beta

API

Every page is built from these endpoints. Send an API key as Authorization: Bearer vpndb_…; create one under Account.

This page

GET /api/v1/meta

curl -s -H 'Authorization: Bearer vpndb_EXAMPLE_NOT_A_REAL_KEY' \
  '/api/v1/meta'

All endpoints

GET /api/v1/ip/{ip}Who operates an address
GET /api/v1/ip/{ip}/historyEvery week of an address
GET /api/v1/prefix/{cidr}Any range, and who is inside it
GET /api/v1/prefix/{cidr}/addressesEvery address of a prefix, in a window
GET /api/v1/prefix/{cidr}/timelineHow a prefix was probed, day by day
GET /api/v1/asn/{asn}A network and its providers
GET /api/v1/asn/{asn}/networksEvery prefix of a network
GET /api/v1/org/{id}A company and all its networks
GET /api/v1/org/{id}/networksEvery prefix of a company
GET /api/v1/country/{cc}The infrastructure located in a country
GET /api/v1/countriesEvery country at a glance
GET /api/v1/service/{tag}A provider's profile
GET /api/v1/service/{tag}/networksEvery network a provider exits from
GET /api/v1/servicesEvery provider at a glance
POST /api/v1/bulkMany addresses at once
GET /api/v1/searchResolve free text
GET /api/v1/suggestSuggestions as you type
GET /api/v1/metaThe dataset
GET /api/v1/openapi.yamlThis specification
GET /api/v1/sourcesWhere the data comes from
API documentationOpenAPI specification
Sign in

Evidence

External sources

Thirteen published lists, retrieved and read locally, each with its licence recorded.

Some attributes cannot be measured here. There is no probing channel for Tor or for iCloud Private Relay. Published lists supply these and several others.

SourceSuppliesLicence
Tor Bulk Exit Listtypes: ["TOR"], the sole source for itCC0
iCloud Private Relaytypes: ["RELAY"], with the city each egress presents aspublished, no grant
Open-Source VPN IP ListsPer-provider lists for nine VPNs; cross-checks attributionCC0
X4B VPN / DatacenterIndependent corroboration and DATACENTER classificationMIT
Spamhaus DROP / ASN-DROPAbuse context for a networkfree, attribution required
PeeringDBNetwork type per ASN: carrier against access ISPPeeringDB AUP
AWS, GCP, Oracle, DigitalOcean, CloudflareDATACENTER classificationpublished, no grant

Nothing is queried live

Each list is downloaded on a schedule and read from disk. No request leaves the host during a lookup. This is what makes an air-gapped installation viable: behaviour is identical to a connected one, with an older retrieval date.

Agreement and disagreement

Lists that name the provider, rather than flagging “a VPN”, can be compared against our own attribution. Agreement constitutes independent corroboration. Disagreement indicates either a coverage gap here or an error there. Both are reported; neither is recoverable if the data is reduced to a binary flag.

Source catalogueEach source with licence, record count and retrieval age.Open →