IP Intelligence API – Castle
IP Intelligence API
Know the connection behind every IP
Get a complete picture of every IP and its recent connections. Know their types, proxy or VPN operators, even when a residential address hides a proxy exit.
Residential proxy
| Tunnels | Last seen |
|---|---|
| Residential proxy | 1024 Proxy residential |
| Residential proxy | 711 Proxy residential |
| Residential proxy | MangoProxy residential proxies |
| Residential proxy | Novada residential |
| Residential proxy | SwiftProxy residential |
| Show 7 more |
{ "address": "73.162.45.89", "type": "ipv4", "asn": 208172, "location": { "continent_code": "NA", "country_code": "US" }, "tunnels": [ { "type": "proxy", "operator": "1024 Proxy residential", "tier": null, "proxy_type": "residential", "last_seen_at": "2026-07-31T08:11:13.000Z" }, { "type": "proxy", "operator": "711 Proxy residential", "tier": null, "proxy_type": "residential", "last_seen_at": "2026-07-31T06:33:13.000Z" }, { "type": "proxy", "operator": "MangoProxy residential proxies", "tier": null, "proxy_type": "residential", "last_seen_at": "2026-07-30T04:53:23.000Z" }, { "type": "proxy", "operator": "Novada residential", "tier": null, "proxy_type": "residential", "last_seen_at": "2026-07-29T03:48:58.000Z" }, { "type": "proxy", "operator": "SwiftProxy residential", "tier": null, "proxy_type": "residential", "last_seen_at": "2026-07-28T00:07:48.000Z" }, { "type": "proxy", "operator": "Botting Tools residential proxies", "tier": null, "proxy_type": "residential", "last_seen_at": "2026-07-29T18:54:52.000Z" }, { "type": "proxy", "operator": "Plain Proxies residential proxies", "tier": null, "proxy_type": "residential", "last_seen_at": "2026-07-29T11:27:07.000Z" }, { "type": "proxy", "operator": "FlashProxy Lite residential proxies", "tier": null, "proxy_type": "residential", "last_seen_at": "2026-07-25T15:49:55.000Z" }, { "type": "proxy", "operator": "ResiProx residential", "tier": null, "proxy_type": "residential", "last_seen_at": "2026-07-18T09:33:25.000Z" }, { "type": "proxy", "operator": "AnyIP residential", "tier": null, "proxy_type": "residential", "last_seen_at": "2026-07-16T20:49:57.000Z" }, { "type": "proxy", "operator": "FloppyData residential", "tier": null, "proxy_type": "residential", "last_seen_at": "2026-07-14T07:17:32.000Z" }, { "type": "proxy", "operator": "ProxyEmpire residential", "tier": null, "proxy_type": "residential", "last_seen_at": "2026-07-12T14:22:41.000Z" } ]}
Datacenter proxy
| Tunnels | Last seen |
|---|---|
| Datacenter proxy | Bright Data |
| Datacenter proxy | Oxylabs |
| Datacenter proxy | IPRoyal |
| Datacenter proxy | Webshare datacenter proxies |
| Datacenter proxy | Geonode datacenter proxies |
| Show 2 more |
{ "address": "198.51.100.42", "type": "ipv4", "asn": 64500, "location": { "continent_code": "NA", "country_code": "US" }, "tunnels": [ { "type": "proxy", "operator": "Bright Data", "tier": null, "proxy_type": "datacenter", "last_seen_at": "2026-07-30T16:12:08.000Z" }, { "type": "proxy", "operator": "Oxylabs", "tier": null, "proxy_type": "datacenter", "last_seen_at": "2026-07-29T09:44:31.000Z" }, { "type": "proxy", "operator": "IPRoyal", "tier": null, "proxy_type": "datacenter", "last_seen_at": "2026-07-28T21:05:17.000Z" }, { "type": "proxy", "operator": "Webshare datacenter proxies", "tier": null, "proxy_type": "datacenter", "last_seen_at": "2026-07-26T03:35:25.000Z" }, { "type": "proxy", "operator": "Geonode datacenter proxies", "tier": null, "proxy_type": "datacenter", "last_seen_at": "2026-07-23T21:49:41.000Z" }, { "type": "proxy", "operator": "DataImpulse data center proxies", "tier": null, "proxy_type": "datacenter", "last_seen_at": "2026-07-20T20:27:55.000Z" }, { "type": "proxy", "operator": "Thordata datacenter", "tier": null, "proxy_type": "datacenter", "last_seen_at": "2026-07-06T06:10:18.000Z" } ]}
