IPQualityScore MCP integration for AI agents.

Connect AI agents to IPQualityScore through 4 structured actions, including check ip reputation, scan url, and validate email. Review authentication, inputs…

ACTION CONTRACTS
4
AUTHENTICATION
API key
SOURCE STATUS
Provider-backed

CATALOG SOURCE REVIEWED AUGUST 23, 2026 / ACTION NAMES AND SCHEMAS DERIVED FROM WORKING MACHINES PROVIDER SOURCE

CAPABILITY PROFILE

What the IPQualityScore integration exposes

The IPQualityScore Agent App exposes 4 provider-backed actions for security and data work. Its current contract lets an authorized agent check an ip address for proxy, vpn, tor, bot, and abuse risk signals, scan a url or domain and return malware, phishing, and domain risk signals, and validate an email address and return deliverability and abuse risk signals. These operations are called through Working Machines as typed capabilities rather than through browser navigation or copied UI steps.

A connection uses API key. Before execution, the agent can inspect the selected action, its required fields, declared scopes, and expected output contract. Provider credentials remain inside the Working Machines runtime; the calling agent receives the capability and its structured result, not the underlying secret.

For reliable operation, start with the narrowest action that satisfies the task, resolve stable provider identifiers before changing state, and validate the returned object or status after execution. Availability still depends on the connected IPQualityScore account, granted provider permissions, workspace policy, region, plan, and upstream API behavior.

VERIFIED ACTION SAMPLE

Real IPQualityScore capabilities.

Showing 4 of 4 actions. Risk labels are conservative signals based on operation names, not substitutes for provider documentation or runtime policy.

check_ip_reputationREAD

Check an IP address for proxy, VPN, Tor, bot, and abuse risk signals.

INPUTS: ipAddress / strictness / allowPublicAccessPoints / userAgent / userLanguage

scan_urlREVIEW

Scan a URL or domain and return malware, phishing, and domain risk signals.

INPUTS: url / strictness

validate_emailREVIEW

Validate an email address and return deliverability and abuse risk signals.

INPUTS: email / timeout / abuseStrictness

validate_phoneREVIEW

Validate a phone number and return carrier, activity, and risk signals.

INPUTS: phone / country / strictness

INPUT CONTRACTS

Know what the action needs before it runs.

check_ip_reputation

ipAddressREQUIRED
The IPv4 or IPv6 address to inspect.
strictnessOPTIONAL
How strict IPQS should be when scoring the lookup. Higher values may increase false positives.
allowPublicAccessPointsOPTIONAL
Whether to reduce risk flags for public access points such as schools or libraries.
userAgentOPTIONAL
The user agent associated with the IP lookup.
userLanguageOPTIONAL
The browser language associated with the IP lookup.

scan_url

urlREQUIRED
The URL or domain to scan.
strictnessOPTIONAL
How strict IPQS should be when scanning the URL. Higher values may increase false positives.

validate_email

emailREQUIRED
The email address to validate.
timeoutOPTIONAL
Maximum number of seconds IPQS should spend on mail service provider checks.
abuseStrictnessOPTIONAL
How strict IPQS should be when scoring the lookup. Higher values may increase false positives.

validate_phone

phoneREQUIRED
The phone number to validate.
countryOPTIONAL
Optional ISO 3166-1 alpha-2 countries to use when interpreting local numbers.
strictnessOPTIONAL
How strict IPQS should be when scoring the lookup. Higher values may increase false positives.

PROVIDER-SPECIFIC WORKFLOWS

Jobs this Agent App can support

Inspect Check Ip Reputation

Check an IP address for proxy, VPN, Tor, bot, and abuse risk signals. Use this as a bounded discovery step, retain the returned identifier, and avoid expanding the read beyond the task's stated scope.

check_ip_reputation

Verify with Scan Url

Scan a URL or domain and return malware, phishing, and domain risk signals. Compare the returned provider state with the intended outcome and preserve stable IDs or canonical links in the run record.

scan_url

SAFETY BOUNDARY

Operate IPQualityScore with explicit limits

  • Authorize IPQualityScore with API key and grant only the provider access required by the selected actions.
  • The current action names appear read-oriented, but returned IPQualityScore data may still be sensitive and should be minimized before it enters model context.
  • Do not infer permission from catalog visibility. Workspace policy, connection identity, and upstream authorization still govern execution.
  • No provider scope string is declared on the sampled actions. Verify the connected account's actual permissions in IPQualityScore rather than assuming unrestricted access.
  • After a call, inspect the structured result and execution record before reporting that the IPQualityScore task completed successfully.

CONNECTION MODEL

API key

IPQualityScore API key embedded in fraud detection API request URLs. Create or view API keys from the IPQS user dashboard: https://www.ipqualityscore.com/user/settings.

Working Machines stores provider credentials behind the execution boundary. An agent can use an authorized connection identity, but catalog discovery alone does not reveal OAuth tokens, API keys, or provider secrets.

READ SIGNALS
1
WRITE SIGNALS
0
HIGH IMPACT
0
REVIEW SIGNALS
3

EVIDENCE AND AVAILABILITY

Provider reference

Action names, input fields, authentication types, and counts on this page are generated from the Working Machines provider catalog. Provider behavior, quotas, object semantics, account eligibility, and regional availability remain governed by IPQualityScore.

Official IPQualityScore website

ONE CONNECTION. REAL WORK.

Give your agent software it can use.

Connect through MCP or explore the Agent App catalog and choose only the capabilities your workflow needs.

EXPLORE AGENT APPS