NEW Workflow v2 · the multi-agent verification layer is live
All apps

AbuseIPDB

security & identity tools 6 tools available

AbuseIPDB is a project dedicated to helping make the internet safer by providing a central repository for reporting and checking IP addresses associated with malicious activities.

About this integration

Connect AbuseIPDB to Definable to automate repetitive tasks, sync data with the rest of your stack, trigger on real-world events. Personas call AbuseIPDB's 6 tools directly from chat or scheduled flows. You can wire it into any persona to read, write, and react when an event fires.

Connect AbuseIPDB to Definable and it becomes a set of typed tools your agents plan with — triggered by events, run on schedules, or invoked mid-conversation. Every write is checked by the verifier before it lands.

Auth OAuth2 · 2 clicks
Tools 6 exposed
Plans All, incl. Free
Data Never trained on

AbuseIPDB · in workflows

What teams actually run.

Three patterns teams run with AbuseIPDB on day one. Each one is a plain-English prompt — no canvas, no glue code — and you can remix them into anything.

01

Trigger on event

Listen for a new event
Parse and validate the payload
Take an action with the linked tool
02

Daily summary

Pull yesterday's activity
Summarise with the model of your choice
Send the digest via email or Slack
03

Cross-tool sync

Read records from one app
Transform with a persona
Write the result back via this integration

6 tools available

The AbuseIPDB toolbox.

Every AbuseIPDB capability your agents can call, each with a typed schema the planner reads. The router picks the right tool per step; the verifier checks the result.

Retrieve IP Blacklist

Retrieves a list of the most reported malicious IP addresses from AbuseIPDB's database. Use this tool to build dynamic blocklists, threat intelligence feeds, or firewall rules. The blacklist is updated hourly and contains IPs with high abuse confidence scores. Free accounts receive up to 10,000 IPs. Paid subscriptions unlock filtering options (confidenceMinimum, country filters) and higher limits (up to 500,000 IPs).

Bulk Report

Submit multiple IP abuse reports to AbuseIPDB in bulk via CSV upload. Use this when you need to report many malicious IPs at once instead of one-by-one. Returns the count of successfully saved reports and details about any invalid entries.

Check Block

Tool to check the reputation of all IP addresses in a CIDR range. Use when you need aggregated abuse data for a network block.

Check IP Reputation

Tool to check the reputation of an IP address. Use when you need to determine if an IP address has been reported for abusive activity within a specified look-back period. Example: CheckIp(ipAddress='8.8.8.8', maxAgeInDays=90).

Clear Address Reports

Tool to remove all reports associated with a specific IP address. Use when you need to purge your own abuse records after verifying control of the IP.

Get Abuse Reports

Retrieve abuse reports for a specific IP address from AbuseIPDB. Use this tool to view the history of abuse complaints filed against an IP address, including the reported abuse categories, reporter details, and timestamps. Supports pagination for IPs with many reports.

See it run

One prompt, start to finish.

A real prompt, the AbuseIPDB tools it calls, and what comes back. This is the whole interface — describe the outcome, agents handle the rest.

Run a real AbuseIPDB task end-to-end — plan it, execute across the API, and hand back a verified result.

abuselpdb.retrieve_ip_blacklist Retrieves a list of the most reported malicious IP addresses from AbuseIPDB's database. Us
abuselpdb.bulk_report Submit multiple IP abuse reports to AbuseIPDB in bulk via CSV upload. Use this when you ne
abuselpdb.check_block Tool to check the reputation of all IP addresses in a CIDR range. Use when you need aggreg · verified
done

Done. AbuseIPDB responded across 3 calls, the verifier signed off, and the result is logged with every payload.

FAQ · AbuseIPDB

Questions, answered.

What teams ask before connecting AbuseIPDB.

01 What can I automate with AbuseIPDB on Definable?

Anything AbuseIPDB exposes through its API. Common security & identity tools workflows on Definable include automate repetitive tasks, sync data with the rest of your stack, trigger on real-world events. Personas can call any of the 6 AbuseIPDB tools directly, then chain the result into another integration without you writing code.

02 How does AbuseIPDB authentication work?

AbuseIPDB uses API_KEY on Definable. You connect once from the integrations page, scoped to the permissions you choose, and from then on any persona that has the integration enabled can act on your behalf. Tokens are encrypted at rest and rotated automatically.

03 Is the AbuseIPDB integration included in my Definable plan?

Yes — every Definable plan, including Starter, includes access to all 6 AbuseIPDB tools. You only need a separate AbuseIPDB subscription if AbuseIPDB itself charges per seat or per API call.

04 Is using AbuseIPDB through Definable secure?

Every call from a persona to AbuseIPDB is logged with the user, persona, prompt, and response. Tokens never leave Definable's secrets vault, scopes are configurable per persona, and you can revoke access at any time from the integration page.

05 How do I get started with AbuseIPDB on Definable?

Sign up for Definable, open the integrations page, find AbuseIPDB, and connect via OAuth or API key. You can immediately attach AbuseIPDB to any persona and start running workflows. The free Starter plan includes 5,000 credits/month.

06 What AbuseIPDB actions does Definable expose?

Definable exposes all 6 AbuseIPDB actions as callable tools — including `Retrieve IP Blacklist`, `Bulk Report`, `Check Block`, plus 3 more. Each tool gets a typed parameter schema so personas know exactly how to call it.

Put AbuseIPDB to work tonight.

Connect in two clicks, describe an outcome, and your first workflow is live in minutes. Free plan included — no card required.

← All apps