Watch-IP
IP, email & login-risk API

IP geolocation, email checks and login-risk signals from one API.

Locate website visitors from the browser, look up IP addresses from your backend, check signup emails for disposable domains and typos, and flag impossible travel at login — all on one plan and one monthly request allowance. The card previews this page request's edge data and local enrichment; it is not an API response.

Page-request edge previewrequest.cf
Columbus, OH, US

216.73.217.115

Map showing a marker over Columbus
Coordinates
39.9612, -82.9988
Timezone
America/New_York
Postal code
43215
Continent
NA
Network
Anthropic, PBC
ASN
AS16509
Currency
$ USD
Calling code
+1
Sunrise / sunset
7:24 AM / 7:19 PM
Device
—
Security
Unavailable — not checked

Choose the API for your task

Locate the visitor on your website

Call the visitor geolocation API directly from the browser with a publishable key restricted to your allowed origins. Use approximate country and city data, timezone, and available regional context to suggest a more relevant experience.

Explore visitor geolocation →

Look up an IP from your backend

Already have an IP address in your application? Send it to the IP lookup endpoint from your server. A secret key authenticates the request, and the response contains location fields from a third-party IP geolocation database.

Explore the IP lookup API →

Process a list of IP addresses

Send up to 100 IP addresses in one batch request and receive an ordered list of lookup results for reporting, enrichment, and other backend workflows. Lookup usage is measured per IP, not per batch request.

Explore bulk IP lookup →

Check email addresses at signup

Check syntax, known disposable domains, whether the domain has a mail server, likely typos and role addresses, and get an accept, review or reject verdict with reasons. Call it from your form with a publishable key, or check up to 100 addresses per request — or lists of up to 100,000 — from your backend or the dashboard.

Explore email checks →

Score a new signup in one call

POST /v1/signup/check combines the email check with the signing-up IP's country, network and plan-dependent VPN, Tor and datacenter indicators, plus the email domain's age, into a 0–100 score and verdict with reasons. The score is context for your decision, not proof of abuse.

See the signup-abuse workflow →

Flag impossible travel at login

POST /v1/risk/check compares a login IP's approximate location with the user's previous stored location and returns distance, elapsed time, implied speed and a risk level. It can produce false positives and does not prove account takeover.

Explore impossible-travel detection →

Browser integration example and edge preview

The example shows how to call GET /v1/geo from a browser. It was not executed to produce this preview. Location comes from this page request; enrichment is derived locally. Missing values are unavailable, and security checks are not run.

Example request — not executed

import { WatchIP } from "@digitload/watch-ip-sdk";

const client = new WatchIP("wip_pub_xxxxxxxx");
const { country, city, timezone, currency, callingCode } = await client.getGeo();

Page-request preview — not an API response

{
  "ip": "216.73.217.115",
  "country": "US",
  "region": "Ohio",
  "regionCode": "OH",
  "city": "Columbus",
  "postalCode": "43215",
  "latitude": 39.96118,
  "longitude": -82.99879,
  "continent": "NA",
  "timezone": "America/New_York",
  "isEUCountry": false,
  "asn": 16509,
  "asOrganization": "Anthropic, PBC",
  "currency": {
    "code": "USD",
    "name": "US Dollar",
    "symbol": "$"
  },
  "callingCode": "+1",
  "compliance": {
    "isGDPR": false,
    "usPrivacyLaw": null,
    "isLGPD": false,
    "requiresCookieConsent": false,
    "dataResidencyZone": "US",
    "isEmbargoedCountry": false
  },
  "locale": {
    "suggestedLocale": "en-US",
    "measurementSystem": "imperial",
    "firstDayOfWeek": 0,
    "dateFormat": "MM/DD/YYYY"
  },
  "sun": {
    "sunrise": "2026-09-29T11:24:51.406Z",
    "sunset": "2026-09-29T23:19:33.268Z"
  },
  "holiday": {
    "isPublicHolidayToday": false,
    "todayHolidayName": null,
    "nextHoliday": {
      "date": "2026-10-12",
      "name": "Columbus Day"
    }
  },
  "age": {
    "ageOfMajority": 18,
    "drinkingAge": 21,
    "adultContentVerificationRequired": true,
    "jurisdictionNote": "HB 96 (2025)"
  },
  "tax": {
    "jurisdictionCode": "US-OH",
    "taxSystem": "US_SALES_TAX",
    "rate": null
  },
  "userAgent": {
    "browser": null,
    "browserVersion": null,
    "os": null,
    "osVersion": null,
    "deviceType": "bot"
  }
}

Visitor and backend geolocation

Use GET /v1/geo in the visitor’s browser with a publishable key. Use GET /v1/lookup/{ip} or POST /v1/lookup on your backend with a secret key for supplied IPs.

One plan for every check

Geolocation, IP lookup, email, signup and impossible-travel checks all draw from the same monthly request allowance — one request per call, checked IP or checked address. There is no separate product to buy, and every plan, including Free, can issue both key types.

Domain-level email checks

Email checks look at syntax, the domain's disposable status and mail-server records, likely typos and role addresses. They never contact the mailbox, so no result confirms that an address exists or can receive mail.

Origin-locked keys

Your API key is publishable, like a Stripe or Google Maps key. Requests are only served — and CORS only granted — to the origins you register.

