Changelog
All notable changes to IPBot are documented here. The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
[Unreleased]
Section titled “[Unreleased]”-
ASN hosting-role inheritance — a monthly offline inventory aggregates IP2Proxy datacenter evidence across each ASN’s IPv4 ranges (with PeeringDB access-network veto and contradiction-sample rejection) so hosting ASNs outside every keyword, overlay, and per-IP signal — notably their IPv6 space — now classify with
is_datacenter,usage_type=datacenter,network.category=datacenter, anddecision.role=datacenter. Inherited roles are classification evidence only and add zero risk-score weight. The IP2Proxy download now prefers the IPV6 BIN variant (IPv4+IPv6 coverage) with automatic fallback. Curated coverage added for Spartan Host, VirMach, Hosteons, GreenCloudVPS, and Crunchbits, including corrections where PeeringDB self-reported types were wrong; budget-hosting risk keywords extended accordingly (evidence-tiered, per existing Tier-3 semantics). -
Programmable IP-quality parity — legacy
/and/{ip}lookups now support deterministic plain-text output through?format=textorAccept: text/plain, including a four-linedetail=1form for shell scripts. Canonical/v1endpoints remain JSON-only. -
Publisher-reviewed RFC 8805 corroboration — a new atomic geofeed update pipeline, reloadable longest-prefix index, readiness reporting, and conservative mapper truth table can raise
classification.country_alignment.confidencetohighonly when a reviewed operator publication corroborates the estimated country. The current authority check is publisher-level rather than per-prefix; unreviewed rows are ignored, conflicts returnunknown, andscore_effectremains0. -
Reloadable operator directory — curated ASN/operator records can now overlay the built-in map and expose the optional display-only
network.operator_domain; lookup and ASN pages render verified official hostnames as outbound links. Missing data falls back to built-ins and never changes scoring. -
Local-only environment consistency checks — after an explicit Diagnose action, the dual-stack diagnostic compares the supplied IPv4/IPv6 countries with each other and with browser timezone/language hints. Those browser values stay in the page and are not added to the API request.
-
IP-quality guidance and documentation — lookup results include a collapsed, advisory use-case view derived from the existing scenario decisions, plus new Native IP and neutral IPBot-versus-Ping0 documentation pages.
-
Independent-label benchmark foundation — a standard-library runner now captures public API predictions against approved, time-bounded labels and reports per-task coverage, precision, recall, specificity, and false-positive rate without treating
risk_scoreas a probability. It fails closed on expired labels, mixed builds, incomplete build metadata, IP mismatches, and unsupported provenance; reports remainclaim_status=not_approveduntil separate human and license review. -
Accuracy & Methodology page —
/accuracynow states which regression, safety, source-readiness, and shadow properties IPBot measures, which real-world accuracy and calibration properties remain unmeasured, and the evidence required before a public benchmark claim. -
Privacy-safe product-use telemetry — Prometheus and Grafana now separate canonical product endpoints by bounded access tier, client class, and status family without IP, queried-address, user-agent, account, or API-key labels.
Changed
Section titled “Changed”- The lookup Country Alignment section now sits after Location and presents observed GeoIP country and registration country side by side with plain-language alignment labels, while preserving the five-state API status and its evidence-only semantics.
- Application request logs now retain canonical route, status, timing, response size, bounded tier, and bounded client class instead of raw request paths, raw user agents, or client-IP hashes. Privacy and pricing copy now disclose request processing, account records, usage counters, sessions, and normalized RDAP caching instead of claiming the service is completely stateless.
- Public positioning now describes estimated location and explainable risk evidence rather than promising fraud detection, a calibrated probability, fixed geolocation accuracy, or unmeasured response times. Structured data no longer includes a fabricated aggregate rating, an unimplemented site-search action, or invisible FAQ claims.
- Solutions documentation links now use their real routes, and the sitemap excludes login, dashboard, and internal pages.
Removed
Section titled “Removed”- The stale
free-ip-geolocation-apis-2026article, whose quota, pricing, latency, and accuracy tables were not supported by a reproducible current methodology, is retired with a permanent redirect to the maintained comparison page.
