Security data API

VPN & Proxy Detection API

The ipbase API tells you whether an IP address belongs to a VPN, a proxy, the Tor network, iCloud Private Relay or a data center, and gives it a threat score. You get the security flags in the same JSON response as the location and network of the address, for IPv4 and IPv6.

Example request and response

The security object of the /v2/info endpoint, shortened from the example in the documentation. Add fields=security to get only the security data.

curl "https://api.ipbase.com/v2/info?ip=1.1.1.1" \
  -H "apikey: YOUR-API-KEY"
{
  "data": {
    "ip": "1.1.1.1",
    "connection": {
      "asn": 13335,
      "organization": "Cloudflare, Inc.",
      "isp": "APNIC Research and Development",
      "range": "1.1.1.1/32"
    },
    "location": { "country": { "alpha2": "US", "name": "United States" } },
    "security": {
      "is_anonymous": false,
      "is_datacenter": false,
      "is_vpn": false,
      "is_bot": false,
      "is_abuser": false,
      "is_known_attacker": false,
      "is_proxy": false,
      "is_spam": false,
      "is_tor": false,
      "is_icloud_relay": false,
      "threat_score": 0
    }
  }
}

Response fields

security.is_vpn
The address belongs to a VPN provider.
security.is_proxy
The address is a known open or anonymizing proxy.
security.is_tor
The address is a Tor exit node.
security.is_icloud_relay
The address is an iCloud Private Relay egress address.
security.is_datacenter
The address belongs to a hosting or cloud provider rather than a consumer network.
security.is_anonymous
The address hides the real client (VPN, proxy, Tor or relay).
security.is_bot, is_abuser, is_known_attacker, is_spam
The address has been seen sending bot traffic, abuse, attacks or spam.
security.threat_score
A score from 0 (no known threat) to 100, computed from the security flags.

Use cases

Sign-up and checkout fraud

Flag sign-ups and payments from VPNs, proxies and Tor before they reach your fraud review, and ask those users for extra verification.

Geo-restricted content

Licensing and compliance rules apply to the real location of a user. Detect when a VPN or proxy hides it.

Bot and abuse filtering

Rate-limit or challenge traffic from data centers and from addresses with a known abuse history.

Ad and analytics quality

Keep data center and anonymized traffic out of conversion and campaign reports.

Security data from the Medium plan

The free plan includes 150 requests a month with location and network data. The security flags are part of the Medium plan and above. Compare the plans.

Frequently asked questions

Can the API detect any VPN?

It detects the IP addresses of known VPN providers, proxies, Tor exit nodes and iCloud Private Relay. A private VPN on a residential or business connection looks like that connection and cannot be told apart by its IP address alone.

Does it work for IPv6 addresses?

Yes. /v2/info accepts IPv4 and IPv6 addresses, and the security object has the same fields for both.

Can I check many IP addresses at once?

Yes. POST /v2/batch looks up to 100 IP addresses per request; each address counts as one request of your quota.

Which plan includes VPN and proxy detection?

The security data is included in the Medium, Large and custom plans. The free and Small plans return location, network and time zone data without the security object.

Is there a free way to try it?

The free VPN and proxy checker on this site shows the same flags for one IP address at a time, without an API key.

Related

Free IP tools

Example lookups: 8.8.8.8 · 8.8.8.0/24 · AS15169 · example.com · all IPv4 ranges

Get your free IP geolocation API key

Start with 150 free requests a month