IP Fraud Detection API

Check the IP behind every signup, login and payment: known VPN networks, Tor exits, privacy relays, hosting ranges, and the IP’s country with an accuracy radius and confidence. Plain signals you combine into your own risk score, not a black-box verdict.

Sign up Read the docs

Free: 1,000 req/day · HTTPS · commercial OK

Example

Look up one IP and keep the fields that matter for risk with jq:

GET /v0/ip/{ip}
$ curl -s https://api.networkdatalabs.com/v0/ip/4.2.2.2 \
    -H "Authorization: Bearer YOUR_API_KEY" \
    | jq '{country_code: .location.country_code, accuracy_radius_km: .location.accuracy_radius_km,
           confidence: .location.confidence, traits: (.traits | {is_vpn, is_tor, is_relay, is_hosting})}'

{
  "country_code": "US",
  "accuracy_radius_km": 50,
  "confidence": "medium",
  "traits": {
    "is_vpn": false,
    "is_tor": false,
    "is_relay": false,
    "is_hosting": false
  }
}

4.2.2.2 comes back as a US IP with a 50 km radius at medium confidence and every flag false. An IP in a known VPN network returns "is_vpn": true, and a Tor exit returns "is_tor": true. Have a list? POST /v0/bulk takes up to 100 IPs per request with the same schema; a bad IP shows up under errors without failing the batch, and each IP counts toward the daily quota.

Response fields

  • location.country_code — the IP’s country, to compare with the billing, card or account country
  • accuracy_radius_km and confidence — how much to trust the location before you act on a mismatch
  • is_vpn — known VPN networks, including major commercial VPN providers
  • is_tor — current Tor exit nodes
  • is_relay — privacy relay; usually legitimate consumer traffic, so it’s kept separate from is_vpn
  • is_hosting — hosting/datacenter detection: traffic coming from servers rather than home or mobile connections
  • network.asn and as_org — the network behind the IP, to group abuse by network (see the ASN lookup API)

The response has no single risk score: you weigh these signals in your own code, so every decision stays explainable and tuned to your own risk tolerance.

What teams use it for

  • Signup — ask for email or phone verification when is_vpn, is_tor or is_hosting is true, or when the IP country doesn’t match the country the user picked
  • Login — step up to 2FA or an email check when the IP country differs from the account’s usual country, or the IP is a Tor exit
  • Payments & checkout — compare the IP country with the card or billing country, and send mismatches with high or medium confidence to manual review
  • Promo & trial abuse — limit free trials, coupons and referral rewards claimed from known VPN networks, Tor exits and datacenter IPs

What it doesn’t do

  • Signals, not verdicts. A flag says what kind of network an IP is on, not who the user is or what they intend; plenty of VPN and hosting traffic is legitimate.
  • Location is an estimate. Check accuracy_radius_km and confidence before acting on a country mismatch.
  • New networks can take time to show up. A brand-new VPN range or Tor exit can show false until our data picks it up.

Step up verification instead of hard-blocking on a single flag, and review outcomes to tune your weights.

FAQ

Does it return a risk score?

No. The API returns the individual signals (location with accuracy radius and confidence, network and traits), and you combine them in your own code. For example: weight is_tor above is_vpn and is_hosting, add points when the IP country doesn’t match the billing country, and count that mismatch only when confidence is high or medium.

Does it support IPv6?

Yes. GET /v0/ip/{ip} and POST /v0/bulk accept both IPv4 and IPv6 addresses (for example 2001:4860:4860::8888). Malformed IPs return 400 INVALID_IP.

Is there a free plan?

Yes: 1,000 requests per UTC day with the full response schema, commercial use OK. In bulk, each IP counts as one request toward the daily quota.

Start building

Sign up for a free account, or read the quickstart and full reference in the docs.

Sign up Read the docs

Related APIs