REQUESTINTEL API

RequestIntel API

Identify supported bots and crawlers, then understand whether a claimed identity is verified, unverified, or spoofed. Inspection data is processed ephemerally and is not stored by default.

Base URL

https://api.requestintel.dev/v1

Quickstart

Send an IP address and User-Agent to /v1/inspect using your RequestIntel API key.

Quickstart
curl -X POST https://api.requestintel.dev/v1/inspect \
  -H "Authorization: Bearer ri_live_xxxxxxxxx" \
  -H "Content-Type: application/json" \
  -d '{
    "ip": "20.171.207.12",
    "user_agent": "GPTBot/1.2"
  }'

Authentication

Authenticate every API request with an active API key created in your RequestIntel account.

Authorization: Bearer ri_live_xxxxxxxxx

Treat API keys as secrets and never expose them in client-side code.

POST/v1/inspect

Inspect a single IPv4 or IPv6 request using its IP address and User-Agent.

ParameterTypeRequiredDescription
ipstringYesIPv4 or IPv6 address to inspect.
user_agentstringYesUser-Agent reported by the request.
headersobjectNoOptional additional request headers. Accepted by the API for forward compatibility, but headers do not currently affect V1 bot identification or verification.
Request body
{
  "ip": "20.171.207.12",
  "user_agent": "GPTBot/1.2",
  "headers": {
    "accept": "*/*"
  }
}

POST/v1/inspect/batch

Inspect between 1 and 100 requests in one call. The output order matches the input order.

Request body
{
  "requests": [
    {
      "ip": "20.171.207.12",
      "user_agent": "GPTBot/1.2"
    },
    {
      "ip": "192.0.2.7",
      "user_agent": "Mozilla/5.0"
    }
  ]
}

A batch containing 100 items is one HTTP request for rate limiting, but consumes 100 API lookups from the account's monthly allowance.

Batch quota checks are atomic. If the account does not have enough remaining monthly allowance for the entire batch, the whole batch is rejected before inspection begins. No items are processed and no lookup allowance is consumed. For example, if an account has 7 lookups remaining and sends a batch containing 10 items, the full batch is rejected.

GET/v1/me

/v1/me inspects the request that is calling the RequestIntel API. It requires API-key authentication and is intended for integration testing and diagnostics.

  • It is a diagnostic convenience endpoint, not a replacement for sending an end-user request to /v1/inspect.
  • Reverse-proxy or trusted-proxy configuration can affect which source IP RequestIntel sees.
  • It returns the same core response shape as an inspection.
Request
curl https://api.requestintel.dev/v1/me \
  -H "Authorization: Bearer ri_live_xxxxxxxxx"

Response object

This example includes every field returned for an identified bot. When no supported bot is identified, bot, identity, and network are null.

Response
{
  "request_id": "req_01K...",
  "is_bot": true,
  "bot": {
    "id": "openai-gptbot",
    "name": "GPTBot",
    "organization": "OpenAI",
    "category": "ai_crawler",
    "purposes": ["training"]
  },
  "identity": {
    "status": "verified",
    "signals": [
      { "type": "user_agent", "result": "match" },
      { "type": "official_ip_range", "result": "match" }
    ]
  },
  "network": {
    "asn": 8075,
    "organization": "Microsoft Corporation"
  }
}

is_bot: false means RequestIntel did not match the request to a supported known bot identity. It does not prove that the request came from a human.

verified
The claimed bot identity has been independently confirmed using supported authoritative verification data.
unverified
The request matches a known bot identity, but RequestIntel does not currently have enough independent evidence to prove the identity. It does not mean fake.
spoofed
A supported authoritative verification check contradicts the claimed crawler identity.

bot.organization is the organisation operating the identified crawler.

network.organization is the organisation associated with the source IP's network/ASN. Network enrichment may be null, is not guaranteed for every request, and does not mean the crawler operator owns that infrastructure.

Common outcomes

These examples describe what a response means without exposing the intelligence rules behind it.

Verified

GPTBot · is_bot: true · identity.status: verified

A supported crawler identity is recognised and independently confirmed by RequestIntel.

Unverified

ClaudeBot · is_bot: true · identity.status: unverified

A supported crawler identity is recognised, but RequestIntel does not currently have enough independent evidence to prove it.

Spoofed

Claimed GPTBot · is_bot: true · identity.status: spoofed

A request claims to be a supported crawler, but RequestIntel's authoritative verification checks contradict the claim.

Unknown / not recognised

is_bot: false · bot: null · identity: null

No supported bot identity matched the request. This does not prove the request was human.

An unavailable verification signal is not the same as a failed verification signal. spoofed is reserved for cases where a supported authoritative check contradicts the claim.

Response signals use generic types such as user_agent, official_ip_range, reverse_dns, forward_dns, and asn. They describe the result; RequestIntel does not publish per-bot verification recipes.

Errors & limits

Request-rate limit

API requests are rate-limited per API key. Your dashboard shows the request-rate limit that applies to your account.

Monthly lookup allowance

Monthly usage is counted per inspected item at the account level. This allowance is separate from the request-rate limit.

Monthly limit exceeded

429 Too Many Requests

Error response
{
  "error": {
    "code": "monthly_limit_exceeded",
    "message": "monthly limit exceeded"
  }
}

Monthly limits are hard limits. RequestIntel does not automatically charge overages. Browse supported bots and crawlers to see the public reference coverage.

Privacy by default

RequestIntel does not retain inspected IP addresses, User-Agent strings, headers, URLs, request bodies, or individual request results by default. Only aggregate usage required for billing and account limits is retained.