IP-API.com
ipinfo.io
ipapi
ipgeolocation.io
ipstack
ipdata.co
ipwhois.io
IP2Location
LayerCall
IPQualityScore
ipinfo.io
MaxMind
ZeroBounce
Abstract APIs
Bounceless
DeBounce
A simple to integrate Geolocation API that provides information about your users, either directly from a browser or device, or from any of your servers.
Provides data such as City, Region, Postal code, Country, Continent, Coordinates, Timezone, Currency, Organization, ISP, AS, if they are using a mobile network, or an anonymous proxy/VPN.
Works with IPv4, IPv6 or hostnames. Supports batch requests with up to 100 queries per HTTP request.
The free version requires no sign up or keys, and it's limited to 45 HTTP requests per minute from an IP address. Non-commercial use only.
The pro service includes more features such as SLA for 99.9% of monthly uptime, a dashboard with usage statistics, up to 10 API keys (customizable with restrictions), and more.
LayerCall scores a whole signup in one API call.
Most fraud tools answer one question at a time: is this IP a VPN, is this email disposable, is this phone real. LayerCall returns all of them together โ IP, email, phone, domain and device โ plus the relationships between them, which is where most fake signups actually show up. A brand-new domain paired with a datacenter IP and a throwaway mailbox is obvious in combination and unremarkable one field at a time.
Every response carries a 0โ100 risk score, an allow / review / block verdict, and the individual signals behind it, so a decision can be explained rather than just made. Strictness is tunable per request without re-scoring, and when a data source is unavailable the response says so rather than quietly scoring lower.
It also authorizes AI agents. Web Bot Auth signature verification tells you which agent is calling and whether it can prove it, and a policy engine decides what it may do โ a question classical fraud signals cannot answer, because an agent arrives with a real browser, a real fingerprint and a real mailbox.
Built for developers. REST, an MCP server for AI tooling, official Node and Python SDKs, a live demo that needs no signup, and a free tier that needs no card.
IP-API.com
LayerCallLayerCall's answer:
Most fraud APIs answer one question per call โ is this IP a VPN, is this email disposable, is this phone real. LayerCall returns IP, email, phone, domain and device together, and scores the relationships between them. A brand-new domain paired with a datacenter IP and a throwaway mailbox is obvious in combination and unremarkable one field at a time.
Every response also carries the reasoning: a 0โ100 risk score, an allow / review / block verdict, and the individual signals behind it, so a decision can be explained rather than only made.
It treats AI agents as a first-class case as well. Web Bot Auth signature verification establishes which agent is calling and whether it can prove it, and a policy engine decides what it is allowed to do โ a question classical fraud signals cannot settle, because an agent arrives with a real browser, a real fingerprint and a real mailbox.
LayerCall's answer:
Because of what comes back in the response, not what it costs.
Every result carries a 0โ100 risk score, an allow / review / block verdict, and the individual signals behind it โ so a decision can be explained to a customer, a colleague or an auditor rather than only made. Strictness is tunable per request without re-scoring, which means the same integration can be strict at signup and forgiving at login.
Two smaller things tend to matter more in production than they sound. When a data source is unavailable, the response says so instead of quietly scoring lower, so an incomplete answer stays distinguishable from a clean one. And test keys return fixed, fictional data that never bills and never touches live reputation data, so a test suite can assert on exact values without polluting anything.
Beyond that, it is worth comparing directly rather than taking our word for it: the live demo runs the real scoring engine with no signup, and the free tier needs no card.
LayerCall's answer:
Developers and small product teams who need a trust decision at signup, login or checkout, and who would rather call one endpoint than integrate several vendors and reconcile their answers by hand.
In practice that means SaaS signups, marketplaces, fintech onboarding, and anyone whose free tier is being farmed by throwaway accounts.
A newer part of the audience is teams who suddenly have to decide what an AI agent may do on their site. That is a different question from classical fraud โ an agent can be entirely legitimate and still need a policy โ which is why agent verification sits in the same API rather than in a separate product.
LayerCall's answer:
It started from a specific frustration: the signal that actually catches a fake signup is usually a relationship between fields, and the tools available answered one field at a time.
Blocking disposable email domains stops very little on its own. The signups that matter use real mailboxes, often on domains registered days earlier, arriving from addresses that look entirely ordinary. What gives them away is the domain's age set against the IP's provider set against whether the phone is a VoIP line โ and assembling that meant several vendors, several response shapes, several bills, and writing the correlation by hand anyway.
LayerCall is that correlation as a product: one call, every signal, and the reasoning returned next to the score.
The AI-agent side came later, from the same observation in a new place. An agent has a real browser, a real fingerprint and a real mailbox, so nothing in a classical fraud stack has an opinion about it. What you need to know is which agent it is and whether it can prove it โ a signature problem, not a fraud-signal problem.
LayerCall's answer:
TypeScript on Next.js, running on Vercel's Fluid Compute, with Postgres (Supabase) behind accounts, keys and usage.
The scoring path is deliberately boring. No third-party SDK sits in the request path; every external feed is fetched under its own timeout inside a request-wide deadline, so one slow source cannot hold up a response. A feed that fails degrades the result rather than failing the call, and the response names any signal that was unavailable so the caller can tell the difference between a clean answer and an incomplete one.
On the client side: official Node/TypeScript and Python SDKs, Express and Next.js middleware, a published OpenAPI spec, and an MCP server so AI tools can call the API directly.
Based on our record, IP-API.com seems to be more popular. It has been mentiond 34 times since March 2021. We are tracking product recommendations and mentions on various public social media platforms and blogs. They can help you identify which product is more popular and what people think of it.
Free public geo APIs do not love datacenter traffic. My first instinct was to use ip-api.com โ itโs the go-to for โwhat country is this IPโ lookups and has a generous free tier. Hooked it up, ran the direct profile, got a clean response. Then I ran it through the Bright Data proxies I had (these) and got a HTTP 402. Turns out ip-api.comโs free tier detects any datacenter egress and refuses to serve it. The proxy... - Source: dev.to / 2 months ago
The original version used http://ip-api.com โ plain HTTP. On a cloud server, that traffic is unencrypted and could be intercepted and spoofed. I switched to https://ipinfo.io which supports HTTPS on the free tier. - Source: dev.to / 5 months ago
In this example, I'll process messages based on their originating IP address. Multiple threads will enrich them with location data fetched from the public API at https://ip-api.com/. - Source: dev.to / 8 months ago
Ip-api โ IP Geolocation API, Free for non-commercial use, no API key required, limited to 45 req/minute from the same IP address for the free plan. - Source: dev.to / over 2 years ago
The Language may be different: You can check up the [Set language based on IP], and make the system automatically set up the browser language according to the IP that you set up. Mismatch of DNS or system time: We recommend you to replace the proxy IP and start the operation. Or you can enter the site https://ip-api.com for verification. Source: over 2 years ago
ipinfo.io - Simple IP address information.
IPQualityScore - IPQualityScore (IPQS) proactively prevents fraud without disrupting the user experience. Access leading fraud prevention tools to detect bots, emulators, VPNs, proxies, stolen user data, and fake users.
ipapi - Web analytics with IP address lookup and location API
ipgeolocation.io - Free IP Geolocation API and Accurate GeoIP Lookup Location Database
MaxMind - Determine the geographical location of website visitors based on the IP addresses for fraud detection, content localization, geo-targeting.
ipstack - ipstack is a free, real-time IP address to location JSON API and database service supporting IPv4 and IPv6 lookup.