Developer API

Start without a key. Add one when you need more.

The public v1 API works immediately with no account. A free API key keeps the same endpoints and response format, but raises limits and gives you named, revocable credentials with per-key usage tracking.

Choose your access level

Same API. Different allowance.

Authentication changes your quota and gives requests a revocable identity. It does not unlock a different response format or a separate set of endpoints.

Anonymous

No account required

Start now
Standard API120/min10,000/day
Domain Health6/min100/day
  • No signup or secret to manage
  • Good for light scripts, testing and browser requests
  • Rate limits use a privacy-preserving client hash
Use anonymously ->
Free API key

More room for apps

Higher limits
Standard API300/min50,000/day
Domain Health30/min1,000/day
  • Named and individually revocable keys
  • Per-key request counts and last-used visibility
  • Better fit for integrations, apps and automation
Create a free key ->
Endpoints

Pick the data you need.

Every v1 JSON endpoint works anonymously or with the same Bearer-token authentication. Copy a request and try it immediately.

TEXT /ip
Your public IP Plain-text caller IP for tiny scripts and health checks.
GET /api/v1/me
Your network details Caller IP, hostname, protocol, GeoIP and ASN details.
GET /api/v1/lookup?ip=8.8.8.8
IP lookup Scope, reverse DNS, GeoIP and ASN data for an IPv4 or IPv6 address.
GET /api/v1/dns?host=example.com&type=A
DNS lookup A, AAAA, MX, TXT, NS and CNAME records with structured values and TTLs.
GET /api/v1/reverse?ip=1.1.1.1
Reverse DNS PTR hostname for a valid IPv4 or IPv6 address.
GET /api/v1/asn?ip=1.1.1.1
ASN / network owner Autonomous system number and network organisation for an IP address.
GET /api/v1/inspect?domain=example.com
Domain Health DNS, HTTPS, headers, mail authentication, DNSSEC, CAA, crawler files and registration data.
Authentication

No key by default. Bearer token when you want one.

Anonymous requests need no extra headers. For authenticated requests, keep the secret server-side and send it in the standard Authorization header.

Anonymous

Nothing to configure.

curl "https://ipgetter.com/api/v1/lookup?ip=8.8.8.8"
Free API key

Add one header.

curl \
  -H "Authorization: Bearer ipg_live_YOUR_KEY" \
  "https://ipgetter.com/api/v1/lookup?ip=8.8.8.8"
Keep secrets server-side. Do not publish API keys in browser JavaScript. IPGetter stores only a hash of each key, shows the full secret once and lets you revoke keys independently.
Quick examples

Use the API from whatever you already have.

The examples below all perform the same IP lookup. Open only the language you need.

cURLExample
cURL
curl "https://ipgetter.com/api/v1/lookup?ip=8.8.8.8"
JavaScriptExample
JavaScript
const res = await fetch('https://ipgetter.com/api/v1/lookup?ip=8.8.8.8');
const data = await res.json();
console.log(data);
PythonExample
Python
import requests

data = requests.get(
    'https://ipgetter.com/api/v1/lookup',
    params={'ip': '8.8.8.8'},
    timeout=10,
).json()
print(data)
PHPExample
PHP
$json = file_get_contents(
    'https://ipgetter.com/api/v1/lookup?ip=8.8.8.8'
);
$data = json_decode($json, true);
var_dump($data);
Reference

Details when you need them.

Response format, limits, errors, CORS and data-source notes are kept here so they are easy to find without dominating the main flow.

Response formatJSON success and error shapes

Successful lookup

{
  "success": true,
  "ip": "8.8.8.8",
  "version": "IPv4",
  "scope": "Public",
  "hostname": "dns.google",
  "geo": {
    "country_code": "US",
    "asn": "AS15169",
    "organisation": "Google LLC",
    "source": "DB-IP Lite"
  }
}

Validation error

{
  "success": false,
  "error": {
    "code": "invalid_ip",
    "message": "Provide a valid IPv4 or IPv6 address in the ip parameter."
  }
}
Limits and rate headersQuotas, reset information and 429 behaviour

Standard endpoints allow 120/minute and 10,000/UTC day anonymously, or 300/minute and 50,000/day with an API key.

Domain Health uses separate limits of 6/minute and 100/day anonymously, or 30/minute and 1,000/day with a key.

Counted requests include X-RateLimit-* response headers. A 429 response also includes Retry-After.

ErrorsStatus codes and machine-readable error codes
StatusCodeMeaning
400invalid_ipThe supplied IP parameter is missing or invalid.
400invalid_domainThe supplied domain parameter is missing or invalid.
401invalid_api_keyThe supplied Bearer token is invalid or revoked.
405method_not_allowedThe endpoint was called with a method other than GET or OPTIONS.
429rate_limit_exceededThe applicable per-minute or daily limit has been exceeded.
CORS, privacy and data sourcesBrowser access and how requests are handled

CORS: public endpoints send Access-Control-Allow-Origin: * and allow the Authorization header. Secret API keys should still stay in server-side code.

Privacy: anonymous rate limiting uses a one-way server-side client hash. Raw client IP addresses are not stored in IPGetter analytics logs.

Data sources: GeoIP and ASN enrichment comes from IPGetter's managed local Geo Engine using DB-IP Lite with validated monthly updates and rollback protection. Reverse DNS uses the server's configured resolver.

Need a hand?

API questions and integration help.

Send the endpoint, response status and a redacted example to support. Never include a full API secret.

Contact support