IP Intelligence API logo

IP Intelligence API

|
Data
|
1 tokens / call

Fraud and abuse signals for any IPv4 or IPv6 address, from a self-hosted dataset of 1.37 million ranges: geolocated country, the AS number and organisation announcing the prefix, whether the address sits in published cloud or CDN address space (AWS, Azure, Google Cloud, Oracle, DigitalOcean, Cloudflare, Fastly, GitHub — 88,000 ranges across 8 operators), and whether it is a live Tor exit node. Two countries are returned, not one: where the block GEOLOCATES and where it is REGISTERED with its regional registry. Those disagree on about 16% of routed ranges, and the mismatch is itself a weak signal, so both are exposed along with a flag for whether they agree. Every answer carries a transparent risk score whose every point is attributed to a named, explained signal — there is no black box, because a fraud team has to justify the customers it blocks. Look up one address, up to 50 in a batch, or the caller's own address via /v1/ip/me; search 86,000 autonomous systems by name; list the prefixes an AS announces. Non-routable space (loopback, RFC1918, link-local, documentation) is labelled rather than returned empty, and IPv4-mapped IPv6 literals are unwrapped to the address they carry. Cloud ranges and the Tor exit list are refreshed daily. Built entirely on free, redistributable sources — RouteViews BGP via iptoasn (public domain), DB-IP Lite (CC-BY), and each operator's own published ranges — with no third-party calls at request time.

Quick Start

Subscribe to get instant API access with your unique API key.

View Pricing Plans

Available Endpoints

Request Parameters

API URL

Please subscribe to see the API URL

Headers

X-Api-Key

Please subscribe to see the actual API URL

import axios from 'axios';

const url = '{API_URL}';
const { data } = await axios.get(url, {
  headers: { 'X-Api-Key': 'YOUR_API_KEY' }
});