beta

API

Every page is built from these endpoints. Send an API key as Authorization: Bearer vpndb_…; create one under Account.

This page

GET /api/v1/meta

curl -s -H 'Authorization: Bearer vpndb_EXAMPLE_NOT_A_REAL_KEY' \
  '/api/v1/meta'

All endpoints

GET /api/v1/ip/{ip}Who operates an address
GET /api/v1/ip/{ip}/historyEvery week of an address
GET /api/v1/prefix/{cidr}Any range, and who is inside it
GET /api/v1/prefix/{cidr}/addressesEvery address of a prefix, in a window
GET /api/v1/prefix/{cidr}/timelineHow a prefix was probed, day by day
GET /api/v1/asn/{asn}A network and its providers
GET /api/v1/asn/{asn}/networksEvery prefix of a network
GET /api/v1/org/{id}A company and all its networks
GET /api/v1/org/{id}/networksEvery prefix of a company
GET /api/v1/country/{cc}The infrastructure located in a country
GET /api/v1/countriesEvery country at a glance
GET /api/v1/service/{tag}A provider's profile
GET /api/v1/service/{tag}/networksEvery network a provider exits from
GET /api/v1/servicesEvery provider at a glance
POST /api/v1/bulkMany addresses at once
GET /api/v1/searchResolve free text
GET /api/v1/suggestSuggestions as you type
GET /api/v1/metaThe dataset
GET /api/v1/openapi.yamlThis specification
GET /api/v1/sourcesWhere the data comes from
API documentationOpenAPI specification
Sign in

Evidence

How the coverage figure is built

Three evidence layers, counted as a union rather than a sum, each labelled by strength.

The figure on the front page is the volume of anonymised address space the dataset can make a statement about. It spans the whole record rather than a recent window: an analyst reconstructing an intrusion discovered ten months late needs the addresses that were live then. Its three inputs differ in evidential strength and are reported separately.

LayerWhat it isMethod
MeasuredEvery exit address any of our sources knows — our probing, the enriched snapshot, scan certificates — across the whole recordprobe, snapshot, scan
InterpolatedThe rest of every announced prefix in which we know at least one address, at high or medium confidenceinterpolated
From external listsNetblocks published sources attribute to anonymising servicesfeed

Why interpolate at all

Where 30 of the 256 addresses in a block are observed and the block demonstrably belongs to one provider, treating the remaining 226 as unknown understates the evidence. Every prefix with an observation is therefore interpolated, and the confidence says how far the inference reaches: above 50 % observed it is high, from 10 % medium, from 1 % low, below that very low. A lookup answers every band, with its confidence. The figure counts high, medium and low, but not very low: that band is by far the largest — over a billion addresses in the big residential prefixes in which a single proxy exit was seen — and in a headline it would read as a measurement it is not.

Union, not sum

The layers overlap substantially: most measured addresses fall inside an interpolated prefix, and many of those fall inside a listed netblock. Summing the three totals would count the same addresses up to three times. The ranges are therefore merged, and each layer reports only its marginal contribution. The rows sum correctly because they are differences, not independent totals.

What is left out

  • Datacenter and cloud ranges. AWS, GCP, Cloudflare and comparable sources describe hosting, not anonymising services. A datacenter host is not by itself a VPN exit.
  • Abuse feeds. Spamhaus DROP indicates a network is listed for abuse, which is context rather than evidence of anonymisation.
  • IPv6. Not collected by probing. Some lists cover it, but the figure is IPv4 only.
  • No time window. Addresses retired months ago still count. Whether one was live on a given date is a point-in-time question, answered per address rather than by filtering this total.

Recomputed by scripts/compute-coverage.ts whenever the data or feeds are refreshed. If it has not run, the page shows the measured count alone rather than an uncomputed estimate.