beta

API

Every page is built from these endpoints. Send an API key as Authorization: Bearer vpndb_…; create one under Account.

This page

GET /api/v1/meta

curl -s -H 'Authorization: Bearer vpndb_EXAMPLE_NOT_A_REAL_KEY' \
  '/api/v1/meta'

All endpoints

GET /api/v1/ip/{ip}Who operates an address
GET /api/v1/ip/{ip}/historyEvery week of an address
GET /api/v1/prefix/{cidr}Any range, and who is inside it
GET /api/v1/prefix/{cidr}/addressesEvery address of a prefix, in a window
GET /api/v1/prefix/{cidr}/timelineHow a prefix was probed, day by day
GET /api/v1/asn/{asn}A network and its providers
GET /api/v1/asn/{asn}/networksEvery prefix of a network
GET /api/v1/org/{id}A company and all its networks
GET /api/v1/org/{id}/networksEvery prefix of a company
GET /api/v1/country/{cc}The infrastructure located in a country
GET /api/v1/countriesEvery country at a glance
GET /api/v1/service/{tag}A provider's profile
GET /api/v1/service/{tag}/networksEvery network a provider exits from
GET /api/v1/servicesEvery provider at a glance
POST /api/v1/bulkMany addresses at once
GET /api/v1/searchResolve free text
GET /api/v1/suggestSuggestions as you type
GET /api/v1/metaThe dataset
GET /api/v1/openapi.yamlThis specification
GET /api/v1/sourcesWhere the data comes from
API documentationOpenAPI specification
Sign in

Evidence

Methods and evidence

probe, scan, cert, interpolated, feed: what each method establishes and what it does not.

Every claim carries the method that produced it. The methods are not interchangeable; the ordering below reflects evidential strength.

MethodWhat happenedStrength
probeTraffic was routed through the provider and egressed hereDirect observation
certThe TLS certificate issuer names the providerStrong. Operators sign with their own CA
scanThe host responded on a port used by this infrastructurePresence established, egress not proven
interpolatedNot observed itself; other addresses of its announced prefix were, and the prefix’s providers are reportedInference. Confidence from the share of the prefix observed
feedAn external list asserts itThird-party measurement. Publisher and retrieval date attached
inferredDerived from neighbouring observationsWeakest. Treat as a lead

Interpolated addresses

An address we never observed is answered from the announced prefix it sits in — the most specific one the routing table carries — whenever any of our sources knows at least one address of that prefix, datacenter or residential. The prefix’s figures are the union of all sources as computed after the last sync — the same the prefix search shows: each known address once, by the provider of its most recent sighting. Providers and weights follow from those counts; network names the prefix; evidence.coverage is the share known, computed by us: distinct known addresses divided by the prefix’s size. First and last seen are the prefix’s first and last sighting in any source.

Share of the prefix observedConfidence
More than 50 %High (3)
10 % to 50 %Medium (2)
1 % to 10 %Low (1)
Less than 1 %Very low (0)

Confidence

Every answer states its confidence — high (3), medium (2), low (1) or very low (0) — and how it was computed, in evidence.confidenceBasis and on the address page. The rule depends on what the answer rests on:

Rests onHigh (3)Medium (2)Low (1)Very low (0)
Our probe events for the address50 or more5 to 49fewer than 5—
A certificate naming the provideralways———
The enriched snapshot alone—always——
Interpolation from the prefixmore than 50 % observed10–50 %1–10 %less than 1 %
External lists alone——always—

Feeds never become measurements

External lists supplement gaps and never override a measurement. Attribution weights derive from our own probing and scanning only. Where a list names a provider, it appears under method: "feed" with the publisher, keeping retrieved data distinguishable from measured data. See External sources.