[{"name":"datacenter","code":"d","scope":"ip","description":"IP belongs to a datacenter or cloud provider and is unlikely to be a real residential user."},{"name":"vpn","code":"v","scope":"ip","description":"IP is associated with a VPN provider and may be used to mask the user's true location or identity."},{"name":"proxy","code":"p","scope":"ip","description":"IP is acting as a proxy server, routing traffic on behalf of other clients."},{"name":"tor","code":"t","scope":"ip","description":"IP is a known TOR exit node, commonly used for anonymous browsing and to bypass geo-restrictions."},{"name":"abuse","code":"a","scope":"ip","description":"IP has been reported for abusive behaviour such as spam, brute-force attacks, or fraud."},{"name":"automated_navigation","code":"A","scope":"ip","description":"IP has been associated with automated browser activity such as headless browsers or bot frameworks."},{"name":"scraper","code":"s","scope":"ip","description":"IP has been detected harvesting content from websites at scale."},{"name":"ai_scraper","code":"i","scope":"ip","description":"IP belongs to an AI training crawler or data pipeline scraping content to train machine learning models."},{"name":"botnet","code":"b","scope":"ip","description":"IP is part of a botnet and likely being used to conduct coordinated malicious activity such as DDoS attacks or credential stuffing."},{"name":"client_impersonation","code":"C","scope":"request","description":"Multiple signals indicate the client is impersonating a legitimate browser or device. TLS fingerprint, user-agent, and header profile are mutually inconsistent."}]