[1.12.4] - 2026-07-12
Section titled “[1.12.4] - 2026-07-12”Changed
Section titled “Changed”- Risk presentation aligned with decision semantics — the IP lookup risk color now follows the API
verdict/band(allow → green, monitor → amber, challenge → orange, block → red), with numeric thresholds only as a fallback for older APIs, so visual severity matches the Decision Engine rather than a raw number. Sub-scores now show direction correctly: adverse scores (abuse, routing risk) escalate in color, Trust and Evidence Quality read as positive, and Infrastructure is neutral context. The Risk Score is now labeled an evidence-derived model score (not a fraud probability), to be read together with Threat Evidence and Decision. Lookup data copy is corrected accordingly (country/region/city as GeoIP estimates, ISP/ASN as network/routing identity).
Removed
Section titled “Removed”- The datacenter-IP “danger” alert and the Surfshark affiliate link have been removed from lookup results — a network-type observation is no longer presented as a threat, and product judgment is no longer mixed with a commercial call-to-action.
[1.12.3] - 2026-07-12
Section titled “[1.12.3] - 2026-07-12”- P4 continuity scoring shadow — an internal-only, non-selectable candidate now records a two-decimal exact score, a rounded hypothetical verdict preview, active/current deltas, model versions, and explicit
calibration_status=not_measuredin the admin score trace. Independent low-cardinality metrics and a reproducible fixed-corpus report support a 7–14 day shadow evaluation. It does not change any public response, score, verdict, action, or Decision Engine output.
- Special-use threat suppression across source-tier scoring — a threat-feed match suppressed by the routability guard for special-use/bogon addresses can no longer be resurrected by the source-tier community-threat floor. The floor now requires an actual unsuppressed
threat:*scoring input. - Public score documentation no longer describes the evidence-derived 0–100 model value as an outcome-calibrated abuse probability; real calibration remains unmeasured without independently defined outcome labels.
[1.12.2] - 2026-07-12
Section titled “[1.12.2] - 2026-07-12”Changed
Section titled “Changed”- Five-axis lookup results — the IP lookup tool (and the compact demo on the homepage and What Is My IP) now presents results along five independent axes so source, network, anonymity, evidence, and risk can no longer be conflated: IP Source (the
country_alignmenttendency with fixed help copy explaining that “native” only compares registration and estimated GeoIP countries), Network (location + network + the former “Security” card, renamed Network Profile, minus risk/proxy/threat rows that belonged elsewhere), Anonymity (proxy/VPN/Tor/residential-proxy/privacy-relay in one place), Threat Evidence (direct-record vs prefix-context vs no-record state fromevidence.summary, the sampled/24context, threat level, main risk reasons, and threat/context signals), and Risk & Decision (score verdict and recommended action now live with the Decision Engine output). Cross-region (“non-native”) tendency renders in an amber warning tone, never the danger tone. On older API versions without the new fields, the Source and Threat Evidence states hide instead of guessing. - Contract tightening —
classification.country_alignmentandevidence.summaryare now documented as always present (non-null) on v1 IP responses, matching runtime behavior since 1.12.0.
Removed
Section titled “Removed”- The lookup UI’s never-populated ASN Insights/Services/Users-by-Location/Related-ASNs sections (driven by the removed
network.radarfield) are gone from the IP lookup results.
[1.12.1] - 2026-07-12
Section titled “[1.12.1] - 2026-07-12”- Decision proxy precedence — ISP/residential context can no longer hide generic proxy (
CPN,EPN,PROXY, or subtype-less proxy) or known-abuser evidence. Generic proxies now userole=proxy,profile=anonymizing_network, the proxy expected-loss class, and a minimummonitorguardrail; verified crawlers, public DNS resolvers, and private relays remain protected from conflicting proxy evidence. The public Decision Engine policy identifier is nowdecision-v1-2026-07.1. - Classification and alignment edge cases — CDN/operator overrides now clear heuristic
DCHlabels and flags together; malformed or unknown country-code sentinels no longer produce an alignment verdict; dynamic bogons reportbogon_addressinstead ofspecial_use_address. - Evidence summary semantics — documentation now states that
risk_score=0can result from suppression, trust offsets, or rounding even when a direct threat record exists. Clients should useevidence.summary.direct_threat_matchto answer that question. - Radar public boundary and ASN fallback — the default-off
IPBOT_RADAR_PUBLIC_ENABLEDgate now covers both the ASNradarblock and Radar-derived public IP operator/category fields. Internal Radar shadow telemetry remains independent. ASN pages always show local ASN identity when optional enrichment is absent and no longer suggest retrying a stableradar: nullresponse.
