Fendpoints\u002Fnetwork","Network intelligence and routing data","i-lucide-network",{"label":82,"to":83,"description":84,"icon":85},"Summary API","\u002Fdocs\u002Fendpoints\u002Fsummary","Full IP intelligence summary","i-lucide-bar-chart-2",{"label":87,"to":88,"description":89,"icon":90},"Lookup IP API","\u002Fdocs\u002Fendpoints\u002Flookup-ip","Single IP data lookup","i-lucide-search",{"label":92,"to":93,"description":94,"icon":31},"Geo Check API","\u002Fdocs\u002Fendpoints\u002Fgeo-check","Check geographic location",{"label":96,"to":73,"description":97,"icon":46},"Email Domain Check API","Verify disposable email domains",{"label":99,"to":100,"description":101,"icon":102},"User Agent Check API","\u002Fdocs\u002Fendpoints\u002Fuser-agent-check","Detect malicious user agents","i-lucide-monitor",{"label":104,"icon":105,"nested":10,"children":106},"Resources","i-lucide-library",[107,112,117],{"label":108,"to":109,"icon":110,"description":111},"About Us","\u002Fabout","i-lucide-info","Learn more about IP Shield and our mission",{"label":113,"to":114,"icon":115,"description":116},"Blog","\u002Fblog","i-lucide-newspaper","Latest news, updates, and security articles",{"label":118,"to":119,"description":120,"icon":46},"Contact Us","\u002Fcontact","Get in touch with our support team",{},"navigation","OH-Zj4UmYqVQJC8Ts6f4KeKRzXJYi5trdK22JpX9Y0Q",[],[126],{"title":63,"path":64,"stem":127,"children":128},"docs",[129,132,149],{"title":130,"path":64,"stem":131},"Introduction","docs\u002Findex",{"title":133,"path":134,"stem":135,"children":136,"page":61},"Credit & Authorization","\u002Fdocs\u002Fcredits-and-auth","docs\u002Fcredits-and-auth",[137,141,145],{"title":138,"path":139,"stem":140},"Authentication","\u002Fdocs\u002Fcredits-and-auth\u002Fauth","docs\u002Fcredits-and-auth\u002Fauth",{"title":142,"path":143,"stem":144},"Credits & Usage","\u002Fdocs\u002Fcredits-and-auth\u002Fcredits-usage","docs\u002Fcredits-and-auth\u002Fcredits-usage",{"title":146,"path":147,"stem":148},"Rate Limits","\u002Fdocs\u002Fcredits-and-auth\u002Frate-limits","docs\u002Fcredits-and-auth\u002Frate-limits",{"title":150,"path":151,"stem":152,"children":153,"page":61},"API Endpoints","\u002Fdocs\u002Fendpoints","docs\u002Fendpoints",[154,156,158,160,162,164],{"title":96,"path":73,"stem":155},"docs\u002Fendpoints\u002Femail-domain-check",{"title":92,"path":93,"stem":157},"docs\u002Fendpoints\u002Fgeo-check",{"title":87,"path":88,"stem":159},"docs\u002Fendpoints\u002Flookup-ip",{"title":77,"path":78,"stem":161},"docs\u002Fendpoints\u002Fnetwork",{"title":82,"path":83,"stem":163},"docs\u002Fendpoints\u002Fsummary",{"title":99,"path":100,"stem":165},"docs\u002Fendpoints\u002Fuser-agent-check",{"id":4,"extension":5,"links":167,"meta":195,"stem":122,"__hash__":123},[168,179,180,190],{"label":8,"icon":9,"nested":10,"children":169},[170,171,172,173,174,175,176,177,178],{"label":13,"to":14,"description":15,"icon":16},{"label":18,"to":19,"description":20,"icon":21},{"label":23,"to":24,"description":25,"icon":26},{"label":28,"to":29,"description":30,"icon":31},{"label":33,"to":34,"description":35,"icon":36},{"label":38,"to":39,"description":40,"icon":41},{"label":43,"to":44,"description":45,"icon":46},{"label":48,"to":49,"description":50,"icon":51},{"label":53,"to":54,"description":55,"icon":56},{"label":58,"to":59,"icon":60,"nested":61},{"label":63,"to":64,"icon":65,"nested":10,"children":181},[182,183,184,185,186,187,188,189],{"label":68,"to":64,"description":69,"icon":70},{"label":72,"to":73,"description":74,"icon":75},{"label":77,"to":78,"description":79,"icon":80},{"label":82,"to":83,"description":84,"icon":85},{"label":87,"to":88,"description":89,"icon":90},{"label":92,"to":93,"description":94,"icon":31},{"label":96,"to":73,"description