IP ASN API
You need reliable ASN and network attribution for an IP address so you can route traffic, enforce policy, or enrich logs. By the end of this guide, you’ll know how to call ipXapi’s IP ASN lookup, parse the authoritative response, and integrate it into your network services with production-minded behaviors like caching and error handling.
What this IP ASN API provides
The IP ASN lookup returns core network attributes for an IP address, including the autonomous system (AS), ISP and organization, location metadata, and security flags. You can use these fields to drive network decisions such as geo-aware routing, access control, or analytics enrichment.
- Path:
/api/ip - Authentication: HTTP header Authorization: Bearer YOUR_API_KEY
- MCP (management/control plane): MCP
- Docs: Documentation
- Register: Register
Pricing overview for planning: Basic is $29.99/mo; the trial is 7 days or 50 requests.
Quickstart: one endpoint, one IP
The lookup endpoint accepts an IP via the ip query parameter. Authentication uses a standard Bearer token in the Authorization header. The example below uses the documented fixture IP for demonstration purposes and should not be treated as the reader’s IP.
Official cURL request (copy-paste)
curl "https://ipxapi.com/api/ip?ip=148.105.12.120" -H "Accept: application/json" -H "Authorization: Bearer YOUR_KEY"
Official JSON response (fixture)
{
"status": "success",
"country": "United States",
"countryCode": "US",
"region": "US-CA",
"regionName": "California",
"city": "Mountain View",
"zip": "94043",
"lat": 37.40599,
"lon": -122.0786,
"timezone": "America/Los_Angeles",
"isp": "MailChimp",
"org": "MailChimp",
"as": "AS14782 MailChimp",
"query": "148.105.12.120",
"inEU": false,
"continentCode": "NA",
"security": {
"is_proxy": false,
"is_vpn": false,
"is_cloud_provider": true
}
}
Key fields you’ll commonly use:
as: The autonomous system identifier and name for routing attribution.ispandorg: Network operator and organization for policy decisions.countryCode,region,city,timezone: Geolocation hints and local time context.security.is_proxy,security.is_vpn,security.is_cloud_provider: Security posture indicators for risk-based controls.
Note: Live flags can change. Use them as signals at request time and cache responsibly.
Integrate with Python
This example calls the same endpoint and extracts the as, ISP and security flags. Replace YOUR_API_KEY with your token from the registration flow.
import os
import requests
API_BASE = "https://ipxapi.com"
ENDPOINT = "/api/ip"
IP = "148.105.12.120" # documented fixture for testing
api_key = os.getenv("IPXAPI_KEY", "YOUR_API_KEY")
url = f"{API_BASE}{ENDPOINT}"
params = {"ip": IP}
headers = {
"Accept": "application/json",
"Authorization": f"Bearer {api_key}",
}
resp = requests.get(url, headers=headers, params=params, timeout=10)
resp.raise_for_status()
data = resp.json()
# Minimal fields for network use-cases
asn = data.get("as") # e.g., "AS14782 MailChimp"
isp = data.get("isp")
org = data.get("org")
country = data.get("countryCode")
region = data.get("region")
city = data.get("city")
tz = data.get("timezone")
sec = data.get("security", {}) or {}
is_proxy = sec.get("is_proxy")
is_vpn = sec.get("is_vpn")
is_cloud = sec.get("is_cloud_provider")
print("ASN:", asn)
print("ISP:", isp)
print("Org:", org)
print("Geo:", country, region, city)
print("Timezone:", tz)
print("Security flags - proxy:", is_proxy, "vpn:", is_vpn, "cloud:", is_cloud)
Request/response semantics that matter in networks
Method: GET. Endpoint path: /api/ip. Query parameter: ip specifies the target IP address. Authentication is via Authorization: Bearer YOUR_API_KEY.
Response data is JSON. The time-related field is timezone, expressed as an IANA identifier (e.g., America/Los_Angeles). Latitude and longitude are decimal degrees. All other fields are strings or booleans as shown in the official sample.
Network applications often normalize ASN and provider fields. If you need to persist as, keep it as the full string, or split on the first space to separate the numeric AS from the name while preserving the original value for audit.
Caching, retries, and throughput
Since ASN and ISP data do not change frequently for a given IP, you can cache successful lookups for hours to days depending on your risk tolerance. Security flags may change more often; if you rely on them, consider a shorter TTL or on-demand revalidation for high-value sessions.
- Client-side caching: Key by the IP address and include a timestamp. Evict or refresh based on your TTL policy.
- Retries: For transient network errors (timeouts, 5xx), use limited retries with exponential backoff. Avoid retrying 4xx responses.
- Timeouts: Set a sensible connect/read timeout (e.g., 5–10 seconds) so your edge logic fails closed or degrades gracefully.
There is no pagination in this endpoint and no streaming behavior. Each call resolves exactly one IP address.
Validation and guardrails
Validate the IP format on the client to avoid unnecessary calls. When building network policies from ASN or ISP fields, treat missing fields as unknown and default to a safe policy. Always log the query field from the response to correlate inputs and outputs in your telemetry.
For access decisions based on security flags, consider combining them with your own heuristics. For example, mark a request as elevated risk if is_proxy is true, or if is_cloud_provider is true and the user session deviates from historical patterns. Use the boolean flags as inputs to a policy engine rather than as sole blockers.
Environments, keys, and plans
Use separate API keys per environment (dev, staging, prod). Inject keys via environment variables and never hard-code them. For CI or local testing, you can rotate a short-lived key and revoke it after use.
Plan overview for budgeting:
- Basic: $29.99/mo
- Trial: 7 days or 50 requests
To obtain a key and start testing, create an account via the registration flow.
Testing via MCP and observability
If you need to validate availability or build monitoring, the control surface is available at MCP. Use it to confirm endpoint health and to align your alerting thresholds. For production, emit structured logs that include the response status, as, and security booleans for correlation.
Practical tips that save time
- Normalize case for country and region codes when storing them; use
countryCodeas-is to avoid mismatches. - Timezone values are IANA names; use a library that supports them directly to avoid manual offset math.
- If your system consumes only ASN numbers, split the
asstring once on space to isolate the leading token. - Never assume the combination of
ispandorgis stable per IP; cache but verify on important sessions. - Respect live variability: security booleans are signals and can change; refresh before enforcing high-impact rules.
FAQ
How do I authenticate requests?
Send Authorization: Bearer YOUR_API_KEY and Accept: application/json headers on every request.
What endpoint should I call for ASN data?
Use GET /api/ip with the ip query parameter, e.g., /api/ip?ip=148.105.12.120.
Which fields identify the ASN owner?
Use as for the ASN identifier and name. You can also use isp and org for operator and organization context.
Are the security flags stable?
They can change. Treat security.is_proxy, security.is_vpn, and security.is_cloud_provider as dynamic indicators and cache with short TTLs if they affect policy.
Is there pagination or batch lookup?
This guide covers the single-IP lookup via /api/ip. For additional patterns, refer to the Documentation.
Next step
Get an API key and run the cURL above in your terminal, then wire the Python snippet into your edge or middleware. Start your 7-day or 50-request trial and move to Basic ($29.99/mo) when you’re ready. Create your account here: Register.
