MCP Server & SIEM/SOAR Integrations

Give your AI assistant live IP reputation, BGP, RPKI and WHOIS data through the Model Context Protocol, or enrich alerts in your SIEM and SOAR with the REST API.

Hosted MCP server

Nothing to install - add one URL to your AI client.

Read-only tools

Nine lookup tools, same data as the REST API.

Free API key

Same credits and rate limits as REST requests.

MCP Server for AI Agents

The Model Context Protocol (MCP) lets AI assistants call external tools. With the ipctl.io MCP server, an assistant can answer questions like "Is 185.220.101.1 malicious?", "Who announces 1.1.1.0/24 and is it RPKI-valid?" or "Which transit providers has AS24940 authorized?" with live data instead of guessing.

Endpoint: https://api.ipctl.io/v1/mcp (Streamable HTTP). Authenticate with your API key as Authorization: Bearer nq_.... Create a free key in the dashboard.

Available tools

lookup_ipOwner, ASN, prefix, geolocation, reverse DNS, threat score and tags of an IP address.
check_ip_reputationIs an IP blacklisted or malicious? Threat score and every flag with its severity.
bulk_ip_lookupMany IPs in one call, e.g. all source IPs of an alert (paid plans).
lookup_asnName, organisation, country, registry, abuse contact and routing statistics of an ASN.
list_asn_prefixesIPv4/IPv6 prefixes an ASN announces in BGP, with RPKI status (first 500).
lookup_prefixBGP routes and origins (incl. MOAS), RPKI/ROA validation, IRR objects, more-specifics.
aspa_lookupAuthorized upstream providers and downstream customers of an ASN (BGP ASPA). Counts as two requests.
whoisRegistry (RDAP/WHOIS) registration data for an IP address.
searchFind ASNs and prefixes by organisation or network name or ASN; for an IP or prefix it lists the covering prefixes (use lookup_ip for IP details).

Setup

Claude Code
claude mcp add --transport http ipctl https://api.ipctl.io/v1/mcp \
  --header "Authorization: Bearer nq_your_api_key"
Cursor (~/.cursor/mcp.json)
{
  "mcpServers": {
    "ipctl": {
      "url": "https://api.ipctl.io/v1/mcp",
      "headers": { "Authorization": "Bearer nq_your_api_key" }
    }
  }
}
VS Code (.vscode/mcp.json)
{
  "inputs": [
    { "type": "promptString", "id": "ipctl-key", "description": "ipctl API key", "password": true }
  ],
  "servers": {
    "ipctl": {
      "type": "http",
      "url": "https://api.ipctl.io/v1/mcp",
      "headers": { "Authorization": "Bearer ${input:ipctl-key}" }
    }
  }
}
Claude Desktop and other stdio-only clients (via mcp-remote)
{
  "mcpServers": {
    "ipctl": {
      "command": "npx",
      "args": ["mcp-remote", "https://api.ipctl.io/v1/mcp", "--header", "Authorization:${IPCTL_AUTH}"],
      "env": { "IPCTL_AUTH": "Bearer nq_your_api_key" }
    }
  }
}

SIEM & SOAR Enrichment

SIEM and SOAR platforms connect to external data through HTTP requests, not MCP. Use the REST API to enrich alerts with IP reputation, ownership and routing context - in a playbook step, an enrichment script or a scheduled lookup.

  1. Add an HTTP request step to the playbook or workflow (every SOAR and automation tool has one).
  2. Call GET https://api.ipctl.io/v1/intel/{ip} with the header X-API-Key: nq_your_api_key (or Authorization: Bearer nq_your_api_key) for each IP in the alert.
  3. Branch on data.score: for example auto-close below 20, enrich and escalate above 75.
  4. For alerts with many IPs, send them in one request to POST https://api.ipctl.io/v1/bulk (paid plans).
curl -s -H "X-API-Key: nq_your_api_key" https://api.ipctl.io/v1/intel/185.220.101.1

{"data": {"score": 50, "intel": [
  {"tag": "tor-node", "severity": "low"},
  {"tag": "vpn", "severity": "low"},
  {"tag": "hosting", "severity": "info"},
  {"tag": "crypto-node", "severity": "info"}
]}}

Full endpoint reference, response fields and rate limits: API documentation. Web-based checks: IP reputation & blacklist check.

Frequently Asked Questions

Is there an MCP server for IP reputation and network lookups?

Yes. ipctl.io runs a hosted MCP server at https://api.ipctl.io/v1/mcp. AI assistants that support the Model Context Protocol can use it to check IP reputation, look up ASNs, prefixes, RPKI and ASPA data, and query WHOIS - no installation required, just the URL and an API key.

Which AI assistants can use the ipctl MCP server?

Any MCP client that supports remote servers over Streamable HTTP with a custom Authorization header, for example Claude Code, Cursor and VS Code. Clients that only run local (stdio) servers, such as Claude Desktop, can connect through the mcp-remote bridge.

Do I need an API key, and what does it cost?

An API key is required; a free key works and includes 1,000 requests per day. Each tool call is billed and rate-limited like the REST request(s) it makes: IP, ASN, prefix and reputation lookups cost 1 credit, search, WHOIS, ASN prefix lists and ASPA lookups are free (aspa_lookup counts as two requests against the rate limit). Bulk lookups need a paid plan and cost 1 credit per unique IP.

Can I connect ipctl to my SIEM or SOAR?

Yes, through the REST API. SIEM and SOAR platforms usually integrate external data with an HTTP request step in a playbook, a lookup or an enrichment script rather than via MCP. Call /v1/intel/{ip} or /v1/ip/{ip} with your API key for each indicator, or /v1/bulk for many IPs at once. If your SOC uses an AI assistant that supports MCP, it can use the MCP server instead.

Is the MCP server read-only?

Yes. All tools only read data and are marked read-only for the client. The server cannot change anything in your account, and it only returns the same data as the public REST API.

Can I use the API without a key?

The REST API allows 250 anonymous requests per day for quick tests. The MCP server always needs a key, because AI agents can issue many requests in a short time.