":97,"icon":46},{"label":99,"to":100,"description":101,"icon":102},{"label":104,"icon":105,"nested":10,"children":191},[192,193,194],{"label":108,"to":109,"icon":110,"description":111},{"label":113,"to":114,"icon":115,"description":116},{"label":118,"to":119,"description":120,"icon":46},{},{"id":197,"title":33,"body":198,"cta":205,"description":216,"extension":217,"faqs":218,"features":243,"hasMarkDownContent":61,"hero":273,"meta":277,"navigation":10,"path":34,"sections":278,"seo":332,"stem":333,"__hash__":334},"pages\u002Fthreat-scoring-system.md",{"type":199,"value":200,"toc":201},"minimark",[],{"title":202,"searchDepth":203,"depth":203,"links":204},"",2,[],{"title":206,"description":207,"links":208},"Implement Threat Scoring","Get 1,000 free requests per month when you register.",[209],{"label":210,"to":211,"external":10,"target":212,"color":213,"size":214,"icon":215,"trailing":10},"Get API Key","\u002Faccount","_self","primary","lg","i-lucide-arrow-right","Combine multiple vectors into a single risk score to dynamically adjust login friction.","md",[219,223,227,231,235,239],{"label":220,"content":221,"icon":222},"How is the threat score calculated?","The score (0-100) is aggregated using models that evaluate proxy status, historical abuse lists, ASN reputation, Tor node directory presence, and geographic consistency.","i-lucide-calculator",{"label":224,"content":225,"icon":226},"What is considered a high-risk score?","A score above 75 typically indicates a highly suspicious or automated connection. We recommend applying CAPTCHA or MFA challenges to scores in this range, and blocking scores above 90.","i-lucide-alert-triangle",{"label":228,"content":229,"icon":230},"Can I customize the scoring weights?","Currently, the threat scoring engine uses a proprietary weighted algorithm optimized across our global network, but custom enterprise rulesets are coming soon.","i-lucide-sliders",{"label":232,"content":233,"icon":234},"Is a VPN user always assigned a high score?","No. While using an anonymizing VPN increases the baseline risk score, if the IP has no history of abuse, it will typically stay in the low-to-medium range, preventing false positives for privacy-conscious users.","i-lucide-shield-check",{"label":236,"content":237,"icon":238},"Does the summary endpoint return geo data?","The summary endpoint returns the ISO country code. If you need city, region, or coordinates, you should use the Granular Geolocation API or the Full IP Lookup API.","i-lucide-map",{"label":240,"content":241,"icon":242},"How fast does a threat score decay?","Scores are dynamic. As an IP stops exhibiting malicious behavior or is removed from global blocklists, its threat score naturally decays over a period of 7 to 30 days depending on the severity of the past abuse.","i-lucide-trending-down",{"title":244,"description":245,"items":246},"Simplify Your Security Logic","Stop managing complex rulesets and rely on a single, continuously updated metric.",[247,251,254,258,262,265,269],{"title":248,"description":249,"icon":250},"Machine Learning Models","Our scoring algorithms adapt to new attack vectors automatically.","i-lucide-brain",{"title":252,"description":253,"icon":16},"Single API Call","Get the score, ASN classification, and proxy status in one fast request.",{"title":255,"description":256,"icon":257},"Reduce False Positives","Context-aware scoring ensures legitimate privacy tool users aren't incorrectly blocked.","i-lucide-target",{"title":259,"description":260,"icon":261},"Protect APIs","Rate-limit or block high-threat IPs from accessing expensive backend resources.","i-lucide-lock",{"title":263,"description":264,"icon":60},"Fraud Prevention","Flag high-risk transactions for manual review before capturing