No account required
- No signup or secret to manage
- Good for light scripts, testing and browser requests
- Rate limits use a privacy-preserving client hash
The public v1 API works immediately with no account. A free API key keeps the same endpoints and response format, but raises limits and gives you named, revocable credentials with per-key usage tracking.
Authentication changes your quota and gives requests a revocable identity. It does not unlock a different response format or a separate set of endpoints.
Every v1 JSON endpoint works anonymously or with the same Bearer-token authentication. Copy a request and try it immediately.
/ip
/api/v1/me
/api/v1/lookup?ip=8.8.8.8
/api/v1/dns?host=example.com&type=A
/api/v1/reverse?ip=1.1.1.1
/api/v1/asn?ip=1.1.1.1
/api/v1/inspect?domain=example.com
Anonymous requests need no extra headers. For authenticated requests, keep the secret server-side and send it in the standard Authorization header.
curl "https://ipgetter.com/api/v1/lookup?ip=8.8.8.8"
curl \
-H "Authorization: Bearer ipg_live_YOUR_KEY" \
"https://ipgetter.com/api/v1/lookup?ip=8.8.8.8"
The examples below all perform the same IP lookup. Open only the language you need.
curl "https://ipgetter.com/api/v1/lookup?ip=8.8.8.8"
const res = await fetch('https://ipgetter.com/api/v1/lookup?ip=8.8.8.8');
const data = await res.json();
console.log(data);
import requests
data = requests.get(
'https://ipgetter.com/api/v1/lookup',
params={'ip': '8.8.8.8'},
timeout=10,
).json()
print(data)
$json = file_get_contents(
'https://ipgetter.com/api/v1/lookup?ip=8.8.8.8'
);
$data = json_decode($json, true);
var_dump($data);
Response format, limits, errors, CORS and data-source notes are kept here so they are easy to find without dominating the main flow.
{
"success": true,
"ip": "8.8.8.8",
"version": "IPv4",
"scope": "Public",
"hostname": "dns.google",
"geo": {
"country_code": "US",
"asn": "AS15169",
"organisation": "Google LLC",
"source": "DB-IP Lite"
}
}
{
"success": false,
"error": {
"code": "invalid_ip",
"message": "Provide a valid IPv4 or IPv6 address in the ip parameter."
}
}
Standard endpoints allow 120/minute and 10,000/UTC day anonymously, or 300/minute and 50,000/day with an API key.
Domain Health uses separate limits of 6/minute and 100/day anonymously, or 30/minute and 1,000/day with a key.
Counted requests include X-RateLimit-* response headers. A 429 response also includes Retry-After.
| Status | Code | Meaning |
|---|---|---|
| 400 | invalid_ip | The supplied IP parameter is missing or invalid. |
| 400 | invalid_domain | The supplied domain parameter is missing or invalid. |
| 401 | invalid_api_key | The supplied Bearer token is invalid or revoked. |
| 405 | method_not_allowed | The endpoint was called with a method other than GET or OPTIONS. |
| 429 | rate_limit_exceeded | The applicable per-minute or daily limit has been exceeded. |
CORS: public endpoints send Access-Control-Allow-Origin: * and allow the Authorization header. Secret API keys should still stay in server-side code.
Privacy: anonymous rate limiting uses a one-way server-side client hash. Raw client IP addresses are not stored in IPGetter analytics logs.
Data sources: GeoIP and ASN enrichment comes from IPGetter's managed local Geo Engine using DB-IP Lite with validated monthly updates and rollback protection. Reverse DNS uses the server's configured resolver.
Send the endpoint, response status and a redacted example to support. Never include a full API secret.