# SniffCat > Privacy-focused IP abuse database and OSINT threat-intelligence platform. Report malicious IP > addresses, check an address's abuse confidence score, and pull score-ordered blocklist feeds over a > free, versioned REST API. Community-moderated, AbuseIPDB-style. Operated by Sefinek (Poland). Generated by API Evangelist on 2026-08-19 from the provider's published documentation. SniffCat does not serve an llms.txt of its own (https://sniffcat.com/llms.txt returned 404), and publishes no OpenAPI, so everything below was read from the HTML reference and verified against live calls to https://api.sniffcat.com. Status: Early Access / open beta. Platform version 0.4.0; API build version 0.1.5; API path version v1. ## API basics - Base URL: https://api.sniffcat.com - Path prefix: /api/v1 - Auth: every endpoint requires the `X-Secret-Token` request header. Generate a token at https://sniffcat.com/api after registering at https://sniffcat.com/register. A call without it returns 403 `{"success":false,"status":403,"message":"Missing API token in request headers."}`. - Every response, success or error, is `{"success": , "status": , ...}` — the HTTP status is repeated inside the body. Errors add a human-readable `message`. There is no stable error code. - Rate limiting: responses carry the IETF `RateLimit` and `RateLimit-Policy` header fields (observed: `limit=400, remaining=399, reset=120` / `400;w=120`). Exhaustion returns 429. No Retry-After. Daily per-operation quotas come from your account ROLES and reset at 00:00 UTC. - Timestamps are ISO 8601 UTC with milliseconds. Countries are ISO 3166-1 alpha-2. ## Endpoints - GET /api/v1/blacklist — reported IPs ordered by abuse score. Required: `confidenceMin` (30-100). Optional: `type` (txt default, or json), `limit` (10-100000, default 1000), `ipVersion` (4|6), `includeCountries` / `excludeCountries` (mutually exclusive, comma-separated alpha-2), `categories` (max 5 ids). Responses cached 25 minutes keyed on a SHA256 of the query string; `X-Cache: HIT` responses do not consume quota. Errors: 400, 403, 429, 500. - GET /api/v1/check — abuse confidence score for one IP. Required: `ip`. Optional: `withReports=true` returns up to 48 recent reports. Errors: 400, 403, 429, 500. - GET /api/v1/reports — paginated report history for one IP. Required: `ip`. Optional: `maxAgeInDays` (default 30, max 365), `perPage` (default 32, max 100), `page` (default 1). Returns `total`, `page`, `count`, `perPage`, `lastPage`. Errors: 400, 404 (never reported), 422 (local/private address), 429, 500. - POST /api/v1/report — submit an abuse report. JSON body: `ip` (public address only), `categories` (array of ids or comma-separated string, at least one), `comment` (min 10 chars). Returns `abuseConfidenceScore`, `previousScore`, `delta`. The same IP may only be reported once every 20 minutes. Errors: 400, 422, 429, 500. - POST /api/v1/bulk — CSV bulk reporting. Documented but NOT yet implemented ("Soon"). ## Report categories (required on every report) 27 ids in 3 groups, each with a severity weight that feeds the abuse score: 1 DNS Compromise (14), 2 DNS Poisoning (13), 3 DDoS Attack (17), 4 Port Scan (8), 5 Mass Scanner (10), 6 Exploited Host (16), 7 Malware Hosting (17), 8 C&C Beaconing (14), 9 CryptoJacking (12), 10 Phishing (17), 11 Hacking (12), 12 SQL Injection (14), 13 Command Injection (14), 14 Spam Activity (6), 15 Bad Web Bot (7), 16 Path Traversal (13), 17 Brute-Force (10), 18 SSH/SFTP (11), 19 FTP (9), 20 Email (8), 21 HTTP/HTTPS (9), 22 RDP (13), 23 Telnet (7), 24 SMB (12), 25 MongoDB (9), 26 Redis (8), 27 Other Abuse (7). Full definitions: https://sniffcat.com/documentation/categories ## Roles and quotas Daily limits are the sum of a base allowance plus every role held. Base: report 3000, bulk 15, check 1000, reports 400, blacklist 7. Roles add on top and also weight how much your reports move an IP's score: Individual (1.00), Early User (1.19), Webmaster (1.24), Contributor (1.36), SniffCat Enthusiast (1.48), Hosting Provider (1.54), ISP (1.62), Security Researcher (1.75), Law Enforcement (1.83). Full matrix: https://sniffcat.com/documentation/roles ## Testing Use 1.1.1.1 — the provider designates it as safe to exercise without affecting the main database. Whitelisted infrastructure (Googlebot, Bingbot, Cloudflare, UptimeRobot and others) is excluded from scoring: https://github.com/sefinek/trusted-ips-whitelist ## Docs - Documentation home: https://sniffcat.com/documentation - API reference: https://sniffcat.com/documentation/api - Endpoint pages: /documentation/api/blacklist, /check, /reports, /report, /bulk - Report categories: https://sniffcat.com/documentation/categories - Roles and API limits: https://sniffcat.com/documentation/roles - Integrations: https://sniffcat.com/documentation/integrations - Terms of Use: https://sniffcat.com/terms-of-use (incomplete) ## Official integrations (git clone, not published to npm) - UFW SniffCat Reporter (JavaScript, v0.5.1) — https://github.com/SniffCatDB/UFW-SniffCat-Reporter - Cloudflare WAF To SniffCat (JavaScript, v1.11.0) — https://github.com/SniffCatDB/Cloudflare-WAF-To-SniffCat - T-Pot To SniffCat (JavaScript, v0.2.0) — https://github.com/SniffCatDB/T-Pot-To-SniffCat - Suricata To SniffCat — announced, repository does not exist yet - Python client `sniffcat` v0.1.8 (PyPI, last released 2025-09-02) — https://github.com/SniffCatDB/sniffcat.py Community: SniffCat Fail2Ban and SniffCat cPanel, both by Rexikon, MIT licensed. ## Operations - Status page: https://status.sniffcat.com/ (human-readable only — no JSON or RSS feed) - Security contact: https://sniffcat.com/.well-known/security.txt (support@sniffcat.com) - Support tickets: https://sniffcat.com/tickets — Discord: https://discord.gg/S7NDzCzQTg - GitHub org: https://github.com/SniffCatDB ## What SniffCat does NOT publish No OpenAPI, Swagger, GraphQL, AsyncAPI or Postman collection. No MCP server. No agent card. No webhooks or event stream. No OAuth/OIDC and no scopes. No RFC 9457 problem details. No changelog, deprecation policy or SLA. No pricing page — the API is free. No privacy policy.