Changed
Section titled “Changed”- Range-reputation scoring prototype retired — the dormant scoring flag, score input, metrics, staging configuration, and active monitoring instructions have been removed.
evidence.prefix_threat_contextremains available, but it is now evidence-only by code construction:score_effect=0and no path intoriskProbs. - Public
score.risk_score,score.verdict, andscore.recommended_actionremain unchanged; the Decision Engine’srole,profile, scenarios, and advisoryactionintentionally change for the corrected proxy/known-abuser combinations.
[1.12.0] - 2026-07-11
Section titled “[1.12.0] - 2026-07-11”classification.country_alignment— an explainable answer to the “native IP” question. Instead of a bareis_nativeboolean, v1 IP responses now compare the estimated GeoIP country with the registration countries (RDAP allocation first, RIR delegation as fallback) and reportstatus(aligned/mismatch/multi_region/unknown/not_applicable), the input countries,basis, machine-readablereason_codes, and a confidence capped atmedium(GeoIP estimates usage location — it cannot prove physical server location;highis reserved for publisher-reviewed operator geofeeds, RFC 8805). Anycast and public-resolver services reportmulti_region; a contested BGP origin or an RDAP-vs-RIR country conflict reportsunknown. Descriptive only:score_effectis always0.evidence.summary+evidence.prefix_threat_context— v1 IP responses now separate “this exact IP has a direct threat record” (direct_threat_match) from “only the surrounding /24 shows threat-list coverage” (prefix_context_only). For IPv4,prefix_threat_contextreports sampled threat-list coverage of the surrounding /24 (sampled_hosts,matched_hosts, methodsampled_hosts_v1), plus aPrefix Threat Contextevidence signal when only the neighborhood matches. Evidence-only:score_effectis always0, it never enters scoring and never flips a verdict. Arisk_scoreof 0 is not an assertion that no direct record exists; suppression, trust offsets, and rounding can also produce zero, so clients should readdirect_threat_matchexplicitly.
- Residential decision role — residential IPs (usage type ISP / residential operator category) now reach their dedicated Decision Engine role (
role=residential,profile=ordinary_residential) instead of falling through tounknown_low_confidence. More specific roles (proxy, mobile, datacenter…) still take precedence. - Classification coherence — ASN/operator-tier context can no longer erase IP-level evidence or leave contradictory output such as
usage_type=datacenterwithis_datacenter=false. Per-IP datacenter evidence (IP2Proxy) always survives the operator tier; heuristic ASN-keyword classifications may be overridden by the operator classification, but the flag and the usage label now always change together.
Changed
Section titled “Changed”- Cloudflare Radar public redistribution is now opt-in and off by default (
IPBOT_RADAR_PUBLIC_ENABLED). Radar API data is licensed CC BY-NC 4.0, so theradarblock onGET /v1/asn/{asn}(and the legacy alias) returnsnullunless public redistribution is explicitly enabled under a separate license. Internal shadow telemetry remains independently controlled; 1.12.1 also places Radar-derived public operator fields behind this gate. The never-populatednetwork.radarfield on IP responses has been removed from the contract, and documentation examples that referenced it now usenetwork.operator_type. - Public
score.risk_score,score.verdict, andscore.recommended_actionare unchanged by all of the above (shadow scoring report byte-identical before/after).
[1.11.0] - 2026-07-06
Section titled “[1.11.0] - 2026-07-06”GET /v1/asn/{asn}— the ASN context endpoint now has a canonical v1 path (the legacy/asn/{asn}stays as a compatibility alias). The response adds a top-levelnamethat prefers IPBot’s local ASN database over Radar, and an evidence-onlyasndropblock when the ASN is on Spamhaus ASN-DROP. Cloudflare Radar enrichment is now optional: if Radar is unavailable or the lookup fails, the endpoint returns200with local fields andradar: nullinstead of an error.evidence.threatfoxmetadata — when the optional ThreatFox sidecar dataset is present and the IP already matched the ThreatFox C2 threat feed, v1 IP responses add the malware family, first/last-seen timestamps, and IOC confidence level, plus aThreatFox IOC Contextevidence signal. This is metadata only — it adds no score beyond the existingTHREAT_LIST:threatfoxhit. ThreatFox data © abuse.ch, CC0.
