Skip to main content
POST
Use this endpoint when your application needs IP-risk signals during a sign-up, login, or abuse-prevention decision. It accepts one permitted IPv4 or IPv6 address and returns a normalised result, regardless of which configured Security provider produced it.
Live Testing Guide: Before using Try it, create a Development project, then enter its Client ID and Client Secret. Configure the relevant provider for that project before sending the request.

API endpoint

POST

Request fields

Outside the documentation Playground, keep the Project Client Secret on your backend. Do not call this endpoint directly from browser code, and process only IP addresses that you are permitted to use for your security workflow.

Result fields

A false risk signal means the selected provider did not classify the address for that indicator. Combine these signals with your own risk policy; they are not a standalone decision to block or approve a user.

Request example

This example uses IPv4. The same field also accepts a valid IPv6 address, such as 2001:4860:4860::8888.
curl

Response example

Error codes

Keep the JSON request_id or X-APIX-Request-ID response header with your support record. It is the safest way for AvraAPI support to trace a request.
See the REST API guide for shared credential, privacy, and error-handling guidance.

Playground resources

The generated reference below lists this endpoint’s API standard details: request fields, authorizations, and response schema. The complete integration guide, request and response examples, and endpoint-specific error handling are above.

Authorizations

X-API-KEY
string
header
required

Your Development project's Client ID. Enter your own value in the Documentation Playground.

X-API-SECRET
string
header
required

Your Development project's Client Secret. Mintlify does not proxy these requests; the browser sends them directly to AvraAPI. Never enter a Production secret in the Documentation Playground.

Headers

X-ENV
enum<string>
default:development

Selects the Development credential environment. The Documentation Playground exposes Development values only; normal backend integrations may use their documented Production credentials outside this tool.

Available options:
dev,
development
Accept
string

Requests a JSON response where the selected operation supports JSON.

Example:

"application/json"

X-Privacy-Mode
boolean
default:false

Optional privacy override. Turn this on to request that AvraAPI suppress request-payload storage in observability logs for this request.

Example:

true

Body

application/json
ip
string<ip>
required

A valid IPv4 or IPv6 address.

Example:

"203.0.113.10"

Response

Normalised VPN and proxy risk result.

success
enum<boolean>
required
Available options:
true
request_id
string<uuid>
required

Include this value when contacting AvraAPI support.

data
object
required

Operation-specific result data.

Last modified on October 1, 2026