Changelog
Every change that affects how the API behaves: new and removed endpoints, changed parameters and response fields, quota and rate-limit changes, and deprecations. We follow semantic versioning — major versions may introduce breaking changes. Releases that changed nothing for API consumers are not listed.
v2.5.1 May 2026
-
Fixed
Quota counters no longer double-charge.
POST /reportused to bump both the daily check counter and the daily report counter on the same call, eating into the check quota every time a customer reported an IP./reportnow charges only the report quota — the check quota is reserved for actual reputation lookups. -
Fixed
POST /bulk-checknow charges N against the daily check quota where N is the number of valid IPs in the request (previously +1 regardless of payload size). Calls that would exceed the remaining quota return HTTP 429 without incrementing the counter. -
Fixed
POST /bulk-reportnow charges N against the daily report quota where N is the number of submitted reports (previously did not increment the report counter at all). Calls that would exceed the remaining quota return HTTP 429 before any report is inserted. -
Fixed
Tier-gated feature endpoints (
GET /blacklist,/blacklist-categories,/blacklist-stats,/reports/{ip},/trends) no longer consume the check quota. They are sold as separate “Threat Feed” / analytics features in the pricing plan and were never supposed to count as checks.
v2.5.0 May 2026
-
Added
bundle_balance,bundle_eligible,inclusive_limit,inclusive_usedandinclusive_availablefields on/relay-quota,/relay-mailand/relay-smsresponses for both Mail and SMS — clients can now render the prepaid bundle saldo next to the inclusive monthly counter. -
Added
Top-level
mail_bundle_balanceandsms_bundle_balanceon/relay-quota. The latter complements the existing field that older Hive clients already read but the service did not populate. -
Added
Public documentation for the 2FA relay endpoints (
GET /relay-quota,POST /relay-mail,POST /relay-sms) including auth, parameters, examples and the full HTTP error matrix (401 / 402 / 403 / 429). -
Changed
/relay-quotanow exposes the prepaid bundle saldo so the Hive dashboard can render the “+ X credits in your bundle balance” line for both Mail and SMS. -
Note
bundle_balanceis a signed integer. Refunded charges produce negative balances which block further sends until a new bundle is purchased — this is the documented Stripe-refund protection (charge.refundedwebhook).
v2.3.0 April 2026
- Added Business tier at 39 € / month (389 € / year): 100,000 API checks/day, 5,000 reports/day, 15 domains, 2,500 included 2FA mails/month, 75 included 2FA SMS/month, white-label setup wizard, WooCommerce integration, GDPR export tool, priority support 12 h SLA.
- Added 2FA mail relay: managed SMTP delivery for Hive plugin authentication mails, 500 included for PRO, 2,500 for Business, fair-use unlimited for Enterprise.
- Added 2FA SMS relay (reportedIP managed relay) with worldwide delivery minus an internal country blocklist (toll-fraud protection), 25 included for PRO, 75 for Business, prepaid bundles available.
- Changed Tier raised limits: PRO is now 25,000 checks/day · 1,000 reports/day · 3 domains (was 25,000 / 1,000 / 1).
v2.1.0 November 2025
-
Added
GET /statisticsendpoint with public service-wide statistics. - Added Threat-categories statistics endpoint and blacklist-stats endpoint with confidence-band breakdowns.
v2.0.0 March 2025
-
Added
Public endpoints:
/check-public,/search-public,/stats-public - Added Honeypot integration with confidence bonus for trusted automated reporters
- Added Bulk check endpoint for Professional+ users (up to 1,000 IPs per request)
- Added Bulk report endpoint for Enterprise users with CSV format support
- Added Trend data endpoint with time series analysis
- Added Detailed reports per IP endpoint for Professional+ users
- Added Blacklist export in TXT, JSON, and CSV formats
-
Added
Rate limit headers:
X-RateLimit-Limit,X-RateLimit-Remaining,X-RateLimit-Reset - Changed Confidence score calculation now includes time dampening with configurable half-life
- Changed Report aggregation with burst protection (5-minute window for duplicate reports)
-
Deprecated
/blacklist-detailed— redirects to/blacklist -
Deprecated
/blacklist-combined— redirects to/blacklist?source=all -
Deprecated
/blacklist-export/git— redirects to/blacklist?format=txt
v1.0.0 January 2025
-
Added
Core IP check endpoint (
/check) -
Added
IP report endpoint (
/report) - Added API key authentication system
-
Added
Basic blacklist endpoint (
/blacklist) - Added 30 predefined threat categories with severity levels
- Added User roles: Free, Contributor, Professional, Enterprise (Business added later in v2.3.0)
-
Added
API key verification endpoint (
/verify-key)
Last updated: · Maintained by the ReportedIP team
Security Focused
GDPR Compliant
Made in Germany