Docs / Options
VPN and Proxy Detection
Add the security module to an IP request to learn whether the visitor is hiding behind a VPN, proxy or Tor.
Enabling the module#
Both IP Geolocation and IP Lookup accept params=security.
curl "https://gurdx.cretip.com/api/geoip?key=YOUR_API_KEY¶ms=security"
curl "https://gurdx.cretip.com/api/lookup/ip?key=YOUR_API_KEY&ip=198.51.100.23¶ms=security"
$res = Http::withToken(env('GURDX_KEY'))
->get('https://gurdx.cretip.com/api/lookup/ip', ['ip' => $ip, 'params' => 'security'])
->json();
if (($res['data']['security']['vpn'] ?? false) || ($res['data']['security']['tor'] ?? false)) {
// ask for additional verification
}
What you get#
The security object reports anonymization and threat signals for the address, such as proxy, VPN, Tor and known bad-reputation flags. For a deeper reputation score and the list of threat categories, use IP Reputation.
{
"data": {
"ip": "198.51.100.23",
"security": {
"proxy": true,
"vpn": false,
"tor": false
}
},
"status": "success",
"executionTime": 21
}
The exact fields are listed on the IP Lookup page.
Plan requirement#
The security module is a plan feature. Without it, the request fails with error 114:
{
"status": "error",
"code": 114,
"type": "security_module_not_allowed",
"description": "You cannot use the security module in your plan. Please upgrade your API plan to unlock this feature."
}
Events and automation#
Suspicious IPs are scored from 0 to 100. In live mode, a score of 50 or higher raises a suspicious_ip event that appears in the dashboard and is sent to your webhooks and integrations. Test mode never raises events. You can also add your own custom rules and blacklists in the dashboard to override the outcome.
How to use the result#
| Signal | Suggested reaction |
|---|---|
| Tor or open proxy on a sensitive action | Block or require strong verification |
| Commercial VPN on sign-up | Allow, but add friction such as email confirmation |
| Clean IP | Proceed normally |
Note: A VPN is not proof of fraud. Many legitimate users have one. Combine this signal with email, phone and payment scoring before blocking.
Found a mistake? Tell us on the contact page. Contact