Changed
Section titled “Changed”- Hot reload (SIGHUP) is now resilient and observable: one failing data module no longer skips the remaining modules, failures are logged and aggregated, and the runtime exposes
ipbot_reload_last_success_timestamp_secondswith a stale-reload alert. The nightly data-refresh chain now triggers a single reload at the end instead of one per update step. - The
fieldsprojection parameter documentation now lists all twelve supported top-level fields, includingdecision,scores,scenarios, andexplanation. - Public
score.risk_score,score.verdict, andscore.recommended_actionare unchanged by all of the above.
[1.10.0] - 2026-07-02
Section titled “[1.10.0] - 2026-07-02”- Spamhaus ASN-DROP evidence — when the announcing ASN appears in the Spamhaus ASN-DROP list, responses include a
Spamhaus ASN-DROPevidence signal and a legacyASN_DROP:spamhausrisk reason. This is ASN-level reputation evidence only — it does not change the IP risk score by itself. ASN-DROP data © Spamhaus Project, used with attribution. - ASN threat density — an offline-precomputed measure of how much of an ASN’s announced IPv4 space appears on loaded threat lists. Surfaces as an
ASN Threat Densityevidence signal on IP lookups (when significant) and as an additivethreat_densityblock onGET /asn/{asn}(ratio,percent,threat_network_count,threat_ipv4_addresses,total_ipv4_addresses,significant). Evidence only; computed from threat lists + IPtoASN, refreshed on data reload. - Recently Allocated Network signal — when RDAP registration data shows the network was allocated within the last 90 days, responses include a
Recently Allocated Networkevidence signal (REGISTRATION_RECENT:<90dreason). Evidence only.
Changed
Section titled “Changed”- Spamhaus eDROP retired — Spamhaus merged eDROP into DROP upstream, so the standalone eDROP feed is no longer fetched or tracked; IP/CIDR coverage continues via DROP. The new ASN-DROP feed replaces it in the data stack with ASN-level evidence.
- PeeringDB operator enrichment now auto-refreshes when the cached snapshot is older than 7 days (previously it was only downloaded once).
GET /healthand theX-IPBot-Buildheader now always carry the realgit_shaandbuild_timefor production deploys.- Public
score.risk_score,score.verdict, andscore.recommended_actionare unchanged by all of the above.
[1.9.0] - 2026-06-30
Section titled “[1.9.0] - 2026-06-30”POST /v1/crawler/verify— a narrow crawler-verification endpoint for site-owner workflows. Given anipand optionaluser_agent, it returns averification_statusofverified,known_unverified, ornot_known, plus crawler classification (crawler_provider,crawler_type,crawler_verified_by,crawler_hostname), publicnetworkowner/allocation context, and anexplanationwith a machine-stablereason_code. DNS-verifiable families (Googlebot, Bingbot) can reachverifiedfrom the IP alone via reverse+forward DNS; OpenAI-family crawlers require both official range membership and a matching crawler user-agent token, otherwise they stayknown_unverified(reason_code: user_agent_mismatch). Documented indocs/openapi.v1.yaml.- Crawler verification tool and hub on the site: a
/crawler-verifyinteractive tool (URL round-tripping, presets, accessible status), a/crawlershub, and per-crawler/crawlers/{slug}detail pages backed by a versioned crawler catalog.
Changed
Section titled “Changed”- The main IP lookup and the new endpoint share crawler range/DNS resolution, but intentionally have different caller-context boundaries. Cacheable third-party
GET /v1/ip/{ip}ignores the caller User-Agent;POST /v1/crawler/verifyaccepts the explicitly supplied User-Agent and always returnsCache-Control: no-store. Current/self lookup retains caller telemetry. Publicscore.risk_score,score.verdict, andscore.recommended_actionare unchanged.
[1.8.1] - 2026-06-28
Section titled “[1.8.1] - 2026-06-28”Changed
Section titled “Changed”- Decision-engine
scenarios.*.actionis now chosen by expected loss (§8) instead of a static role×scenario table: each surface (content, seo_crawler, login, signup, payment, api) picks the action with the lowest combined cost of being wrong, given the IP’s evidence and that scenario’s stakes. Friction is now evidence-driven and proportionate — a clean IP gets no friction on any surface, while anonymizing/abusive IPs get graduated friction that rises on higher-stakes surfaces. Role floors are also enforced as true minimums (e.g. a Tor exit is at leastchallengeon every scenario). scenarios.*.confidenceis now computed per scenario (from each scenario’s expected-loss margin) rather than reusing the top-leveldecision.confidence.- These are additive decision-engine fields. Public
score.risk_score,score.verdict, andscore.recommended_actionare unchanged.
