AbuseIPDB logo
ConnectorAbuseIPDB

AbuseIPDB integration for Claude and Codex

Connect AbuseIPDB once, then control which Spaces can use its approved tools and data without pasting credentials into prompts or threads.

Use AbuseIPDB from Claude

Add the AbuseIPDB connection to a Space that runs Claude, then use it from every channel in that Space.

Use AbuseIPDB from Codex

Add the AbuseIPDB connection to a Space that runs Codex, then use it from every channel in that Space.

Use AbuseIPDB from Sidekick

Connect your own OpenClaw to Sidekick while type.com provides the conversations, permissions, connections, skills, and automations.

Security & Identity

What the AbuseIPDB connector can do

AbuseIPDB maintains a shared database of IP addresses reported for abusive activity, used widely in firewall and SIEM workflows. With an AbuseIPDB connection in type.com, a security Space can ask Claude to check whether an IP has a history of abuse, pull the current blacklist for a blocklist update, or submit reports after confirming malicious traffic.

One connection, many Spaces

Connect AbuseIPDB once, then decide which Spaces can use it in threads, skills, automations, and coding work.

What teams do with AbuseIPDB in type.com

Check a suspicious IP during an investigation

Look up an IP's abuse reports and confidence score before deciding whether to block it at the firewall.

Try asking
Check the reputation of IP 185.220.101.5 in AbuseIPDB over the last 90 days.

Refresh a blocklist with known bad IPs

Pull the latest list of highly reported malicious IPs to update a firewall rule set or threat feed.

Try asking
Retrieve the current AbuseIPDB blacklist and give me the top 50 IPs by abuse confidence.

Report confirmed malicious traffic

Submit a batch of IPs tied to an attack so the shared database reflects the activity your team just saw.

Try asking
Bulk report these 12 IP addresses to AbuseIPDB from the CSV of today's failed login attempts.

Representative actions

  • Retrieve IP Blacklist

    Returns the most reported malicious IPs from AbuseIPDB, useful for building blocklists or threat feeds.

  • Bulk Report

    Submits multiple IP abuse reports at once via a CSV upload instead of reporting addresses one by one.

  • Check Block

    Checks the abuse reputation of every IP address in a CIDR range to get a picture of a whole network block.

  • Check IP Reputation

    Looks up whether a single IP address has been reported for abuse within a chosen time window.

  • Clear Address Reports

    Removes all abuse reports tied to an IP address, intended for use after confirming you control that address.

Connection

API and auth details

AbuseIPDB exposes threat-intelligence APIs for checking IP reputation, checking CIDR blocks, reporting abusive IPs, retrieving blacklists, viewing usage limits, and integrating abuse reports or IP checks into firewalls, Fail2Ban, SIEM, and network-defense workflows.

FAQ

Questions people ask before connecting AbuseIPDB

Can Claude check IP reputation using AbuseIPDB?

Yes. Once an AbuseIPDB connection is shared with your Space, ask Claude in a thread to check an IP, pull the blacklist, or submit a report, and the results stay with the team.

How is the AbuseIPDB connection authenticated?

AbuseIPDB uses an API key. An admin adds it once when creating the connection and controls which Spaces can query or report through it.

Can type.com refresh a blocklist automatically?

Yes. Turn a blacklist pull into a type.com automation, such as a daily refresh, so the agent keeps a channel updated with the latest reported IPs.

Is this the same as an MCP server for AbuseIPDB?

Not exactly. type.com uses connectors and connections to give selected Spaces access to approved app tools and data. Some connectors use hosted MCP, while others use OAuth, API keys, service accounts, or custom APIs.

More security & identity connectors

All Security & Identity integrations