About this endpoint
What it does
Looks up an IP address and returns geolocation, ISP/ASN details, VPN/proxy/Tor/datacenter detection, threat flags, and a fraud risk score with a recommendation.
Query Parameter(s)
| Attribute | Type | Mandatory | Description |
|---|---|---|---|
| ip | String | Yes | IPv4 or IPv6 address to look up. |
Response
Returns a JSON object with the request status and an IP object covering geolocation, network operator, anonymization flags, and a risk score with a recommendation.
| Attribute | Type | Description |
|---|---|---|
| success | Boolean | Whether the request succeeded. |
| code | Integer | Numeric response code. |
| IP | Object | IP lookup result. |
| IP.IP | String | The IP address submitted. |
| IP.ip_version | Integer | 4 or 6. |
| IP.valid | Boolean | Whether the IP is well-formed. |
| IP.alpha2 / country / region / city | String | Geolocation detail. |
| IP.latitude / longitude / zip_code / time_zone / current_time | — | Location and local-time detail. |
| IP.isp / asn | String | Network operator and autonomous system number. |
| IP.is_proxy / is_vpn / is_tor / is_datacenter / is_public_proxy / is_residential_proxy | Boolean | Anonymization/network-type flags. |
| IP.threat_types | Array | Any known threat categories associated with the IP. |
| IP.risk_score | Number | Fraud risk score. |
| IP.risk_level | String | low, medium, or high. |
| IP.recommendation | String | accept, review, or reject. |
| IP.summary | String | Plain-language explanation of the result. |