[1.8.0] - 2026-06-27
Section titled “[1.8.0] - 2026-06-27”Changed
Section titled “Changed”- Public
risk_scoreis now computed by the source-tier scoring model. It weights each piece of evidence by the authority of its source (official > registry/routing > commercial > community > heuristic). In practice this reduces false positives on trusted infrastructure — public DNS resolvers, verified crawlers, CDN/edge nodes, and Apple Private Relay sitting on generic datacenter ASNs now score lower (e.g.8.8.8.830 → 12,1.1.1.125 → 10) — and dampens heuristic-only signals, while strong threat, Tor, routing-conflict, and commercial-fraud signals are preserved or strengthened (e.g. a Tor exit stays at its full score; a BGP origin conflict scores higher). score.verdictthresholds are unchanged; most affected IPs move lower within the same verdict band, and any verdict shifts are toward less friction (e.g.monitor→allow) on genuinely trusted infrastructure. Two IPs with identical evidence still receive an identical score.- This was validated against a promotion gate (zero regressions, zero needs-review cases) before rollout and is reversible. Clients reading
score.risk_score/score.verdictshould expect slightly lower scores for trusted-infrastructure IPs.
[1.7.1] - 2026-06-26
Section titled “[1.7.1] - 2026-06-26”Changed
Section titled “Changed”decision.confidenceis now calculated from a multi-factor model — evidence quality, decision margin (how far the score sits from an action boundary), source authority, contradiction between trust and adverse risk signals, and guardrail stability — instead of a single evidence-quality threshold. Infrastructure context is not treated as adverse by itself. Same schema andlow/medium/highvalues; the levels are simply more accurate.- The decision policy identifier is now
decision-v1-2026-06.2. Admin-onlyGET /v1/internal/score/{ip}responses includetrace.decision_confidencewith the confidence score and component breakdown; public/v1/ip/*responses continue to expose only thelow/medium/highconfidence enum. - At the 1.7.1 release point,
scenarios.*.confidencestill mirrored the top-leveldecision.confidence; 1.8.1 later replaced that with per-scenario computed confidence. explanation.drivers[].impact_scoreis now a true leave-one-out counterfactual (each signal’s marginal effect), so redundant signals in an already-saturated group correctly show a small impact instead of their raw probability.
These remain purely advisory. Public score.risk_score, score.verdict, and score.recommended_action are unchanged.
[1.7.0] - 2026-06-23
Section titled “[1.7.0] - 2026-06-23”- Decision Engine v1: four additive, optional top-level objects on v1 IP lookup responses —
decision(profile/role/action/risk_level/confidence/policy_version/allowed_actions/blocked_actions/guardrails_applied),scores(eight 0-100 component sub-scores: risk, base risk, abuse, anonymity, trust, infrastructure, routing risk, evidence quality),scenarios(per-scenario action/risk_level/confidence/reason forcontent,seo_crawler,login,signup,payment,api), andexplanation(summary, key_reason, drivers with direction and impact, guardrails_applied, reason_chain). decision,scores,scenarios, andexplanationprojection support viafields=.- Decision panel in the web IP Lookup tool surfacing role, action, sub-scores, scenarios, and explanation.
Changed
Section titled “Changed”- These fields are purely advisory. Public
score.risk_score,score.verdict, andscore.recommended_actionare unchanged, and clients that ignore the new fields keep working exactly as before.
[1.6.0] - 2026-06-18
Section titled “[1.6.0] - 2026-06-18”Changed
Section titled “Changed”score.risk_scorenow combines signals with a bounded noisy-OR (probabilistic OR) instead of an additive sum-and-clamp. Multiple risk signals no longer pile up at exactly 100, single-signal scores are unchanged, and two IPs with identical evidence still receive an identical score by design. The value is evidence-derived, not an outcome-calibrated abuse probability.score.verdictthresholds are re-aligned to the public bands so the verdict never contradicts the displayed band:blockatrisk_score≥ 61 (danger),challengeat ≥ 41 (poor),monitorat ≥ 31 (fair), otherwiseallow.
