
IP Intelligence API
Fraud and abuse signals for any IPv4 or IPv6 address, from a self-hosted dataset of 1.37 million ranges: geolocated country, the AS number and organisation announcing the prefix, whether the address sits in published cloud or CDN address space (AWS, Azure, Google Cloud, Oracle, DigitalOcean, Cloudflare, Fastly, GitHub — 88,000 ranges across 8 operators), and whether it is a live Tor exit node. Two countries are returned, not one: where the block GEOLOCATES and where it is REGISTERED with its regional registry. Those disagree on about 16% of routed ranges, and the mismatch is itself a weak signal, so both are exposed along with a flag for whether they agree. Every answer carries a transparent risk score whose every point is attributed to a named, explained signal — there is no black box, because a fraud team has to justify the customers it blocks. Look up one address, up to 50 in a batch, or the caller's own address via /v1/ip/me; search 86,000 autonomous systems by name; list the prefixes an AS announces. Non-routable space (loopback, RFC1918, link-local, documentation) is labelled rather than returned empty, and IPv4-mapped IPv6 literals are unwrapped to the address they carry. Cloud ranges and the Tor exit list are refreshed daily. Built entirely on free, redistributable sources — RouteViews BGP via iptoasn (public domain), DB-IP Lite (CC-BY), and each operator's own published ranges — with no third-party calls at request time.
Available Endpoints
Request Parameters
API URL
Please subscribe to see the API URL
Headers
Please subscribe to see the actual API URL
import axios from 'axios';
const url = '{API_URL}';
const { data } = await axios.get(url, {
headers: { 'X-Api-Key': 'YOUR_API_KEY' }
});