ASN Lookup API

Map any IPv4 or IPv6 address to its ASN, ISP and organization, then look up the Autonomous System itself: name, org, RIR and sample prefixes. Full schema on every plan, including Free.

Sign up Read the docs

Free: 1,000 req/day · HTTPS · commercial OK

Example

Look up the network behind an IP, then the Autonomous System it belongs to:

GET /v0/ip/{ip} · GET /v0/asn/{asn}
$ curl -s https://api.networkdatalabs.com/v0/ip/8.8.8.8 \
    -H "Authorization: Bearer YOUR_API_KEY" | jq '.network'

{
  "asn": 15169,
  "as_org": "Google LLC",
  "isp": "Google LLC",
  "organization": "Google LLC",
  "network": "8.8.8.0/24"
}

$ curl -s https://api.networkdatalabs.com/v0/asn/AS15169 \
    -H "Authorization: Bearer YOUR_API_KEY"

{
  "asn": 15169,
  "name": "GOOGLE",
  "org": "Google LLC",
  "domain": "google.com",
  "type": "hosting",
  "country_code": "US",
  "rir": "ARIN",
  "prefixes_sample": ["8.8.8.0/24", "8.8.4.0/24"]
}

The IP lookup returns the ASN, organization and containing prefix for the IP; the ASN lookup describes the network itself. {asn} accepts 15169 or AS15169, and an unknown ASN returns 404 NOT_FOUND. Have a list? POST /v0/bulk takes up to 100 IPs per request with the same schema; a bad IP shows up under errors without failing the batch, and each IP counts toward the daily quota.

Response fields

  • network.asn — the Autonomous System Number the IP belongs to
  • network.as_org, isp, organization — AS organization, ISP and organization names
  • network.network and network.rir — containing prefix (CIDR) and Regional Internet Registry (ARIN, LACNIC, RIPE, APNIC, AFRINIC)
  • GET /v0/asn/{asn} — name, org, domain, type, country_code, rir and prefixes_sample. type is often unknown for most ASNs today; don’t rely on it to classify traffic

The IP lookup also returns location and traits in the same call; see the IP geolocation API.

What teams use it for

  • Abuse & security — group abusive traffic by ASN and organization, and rate-limit or review whole networks instead of single IPs
  • Fraud & risk — spot server traffic with the IP lookup’s is_hosting flag, alongside the IP fraud detection signals
  • Enrichment & analytics — add ISP and organization names to logs, events and dashboards, and segment traffic by network
  • Routing & networking — map IPs to their Autonomous System and sample prefixes for routing, peering and troubleshooting

What it doesn’t do

  • Prefixes are a sample. prefixes_sample lists some announced prefixes, not the full list.
  • type is often unavailable. For most ASNs today type comes back as unknown (and domain / country_code may be null); don’t use ASN type to classify traffic. Prefer the IP lookup’s is_hosting flag for hosting signals. rir and the containing network can also be missing, so code a fallback.
  • An ASN is a network, not a person. An ISP’s ASN covers many unrelated users, so treat it as context rather than identity.

Use ASN and organization to group and explain traffic, then decide with the rest of the response.

FAQ

What’s the difference between the IP lookup and the ASN lookup?

GET /v0/ip/{ip} tells you which network an IP belongs to (ASN, AS organization, ISP, organization and prefix), together with location and traits. GET /v0/asn/{asn} describes the network itself: name, org, domain, country, RIR and sample prefixes (type is often unknown).

Does it support IPv6?

Yes. GET /v0/ip/{ip} and POST /v0/bulk accept both IPv4 and IPv6 addresses (for example 2001:4860:4860::8888). Malformed IPs return 400 INVALID_IP.

Is there a free plan?

Yes: 1,000 requests per UTC day with the full response schema, commercial use OK. In bulk, each IP counts as one request toward the daily quota.

Start building

Sign up for a free account, or read the quickstart and full reference in the docs.

Sign up Read the docs

Related APIs