- Commercial IP2Proxy fraud scores fold into
risk_scoreas a continuous, bounded probability (replacing fixed buckets); no effect on lite data. GET /healthreturns abuildblock (git_sha,build_time,risk_model_version,verdict_threshold_version,rules_version,data_edition), and every response carries anX-IPBot-Buildheader, so a deployed build is machine-verifiable.- Prometheus
ipbot_scoring_risk_scorehistogram andipbot_scoring_verdicts_total{verdict,band}counter for score-distribution and verdict-mix drift detection. - Admin-only
GET /v1/internal/score/{ip}scoring trace: every contributing signal with its probability, suppressions, trust dampening, and the noisy-OR result. Never exposed in public or legacy responses. - Experimental range-reputation scoring signal: a bounded /24 neighbor-abuse-density estimate computed from existing threat data. It was never enabled in production and was retired in 1.12.1.
[1.5.0] - 2026-06-09
Section titled “[1.5.0] - 2026-06-09”- Pro-only
include=rdap_contactsforGET /v1/ip/currentandGET /v1/ip/{ip}, returning normalized RDAP network/contact data only after Pro API key authentication. fields=rdapprojection support when the Pro RDAP include is accepted.- Normalized RDAP contacts, addresses, phones, emails, notices, remarks, and redaction metadata in the ownership cache without storing raw RDAP JSON or raw WHOIS text.
Changed
Section titled “Changed”- Free and anonymous lookup responses continue to expose only
network.ownerandnetwork.allocation; RDAP contact details remain hidden unless explicitly requested by a Pro key.
[1.4.0] - 2026-05-22
Section titled “[1.4.0] - 2026-05-22”- Evidence-first IP intelligence stack with public proxy, provider, Apple Private Relay, verified crawler, threat, and ASN context.
/v1/data/statusendpoint for public service and capability readiness.- Internal Prometheus counters for lookup volume, signal hit rate, proxy type distribution, residential hits, commercial-field coverage, and conflict/shadow-diff tracking.
- Tracked OpenAPI v1 contract at
docs/openapi.v1.yaml. - OpenClaw release smoke support for API Docker smoke and API + Astro preview validation.
Changed
Section titled “Changed”- Proxy detection is now presented as evidence fusion rather than a single-vendor wrapper.
- Conservative confidence is used when residential/provider/fraud-score evidence is not strong enough for public claims.
- Verified crawler and Apple Private Relay evidence protect those classes from being treated as ordinary high-risk proxy abuse.
- Data update scripts preserve last-known-good files on download failure and avoid replacing
netintel-ranges.jsonluntil normalization succeeds.
[1.3.0] - 2026-01-08
Section titled “[1.3.0] - 2026-01-08”- ASN Insights enrichment data integrated into IP lookup responses
- Skeleton loader for improved perceived loading performance on web tools
Changed
Section titled “Changed”- Rebranded Radar feature to ASN Insights across all documentation and UI
- Cache metadata hidden from user-facing responses for cleaner output
[1.2.0] - 2026-01-08
Section titled “[1.2.0] - 2026-01-08”- API key authentication system for enhanced access control
- Rate limiting with configurable tiers per API key
- ASN context from Radar-backed enrichment in IP lookup responses
[1.1.0] - 2026-01-07
Section titled “[1.1.0] - 2026-01-07”Changed
Section titled “Changed”- Migrated documentation to standalone pages for better SEO
- Updated branding across all web pages
[1.0.2] - 2026-01-06
Section titled “[1.0.2] - 2026-01-06”- API response parsing for nested ASN structure in Radar data
[1.0.1] - 2026-01-05
Section titled “[1.0.1] - 2026-01-05”- ASN-based risk scoring layer with keyword matching
- Redis-backed L2 cache for Radar enrichment data
- Blog infrastructure for content publishing
- Enhanced landing page with interactive demos
Changed
Section titled “Changed”- Improved documentation with code examples
- Enhanced frontend performance and UX
[1.0.0] - 2026-01-04
Section titled “[1.0.0] - 2026-01-04”- Initial release of IPBot IP Intelligence API
- IP geolocation with country, region, city, and coordinates
- ASN and organization lookup
- Threat intelligence with risk scoring
- Explainable risk reasons for auditability
- CORS-enabled endpoints for browser usage
- No API key required for free tier
- Health check endpoint with data version info
- Hot-reload support for configuration updates