funds.",{"title":266,"description":267,"icon":268},"Easy Integration","Simply check if `threat_level > 75` to apply your security policies.","i-lucide-code",{"title":270,"description":271,"icon":272},"Real-time Updates","Threat intelligence is updated continuously as new attacks are detected globally.","i-lucide-refresh-cw",{"badge":274,"orientation":275,"json":276},"Security","horizontal","{\n  \"ok\": true,\n  \"date\": \"2025-06-12T00:00:00Z\",\n  \"data\": {\n    \"ip\": \"104.28.12.34\",\n    \"country_code\": \"US\",\n    \"proxy\": true,\n    \"vpn\": false,\n    \"threat_level\": 85,\n    \"is_known_bot\": false,\n    \"is_tor_node\": false,\n    \"classification\": \"hosting\",\n    \"asn_id\": \"13335\"\n  },\n  \"meta\": {\n    \"total_credits\": 10000,\n    \"credits_remaining\": 9999\n  }\n}\n",{},[279,297,315],{"title":280,"description":281,"orientation":275,"image":282,"features":285},"Unified Threat Score","Evaluating individual flags like proxies, VPNs, or Tor nodes can be complex. The Threat Scoring System simplifies this by analyzing multiple threat vectors and returning a unified, actionable risk score from 0 to 100.",{"src":283,"alt":284},"\u002Fproducts\u002Fthreat_score_1781163855831.png","Unified Threat Score Dashboard",[286,289,293],{"title":287,"description":288,"icon":36},"Unified 0-100 Score","Stop guessing with raw data and use a single, reliable metric for access control.",{"title":290,"description":291,"icon":292},"Sub-10ms Latency","Highly optimized rule evaluation happens in milliseconds at the edge.","i-lucide-zap",{"title":294,"description":295,"icon":296},"Comprehensive Context","The summary payload includes all relevant flags like proxy, ASN, and Tor status alongside the score.","i-lucide-braces",{"title":298,"description":299,"orientation":275,"reverse":10,"image":300,"features":303},"Multi-Vector Analysis","A high threat score isn't just about using a proxy. Our algorithms evaluate historical abuse data, routing anomalies, geographical inconsistencies, and known bad-actor infrastructure to compute a highly accurate risk profile.",{"src":301,"alt":302},"\u002Fproducts\u002Fthreat_multivector_abstract.png","Multi-vector analysis abstract visualization",[304,308,312],{"title":305,"description":306,"icon":307},"Historical Abuse Data","Scores are heavily influenced by known spam, DDoS, and hacking blacklist databases.","i-lucide-history",{"title":309,"description":310,"icon":311},"Infrastructure Profiling","Datacenter IPs, bulletproof hosting, and residential proxies receive appropriate risk weights.","i-lucide-server-crash",{"title":313,"description":314,"icon":26},"Anonymity Networks","Commercial VPNs and Tor exit nodes are factored into the baseline risk calculation.",{"title":316,"description":317,"orientation":275,"image":318,"features":321},"Adaptive Friction Rules","Don't block legitimate users. Instead, use the Threat Score to create adaptive user experiences. Streamline login for low-risk traffic, while applying CAPTCHAs, MFA challenges, or manual review queues for high-risk requests.",{"src":319,"alt":320},"\u002Fproducts\u002Fthreat_friction_abstract.png","Adaptive friction rules abstract visualization",[322,325,328],{"title":323,"description":324,"icon":56},"Low Risk (0-20)","Streamline the checkout or login experience to maximize conversion rates.",{"title":326,"description":327,"icon":21},"Medium Risk (21-70)","Require a CAPTCHA, email verification, or secondary authentication factor.",{"title":329,"description":330,"icon":331},"High Risk (71-100)","Block the request entirely or flag the account for immediate manual review.","i-lucide-ban",{"title":33,"description":216},"threat-scoring-system","2HFFtRiIlV831zDeLNQ7o-p-KTBrsHfNw_twVG1GDr8",1782044514200]