VPN
| Tunnels | Last seen |
|---|---|
| VPN | Urban VPN |
| VPN | NordVPN |
| VPN | Urban VPN |
{ "address": "198.51.100.67", "type": "ipv4", "asn": 64501, "location": { "continent_code": "EU", "country_code": "DE" }, "tunnels": [ { "type": "vpn", "operator": "Urban VPN", "tier": "commercial", "proxy_type": null, "last_seen_at": "2026-07-30T06:46:07.000Z" }, { "type": "vpn", "operator": "NordVPN", "tier": "commercial", "proxy_type": null, "last_seen_at": "2026-07-29T18:32:49.000Z" }, { "type": "vpn", "operator": "Urban VPN", "tier": "commercial", "proxy_type": null, "last_seen_at": "2026-07-27T09:14:36.000Z" } ]}
Relay
| Tunnels | Last seen |
|---|---|
| Relay | iCloud Private Relay |
| Relay | Cloudflare WARP |
| Relay | iCloud Private Relay |
{ "address": "198.51.100.91", "type": "ipv4", "asn": 64502, "location": { "continent_code": "EU", "country_code": "GB" }, "tunnels": [ { "type": "relay", "operator": "iCloud Private Relay", "tier": null, "proxy_type": null, "last_seen_at": "2026-07-30T00:00:00.000Z" }, { "type": "relay", "operator": "Cloudflare WARP", "tier": null, "proxy_type": null, "last_seen_at": "2026-07-29T11:46:22.000Z" }, { "type": "relay", "operator": "iCloud Private Relay", "tier": null, "proxy_type": null, "last_seen_at": "2026-07-28T20:47:16.000Z" } ]}
Tor
| Tunnels | Last seen |
|---|---|
| Tor | Tor network |
| Tor | Tor exit nodes |
{ "address": "198.51.100.118", "type": "ipv4", "asn": 64503, "location": { "continent_code": "EU", "country_code": "NL" }, "tunnels": [ { "type": "tor", "operator": "Tor network", "tier": null, "proxy_type": null, "last_seen_at": "2026-07-30T06:00:24.000Z" }, { "type": "tor", "operator": "Tor exit nodes", "tier": null, "proxy_type": null, "last_seen_at": "2026-07-30T03:00:06.000Z" } ]}
Detect every proxy type
Residential proxies route traffic through ordinary devices on consumer ISPs, so a request can appear to come from a real household. VPNs take a different path: they send traffic through an exit server operated by a company or a consumer provider. One borrows a household connection. The other replaces the original network with shared infrastructure.
Those situations carry different risks. The same residential IP can serve a real customer and a proxy network at the same time, while a corporate VPN can be expected traffic. Most tools collapse both into a single proxy: true flag.
Built for our platform first
We built this intelligence to power our own detection platform, where IP data sits alongside account, device, and behavioral context. Fraud products often buy proxy intelligence as a third-party feed. We needed operator attribution and per-IP observation history at the granularity our own signals use, so we built the core proxy enumeration ourselves.
If you already run risk rules, WAF policies, or feature pipelines in-house, you can use the same underlying intelligence directly.
API Reference
{
"address": "1.0.105.13",
"type": "ipv4",
"asn": 18144,
"location": {
"continent_code": "AS",
"country_code": "JP"
},
"tunnels": [
{
"type": "proxy",
"operator": "FloppyData residential",
"tier": null,
"last_seen_at": "2026-06-25T21:38:40.000Z",
"proxy_type": "residential"
},
{
"type": "proxy",
"operator": "AnyIP residential",
"tier": null,
"last_seen_at": "2026-06-21T22:55:42.000Z",
"proxy_type": "residential"
}
]
}
Flat, flexible pricing
We offer simple, predictable pricing with a generous free tier for you to try it out without commitment.
$0.001 per request
$5 API budget included free
100ms response time
99.99% uptime
SOC 2 Type II compliance
GDPR-ready compliance
Get Started Now
Start with a free quota, with transparent pricing that scales when you do.