VPN Detection API

Detect VPN traffic by IP: check any IPv4 or IPv6 address against known VPN networks, Tor exits, privacy relays and hosting/datacenter ranges, and get its country in the same call. Plain flags with documented limits that you can score, not a black-box verdict.

Sign up Read the docs

Free: 1,000 req/day · HTTPS · commercial OK

Example

Look up one IP and keep the country, the network and the traits with jq:

GET /v0/ip/{ip}
$ curl -s https://api.networkdatalabs.com/v0/ip/8.8.8.8 \
    -H "Authorization: Bearer YOUR_API_KEY" \
    | jq '{country_code: .location.country_code, asn: .network.asn, as_org: .network.as_org, traits}'

{
  "country_code": "US",
  "asn": 15169,
  "as_org": "Google LLC",
  "traits": {
    "is_anycast": true,
    "is_hosting": true,
    "is_mobile": false,
    "is_satellite": false,
    "is_bogon": false,
    "is_proxy": false,
    "is_vpn": false,
    "is_tor": false,
    "is_relay": false
  }
}

8.8.8.8 is a public DNS resolver on a hosting network, so is_hosting and is_anycast are true, while is_vpn, is_tor and is_relay are false. An IP in a known VPN network returns "is_vpn": true, and a Tor exit returns "is_tor": true. Have a list? POST /v0/bulk takes up to 100 IPs per request with the same schema; a bad IP shows up under errors without failing the batch, and each IP counts toward the daily quota.

Response fields

  • is_vpn — the IP belongs to a known VPN network, including major commercial VPN providers.
  • is_tor — the IP is a current Tor exit node.
  • is_relay — the IP is a privacy relay egress. It’s kept separate from is_vpn, so you don’t treat privacy-relay users like VPN users by mistake.
  • is_hosting — hosting/datacenter detection: cloud, hosting and CDN networks where real users rarely browse from.
  • Country and network — country_code, accuracy_radius_km, confidence, ASN and AS organization, so you can compare the IP’s country with the billing or account country.

It’s the same GET /v0/ip/{ip} lookup as our IP geolocation API: one call returns geo, network and traits together.

What teams use it for

  • Signup, login & payment risk — treat each flag as one input to a score (for example, weight is_tor above is_vpn and is_hosting, and add points when the IP country doesn’t match the card or billing country), then add friction (email or SMS check, manual review) above a threshold
  • Promo & trial abuse — limit free trials, coupons and referral rewards claimed from known VPN networks, Tor exits and datacenter IPs
  • Geo-restricted content — flag traffic from known VPN networks and Tor in licensing and regional checks, alongside country_code from the IP to country API

What it doesn’t do

  • It can flag non-VPN servers. Whole networks of VPN-heavy hosting providers are flagged, so other servers there are flagged too. Major public clouds are not included in is_vpn; use is_hosting for those.
  • New networks can take time to show up. A brand-new VPN range or Tor exit can show false until our data picks it up.

Use the flags as signals, not verdicts: step up verification instead of hard-blocking on a single flag.

FAQ

What’s the difference between is_vpn and is_relay?

is_relay marks privacy relay egress IPs. A privacy relay hides the user’s IP for browsing privacy and is usually legitimate consumer traffic, so it’s kept separate from VPN: those IPs are never reported as is_vpn, and you can treat them more gently than a VPN.

Does it support IPv6?

Yes. GET /v0/ip/{ip} and POST /v0/bulk accept both IPv4 and IPv6 addresses (for example 2001:4860:4860::8888). Malformed IPs return 400 INVALID_IP.

Is there a free plan?

Yes: 1,000 requests per UTC day with the full response schema, commercial use OK. In bulk, each IP counts as one request toward the daily quota.

Start building

Sign up for a free account, or read the quickstart and full reference in the docs.

Sign up Read the docs

Related APIs