
ipinfo.io
ipstack
ipgeolocation.io
IP-API.com
ipdata.co
ipwhois.io
IP2Location
Web analytics with IP address lookup and location API

IPQualityScore
ipinfo.io
MaxMind
ZeroBounce
Abstract APIs
Bounceless
DeBounce
Score any IP, email, phone, domain or device in one call. VPN, proxy, Tor, bot and device-fingerprint detection with a 0–100 risk score. Free tier, no card required.

Which is more popular?
Based on our record, ipapi seems to be more popular. It has been mentioned 21 times since March 2021.
Website, pricing, platforms and company facts side by side.
|
|
|
|
|---|---|---|
| Website | ipapi.co | layercall.com |
| Pricing | ||
| Platforms | — | |
| Company | — | 2026 |
| Listed in |
In their own words, as submitted to SaaSHub.


No description of ipapi yet.
LayerCall scores a whole signup in one API call. Most fraud tools answer one question at a time: is this IP a VPN, is this email disposable, is this phone real. LayerCall returns all of them together — IP, email, phone, domain and device — plus the relationships between them, which is where most...
What each product offers, as listed by its team.


Possible disadvantages
An editorial look at what each product does well and who it suits.


Overall verdict
Why this product is good
Recommended for
Developers, businesses, and organizations seeking to enhance their applications with IP geolocation services. It's especially beneficial for projects involving fraud prevention, targeted content delivery, marketing analysis, and user experience customization.
No analysis of LayerCall yet.
Walkthroughs and reviews on video.
How to use the Ipapi API to find information about IP addresses
More videos
No LayerCall videos yet. You could help us improve this page by suggesting one.
How often each product is chosen within a category, 0–100% relative to the other.


As answered by people managing ipapi and LayerCall.
LayerCall's answer:
Most fraud APIs answer one question per call — is this IP a VPN, is this email disposable, is this phone real. LayerCall returns IP, email, phone, domain and device together, and scores the relationships between them. A brand-new domain paired with a datacenter IP and a throwaway mailbox is obvious in combination and unremarkable one field at a time.
Every response also carries the reasoning: a 0–100 risk score, an allow / review / block verdict, and the individual signals behind it, so a decision can be explained rather than only made.
It treats AI agents as a first-class case as well. Web Bot Auth signature verification establishes which agent is calling and whether it can prove it, and a policy engine decides what it is allowed to do — a question classical fraud signals cannot settle, because an agent arrives with a real browser, a real fingerprint and a real mailbox.
LayerCall's answer:
Because of what comes back in the response, not what it costs.
Every result carries a 0–100 risk score, an allow / review / block verdict, and the individual signals behind it — so a decision can be explained to a customer, a colleague or an auditor rather than only made. Strictness is tunable per request without re-scoring, which means the same integration can be strict at signup and forgiving at login.
Two smaller things tend to matter more in production than they sound. When a data source is unavailable, the response says so instead of quietly scoring lower, so an incomplete answer stays distinguishable from a clean one. And test keys return fixed, fictional data that never bills and never touches live reputation data, so a test suite can assert on exact values without polluting anything.
Beyond that, it is worth comparing directly rather than taking our word for it: the live demo runs the real scoring engine with no signup, and the free tier needs no card.
LayerCall's answer:
Developers and small product teams who need a trust decision at signup, login or checkout, and who would rather call one endpoint than integrate several vendors and reconcile their answers by hand.
In practice that means SaaS signups, marketplaces, fintech onboarding, and anyone whose free tier is being farmed by throwaway accounts.
A newer part of the audience is teams who suddenly have to decide what an AI agent may do on their site. That is a different question from classical fraud — an agent can be entirely legitimate and still need a policy — which is why agent verification sits in the same API rather than in a separate product.
LayerCall's answer:
It started from a specific frustration: the signal that actually catches a fake signup is usually a relationship between fields, and the tools available answered one field at a time.
Blocking disposable email domains stops very little on its own. The signups that matter use real mailboxes, often on domains registered days earlier, arriving from addresses that look entirely ordinary. What gives them away is the domain's age set against the IP's provider set against whether the phone is a VoIP line — and assembling that meant several vendors, several response shapes, several bills, and writing the correlation by hand anyway.
LayerCall is that correlation as a product: one call, every signal, and the reasoning returned next to the score.
The AI-agent side came later, from the same observation in a new place. An agent has a real browser, a real fingerprint and a real mailbox, so nothing in a classical fraud stack has an opinion about it. What you need to know is which agent it is and whether it can prove it — a signature problem, not a fraud-signal problem.
LayerCall's answer:
TypeScript on Next.js, running on Vercel's Fluid Compute, with Postgres (Supabase) behind accounts, keys and usage.
The scoring path is deliberately boring. No third-party SDK sits in the request path; every external feed is fetched under its own timeout inside a request-wide deadline, so one slow source cannot hold up a response. A feed that fails degrades the result rather than failing the call, and the response names any signal that was unavailable so the caller can tell the difference between a clean answer and an incomplete one.
On the client side: official Node/TypeScript and Python SDKs, Express and Next.js middleware, a published OpenAPI spec, and an MCP server so AI tools can call the API directly.
Share your experience with using ipapi and LayerCall. For example, how are they different and which one is better?
Recommendations tracked on public social media and blogs since March 2021.


// API 1: ip-api.com (free, no key needed, 45 req/min) $response = $http->get("http://ip-api.com/json/{$ip}?fields=proxy,hosting"); If (!empty($data['proxy']) || !empty($data['hosting'])) { return true; // VPN/Proxy detected } //... - Source: dev.to / 9 months ago
IPapi - Service that provides you an info about an IP address. - Source: dev.to / over 2 years ago
Ipapi - IP Address Location API by Kloudend, Inc - A reliable geolocation API built on AWS, trusted by Fortune 500. The free tier offers 30k lookups/month (1k/day) without signup. - Source: dev.to / over 2 years ago
Tracking LayerCall since Aug 2026.
When comparing ipapi and LayerCall, you can also consider the following products.


IPQualityScore (IPQS) proactively prevents fraud without disrupting the user experience. Access leading fraud prevention tools to detect bots, emulators, VPNs, proxies, stolen user data, and fake users.
Compare IPQualityScore to ipapi or LayerCall:

ipstack is a free, real-time IP address to location JSON API and database service supporting IPv4 and IPv6 lookup.
Compare ipstack to ipapi or LayerCall:

Free IP Geolocation API and Accurate GeoIP Lookup Location Database
Compare ipgeolocation.io to ipapi or LayerCall:

Determine the geographical location of website visitors based on the IP addresses for fraud detection, content localization, geo-targeting.
Compare MaxMind to ipapi or LayerCall:

Free IP Geolocation API - lookup any IP address
Compare IP-API.com to ipapi or LayerCall: