AbuseIPDB

AbuseIPDB MCP integration

Scores an IP or a whole network block before you trust it, reads the complaints behind that score, and files your own reports back.

6actions available

Three actions you can hand over today

Every action runs live through MCP. Nothing to build, nothing to maintain.

  • Check IP reputation

    Lyro checks the abuse reputation of an IP address against AbuseIPDB's database. A security team confirms whether traffic from an address is flagged as malicious before deciding how to respond.

  • Bulk report

    Lyro submits multiple IP abuse reports to AbuseIPDB at once via a CSV upload. A team logs a batch of malicious addresses in one action instead of filing each report separately.

  • Clear address reports

    Lyro removes all abuse reports associated with a specific IP address from AbuseIPDB. A team corrects a mistaken or outdated report without contacting AbuseIPDB support directly.

See all 6 actions

How businesses use AbuseIPDB + Lyro

Each card is one request a support team gets, and the AbuseIPDB actions Lyro runs to close it.

  • Check an address before you trust the request

    Lyro looks up the abuse confidence score for an IP over a chosen look-back period and reads the individual complaints behind it, including the reported categories, rather than treating the score as a bare number.

    Check IP ReputationGet Abuse Reports
  • Judge a whole network, not one address

    Lyro scores every address in a CIDR range for aggregated abuse data on that block, and pulls the most reported addresses in the database to feed a blocklist or firewall rule.

    Check BlockRetrieve IP Blacklist
  • Contribute back what you have seen

    After an abusive session, Lyro submits reports in bulk through a CSV upload and clears the reports your account filed against an address once you have verified you control it.

    Bulk ReportClear Address Reports

How it works

Get started in 3 steps

Connect once, then just ask. There is no workflow builder to learn and nothing to maintain — Lyro reads the AbuseIPDB actions it has and picks the ones a request needs.

  1. 01

    Connect AbuseIPDB

    Authorize the AbuseIPDB account your team already uses — one consent screen, no API keys, no mapping tables. Lyro can only do what you granted that account, and you can disconnect it at any time.

  2. 02

    Tell your agent what you need

    Describe the job the way you would hand it to a teammate. Lyro maps it to the AbuseIPDB actions that close it and chains as many as the request needs.

  3. 03

    Watch it work

    The agent runs the actions inside the conversation the customer is already in, so nobody copies data between tabs and your team can take over at any point.

    Get started free
AbuseIPDB · Lyro

Everything else about AbuseIPDB

Setup, permissions, and the limits of what Lyro can do inside AbuseIPDB.

  • That is your policy call, not the score's. Check IP Reputation returns a community-sourced abuse confidence score over a look-back window you set, and Get Abuse Reports shows the actual complaints and categories behind it - so the decision can be made on what was reported rather than on the number alone.

Every action available in AbuseIPDB

All 6 actions your agent can call on AbuseIPDB, straight from the live MCP connection.

  • Retrieve IP blacklist

    Retrieves a list of the most reported malicious IP addresses from AbuseIPDB's database.

  • Bulk report

    Submit multiple IP abuse reports to AbuseIPDB in bulk via CSV upload.

  • Check block

    Check the reputation of all IP addresses in a CIDR range.

  • Check IP reputation

    Check the reputation of an IP address.

  • Clear address reports

    Remove all reports associated with a specific IP address.

  • Get abuse reports

    Retrieve abuse reports for a specific IP address from AbuseIPDB.

Ready to connect AbuseIPDB?

Authorize the account and your agent has all 6 actions from the first conversation.

Support agent working at a laptop next to the Lyro mascot