Edge geolocation

GET /v1/geo reads network-level location data for the connecting IP. IP location is approximate; response time depends on the request and enabled features.

Regional enrichment

Visitor responses derive currency, calling code, sun times, and device hints from location and request headers. Fields can be null when source data is unavailable.

Regional compliance hints

Static country and region mappings provide compliance hints. They do not establish legal obligations or guarantee compliance.

Locale negotiation, done for you

Every response includes a locale object: the best-fit BCP47 locale (combining the visitor's country with their browser's Accept-Language header, so a French-language visitor in Canada gets fr-CA, not fr-FR), plus measurement system, first day of week, and date format — skip re-implementing this in your own i18n layer.

Public holiday calendar

Every response includes a holiday object: whether today is a public holiday in the visitor's country, its name, and the next upcoming one — handy for "we're closed today" support-widget copy, checkout messaging, or scheduling logic, covering a curated ~40-country list.

Age jurisdiction hints

Static mappings provide age and jurisdiction hints based on approximate IP location. They do not verify identity or age; confirm applicable requirements independently.

Tax jurisdiction hints

Static mappings provide regional tax context. They are not a tax calculation or a substitute for a maintained tax engine.

SDK source packages

The repository includes JavaScript/TypeScript, Python, PHP, Go, and Flutter/Dart clients. Endpoint support varies; see the docs and verify package availability before installation.

VPN, Tor & network signals

Eligible visitor plans include list-based VPN, Tor, datacenter, threat, and sanctioned-network indicators. A false flag means no match in available data, not a safe visitor. IPv6 coverage is partial; IPv6 Tor is not covered.

Branded subdomains

Growth and Scale include a custom-domain setup path in the dashboard. Availability depends on account eligibility and successful DNS and SSL setup; integrations must use the configured base URL.

Impossible-travel signal

POST /v1/risk/check compares a supplied IP’s approximate location with a stored user baseline. It can produce false positives and does not prove account takeover. Available to any account with a secret API key — it draws down your existing plan's monthly request cap, with no separate price or signup.

Understand the response before you integrate

The visitor and lookup APIs serve different requests and return different data. Visitor geo uses the connecting request's edge geolocation and adds regional context. IP lookup resolves the address you supply using a third-party IP geolocation database plus a separately compiled GeoNames index for subdivision names and postal codes. Lookup responses do not contain every field visitor geo does — for example, ASN comes from a different, less current database, and location is only ever as fresh as each database's own release cadence. Email, signup and risk checks each take the input you send — an address, or a user ID and IP — and every row below draws from the same monthly request allowance.

Your taskEndpointKeyData focus
Locate the connecting website visitorGET /v1/geoPublishable, origin-restrictedVisitor location and regional context
Look up one supplied IPGET /v1/lookup/{ip}Secret Bearer keyThird-party IP geolocation database location result
Look up several supplied IPsPOST /v1/lookupSecret Bearer keyUp to 100 ordered location results
Check an email address in a signup formPOST /v1/email/validatePublishable, origin-restrictedSyntax, disposable-domain, mail-server and typo signals with a verdict
Check email addresses in bulkPOST /v1/email/batch, /v1/email/jobsSecret Bearer keyUp to 100 per request, or up to 100,000 per asynchronous list job
Score a new signupPOST /v1/signup/checkSecret Bearer key0–100 score from email, IP network and domain-age signals
Compare a login with the previous locationPOST /v1/risk/checkSecret Bearer keyDistance, implied speed and impossible-travel flag

Frequently asked questions

Can Watch-IP geolocate an IP address I provide?

Yes. Use the server-side IP lookup API with a secret key. The browser visitor endpoint locates the connecting client and does not accept an arbitrary IP to look up.

Can I use Watch-IP from JavaScript in a browser?

Use visitor geo with a publishable key configured for your website's origin. Secret lookup keys belong on your backend and should never appear in browser code.

Is IP geolocation the same as the browser's Geolocation API?

No. Watch-IP estimates location from an IP connection. The browser's Geolocation API is a separate mechanism that can request permission for device-provided location.

Can I look up IPv4 and IPv6 addresses?

The lookup endpoints accept valid IPv4 and IPv6 addresses, subject to available database records. Security-signal coverage is a separate question and varies by indicator and IP version.

Does Watch-IP have a free plan?

Yes. The Free plan includes a monthly request allowance plus a smaller IP-lookup allowance; see the pricing page for current limits. Email, signup and impossible-travel checks draw from the same allowance, with no separate plan.

Does the email check verify that a mailbox exists?

No. Watch-IP checks syntax, the domain (disposable lists, mail-server records, age) and address patterns such as typos and role accounts. It does not contact the mail server, so no result confirms that a mailbox exists or can receive mail.

Do email and risk checks need a separate plan?

No. Each checked address, signup check or impossible-travel check counts as one request against the same monthly allowance as your geolocation and lookup calls. Backend endpoints use a secret key issued from your dashboard.

Does a false security flag mean the visitor is safe?

No. It means the check did not find a match in the data it uses. Missing coverage, unlisted networks, and unavailable signals must be considered separately.

Choose your first integration

Start with the visitor guide for a website, the lookup product page for a backend application, or the email check for your signup form.