IP Intelligence API
Over the past months, we shipped residential proxy detection and VPN detection as signals on the Risk API. The data behind those signals is now a product of its own. Instead of sending an event and reading the signals on the response, you can query an IP directly and get the raw intelligence back:
GET /v1/ips/{value}looks up a single IP in real timePOST /v1/ips/queryresolves many at onceGET /v1/ips/downloads/{dataset}/{window}.{format}.gzgives you precomputed snapshots
For any IP, you get the autonomous system it belongs to, a coarse location, and the proxy and VPN tunnels Castle has recently observed on it. Each tunnel carries the operator running it, a tier for VPN providers, and a last_seen_at timestamp for when we last confirmed activity on that network.
Use lookups to enrich your own systems and feed your own risk logic. Download full datasets to use Castle's data for bulk enrichment or offline analysis.
Full details are in the documentation.
Example request:
curl -sSf -u ":$CASTLE_API_SECRET" \
https://api.castle.io/v1/ips/1.0.105.13{
"address": "1.0.105.13",
"type": "ipv4",
"asn": 18144,
"location": {
"continent_code": "AS",
"country_code": "JP"
},
"tunnels": [
{
"type": "proxy",
"operator": "FloppyData residential",
"tier": null,
"last_seen_at": "2026-06-25T21:38:40.000Z",
"proxy_type": "residential"
},
{
"type": "proxy",
"operator": "AnyIP residential",
"tier": null,
"last_seen_at": "2026-06-21T22:55:42.000Z",
"proxy_type": "residential"
}
]
}