passlisted in Coinbase#4 by calls of 342 on this host
0.005 USDC
per call, as the listing declares it on eip155:
- Validation state
- pass
- Uptime, 7 / 30 / 90 days
- 100% / 100% / 100%
- Calls, trailing 30 days
- 20
- Unique payers, trailing 30 days
- 5
- Last called
- 2026-09-15 14:04 UTC
- First observed by TOLLderived
- 2026-09-10
- Pricederived
- 0.005 USDC
- Networks
- 1
How big is this endpoint among the ones like it?
No trace is drawn of this endpoint’s own volume. Its counters have changed 2 times across 29 observations, and 3 changes are the fewest this site will draw a trace through, because two points and a guess are not a series. Every observation is in the JSON.
fraud ip shares api.agentstools.dev with 341 other listed endpoints and is 4th by calls.
Callers of fraud ip supply the query parameters ip and country.
A response from fraud ip, as declared, includes ip, asn, as_org, is_tor, country, on_drop and 2 others.
fraud ip drew 20 calls from 5 unique payers in the trailing 30 days, about 4 calls per payer.
fraud ip was last called on the day of the snapshot.
On Base, fraud ip asks 0.005 USDC per call.
Of the calls counted across api.agentstools.dev, fraud ip takes 3%.
fraud ip, a GET endpoint on api.agentstools.dev, appears in the Coinbase registry; TOLL's taxonomy puts it in identity.
fraud ip answered the sweep of 2026-09-15 with a valid 402, as at every sweep since 2026-09-11.
Closest in price to fraud ip within identity: my usage at agent402.tools and address profile at agent402.tools.
fraud ip is priced above 20% of comparable listings in identity.
Within identity, 97% of endpoints with counters have fewer calls.
The wallet paid by fraud ip is the payee of 344 endpoints across 2 hosts.
The seller's tags on fraud ip are fraud, anti-abuse, ip and reputation.
The price of fraud ip is declared by 128 other listings in identity too.
the payment options, as of 2026-09-15 21:20 UTC · method · pinnable
| registry | network | asset | amount | scheme | pay to |
|---|---|---|---|---|---|
| Coinbase | eip155: | USDC | 0.005 USDC | exact | 0xF22e55…DFf493 |
the checks, as of 2026-09-15 06:15 UTC · method · pinnableendpoint answered HTTP 402
No named check failed.
Every sweep that observed this endpoint, newest first.
| observed, UTC | state | failed checks | sweep |
|---|---|---|---|
| 2026-09-15 06:15 UTC | pass | 0 | daily-2026-09-15 |
| 2026-09-14 05:45 UTC | pass | 0 | daily-2026-09-14 |
| 2026-09-13 05:39 UTC | pass | 0 | daily-2026-09-13 |
| 2026-09-12 07:56 UTC | pass | 0 | daily-2026-09-12 |
| 2026-09-11 11:50 UTC | pass | 0 | daily-2026-09-11 |
Presence in a registry, not liveness of the service (method). Newest first.
- listed in Coinbase
From the registry record, not validated by TOLL.the declared schema, as of 2026-09-15 19:22 UTC · method · live
The input and output block
{
"input": {
"type": "http",
"method": "GET",
"queryParams": {
"ip": "185.220.101.1",
"country": "US"
}
},
"output": {
"type": "json",
"example": {
"ip": "185.220.101.1",
"asn": 60729,
"as_org": "TORSERVERS-NET",
"is_tor": true,
"country": "DE",
"on_drop": false,
"reasons": [
{
"reason": "IP is a known Tor exit relay.",
"signal": "is_tor",
"weight": 30,
"severity": "high",
"dimension": "anonymity"
}
],
"supported": true,
"disclaimer": "These are automated reputation indicators, NOT a guarantee and NOT a statement about any individual. A high score is not proof of fraud; a low score is not an endorsement. Contains no personal data. Verify before acting.",
"ip_version": 4,
"risk_score": 48,
"is_datacenter": true,
"risk_category": "medium"
}
}
}Cite this page
The pinned URL below renders this page from the snapshot of 2026-09-15 21:20 UTC and does not change; the live page does, every six hours. Data reuse is under CC BY 4.0 (terms).
Plain text
TOLL, "fraud ip on api.agentstools.dev", snapshot of 2026-09-15 21:20 UTC. https://tollindex.com/e/api-agentstools-dev-fraud-ip-b28f47/at/2026-09-15T21-20Z. Accessed [access date].
BibTeX
@misc{toll-e-api-agentstools-dev-fraud-ip-b28f47-2026-09-15T21-20Z,
author = {TOLL},
title = {fraud ip on api.agentstools.dev},
howpublished = {\url{https://tollindex.com/e/api-agentstools-dev-fraud-ip-b28f47/at/2026-09-15T21-20Z}},
year = {2026},
month = {9},
note = {Pinned view of the snapshot of 2026-09-15 21:20 UTC. Accessed [access date].}
}None yet. Anything submitted through the form below is published here with its outcome.