beta

API

Every page is built from these endpoints. Send an API key as Authorization: Bearer vpndb_…; create one under Account.

This page

GET /api/v1/meta

curl -s -H 'Authorization: Bearer vpndb_EXAMPLE_NOT_A_REAL_KEY' \
  '/api/v1/meta'

All endpoints

GET /api/v1/ip/{ip}Who operates an address
GET /api/v1/ip/{ip}/historyEvery week of an address
GET /api/v1/prefix/{cidr}Any range, and who is inside it
GET /api/v1/prefix/{cidr}/addressesEvery address of a prefix, in a window
GET /api/v1/prefix/{cidr}/timelineHow a prefix was probed, day by day
GET /api/v1/asn/{asn}A network and its providers
GET /api/v1/asn/{asn}/networksEvery prefix of a network
GET /api/v1/org/{id}A company and all its networks
GET /api/v1/org/{id}/networksEvery prefix of a company
GET /api/v1/country/{cc}The infrastructure located in a country
GET /api/v1/countriesEvery country at a glance
GET /api/v1/service/{tag}A provider's profile
GET /api/v1/service/{tag}/networksEvery network a provider exits from
GET /api/v1/servicesEvery provider at a glance
POST /api/v1/bulkMany addresses at once
GET /api/v1/searchResolve free text
GET /api/v1/suggestSuggestions as you type
GET /api/v1/metaThe dataset
GET /api/v1/openapi.yamlThis specification
GET /api/v1/sourcesWhere the data comes from
API documentationOpenAPI specification
Sign in

Entities

Networks (ASNs)

Provider distribution across an autonomous system, and the collateral of an ASN-wide block.

An ASN resolves to a distribution of providers with percentages, not a binary result.

NetworkDistributionWhat it means
AS136787NordVPN 99.9 %Single tenant — attribution is near-certain
AS9009CyberGhost 41.6 %, ProtonVPN 17.3 %, PIA 17.3 %, 25 in totalAn address here identifies the host, not the service

Networks carrying providers

The anonymised portion of an ASN is often a small number of prefixes. The page lists those in which providers were observed and marks those shared between providers. The remainder of the ASN is not implicated.

If you block this ASN

Two inputs to the collateral assessment. The provider count gives the number of services an ASN-wide block would affect. Where the operator has registered with PeeringDB, the network type indicates whether subscriber traffic sits behind the ASN; an access ISP carrying a few VPN exits differs materially from a transit carrier.