Choose a plan for the API you need
One plan covers every API: visitor geolocation and email checks from the browser (publishable key), plus IP lookup, bulk email, signup and impossible-travel checks from your backend (secret key). Every tier includes an IP lookup allowance alongside its shared request cap, at the same price.
Plans
Every plan bundles one monthly request cap shared by every API — visitor geolocation, IP lookup, email, signup and impossible-travel checks — plus a separate ceiling on IP lookups (secret backend key; batches accept up to 100 IPs and each IP looked up counts as one request), at one price.
Free
Try it on a side project.
$0/mo
10,000 requests included / month
30/min sustained rate limit
500 IP lookups included / month
- 10,000 requests / month
- 500 IP lookups / month
- Email and signup checks (1 request per address)
- Impossible-travel checks (1 request each)
- 1 origin domain
- Community support
Starter
For small production apps.
$9/mo
or $97.2/yr — save 10%
250,000 requests included / month
120/min sustained rate limit
≈ $0.036 / 1,000 requests
50,000 IP lookups included / month
≈ $0.18 / 1,000 lookups
- 250,000 requests / month
- 50,000 IP lookups / month
- Email and signup checks (1 request per address)
- Impossible-travel checks (1 request each)
- Multiple origin domains
- VPN/Tor/threat detection
- Email support
Growth
For growing products.
$29/mo
or $313.2/yr — save 10%
1,500,000 requests included / month
300/min sustained rate limit
≈ $0.019 / 1,000 requests
300,000 IP lookups included / month
≈ $0.10 / 1,000 lookups
- 1,500,000 requests / month
- 300,000 IP lookups / month
- Email and signup checks (1 request per address)
- Impossible-travel checks (1 request each)
- Multiple origin domains
- VPN/Tor/threat detection
- Priority email support
Scale
For high-traffic sites.
$79/mo
or $853.2/yr — save 10%
5,000,000 requests included / month
600/min sustained rate limit
≈ $0.016 / 1,000 requests
1,000,000 IP lookups included / month
≈ $0.08 / 1,000 lookups
- 5,000,000 requests / month
- 1,000,000 IP lookups / month
- Email and signup checks (1 request per address)
- Impossible-travel checks (1 request each)
- Multiple origin domains
- VPN/Tor/threat detection
- Priority support
Enterprise
Custom volume, SLA, and support.
Custom
Custom requests included / month
Custom sustained rate limit
Custom IP lookups included / month
- Custom request volume
- Custom IP lookup volume
- Email and signup checks (1 request per address)
- Impossible-travel checks (1 request each)
- Multiple origins + SLA
- VPN/Tor/threat detection
- Priority support
What each API includes
The APIs do not share one response shape. Compare endpoint, key, data source, and billing unit before you integrate.
| Product | Endpoint | Key | Data source | Enrichment | Security fields | Billing unit |
|---|---|---|---|---|---|---|
| Visitor geolocation | GET /v1/geo | Publishable, origin-restricted | Network-level request data | Currency, locale, holidays, compliance hints | Eligible plans only | Per successful request |
| IP lookup | GET /v1/lookup/{ip} | Secret Bearer key | Third-party IP geolocation database | Currency, locale, holidays, compliance hints derived from the looked-up location | Eligible plans only | Per looked-up IP |
| Bulk IP lookup | POST /v1/lookup | Secret Bearer key | Third-party IP geolocation database | Currency, locale, holidays, compliance hints derived from the looked-up location | Eligible plans only | Per looked-up IP, up to 100 per request |
| Email check | POST /v1/email/validate | Publishable, origin-restricted — same key as GET /v1/geo | Syntax, disposable-domain lists, DNS mail-server lookup | Typo suggestion, role and free-provider flags, verdict with reasons | Not included | Per checked address, against your plan's request cap |
| Bulk email check | POST /v1/email/batch, POST /v1/email/jobs | Secret Bearer key | Same as email check | Same as email check; list jobs return a CSV | Not included | Per checked address (up to 100 per batch, 100,000 per list job; duplicates in a job charged once) |
| Signup check | POST /v1/signup/check | Secret Bearer key | Email check plus the IP's network indicators and domain registration age | 0–100 score, verdict with reasons | Eligible plans only | Per call, against your plan's request cap |
| Impossible travel check | POST /v1/risk/check | Secret Bearer key — same key as IP lookup | Third-party IP geolocation vs. one stored per-user baseline | None — risk and travel fields only | Not included | Per check, against your plan's request cap |
Compare plans
The breakdown above, side by side.
| Plan | Requests / mo | Lookups / mo | Rate limit | Origins | Support | Price |
|---|---|---|---|---|---|---|
| Free | 10,000 | 500 | 30/min | 1 | Community | $0/mo |
| Starter | 250,000 | 50,000 | 120/min | Multiple | $9/mo | |
| Growth | 1,500,000 | 300,000 | 300/min | Multiple | Priority email | $29/mo |
| Scale | 5,000,000 | 1,000,000 | 600/min | Multiple | Priority | $79/mo |
| Enterprise | Custom | Custom | Custom | Custom | Priority + SLA | Custom |
Frequently asked questions
What counts as a request?
Each authenticated call that passes your key and origin checks counts as one request: a visitor geolocation call, each IP looked up, each email address checked, each signup check and each impossible-travel check. A call that then fails input validation still counts. Calls rejected for a missing or invalid key, a disallowed origin or the per-minute rate limit don't count, and neither do deleting a risk baseline or polling an email list job.
What does the rate limit (e.g. "30/min") actually mean?
It's a fixed one-minute window, aligned to the clock minute — not a rolling average. On the Free plan you can make up to 30 requests between, say, 10:32:00 and 10:32:59; the counter resets to zero at 10:33:00. Going over returns an HTTP 429 with a Retry-After header telling you how many seconds until the window resets. It's independent from your monthly request volume below — it caps burst rate, not total usage. The limit counts API calls, not items: a batch of up to 100 IPs or email addresses, or creating an email list job, is one request toward it — while each IP or address in it still counts separately toward your monthly request volume.
What happens if I go over my monthly request volume?
Requests are rejected in real time once your plan's monthly cap is reached — you'll get a 429 with error: "monthly_limit_exceeded" until the next monthly window starts or you upgrade. We email you at 75%, 90%, and 100% of your cap so this shouldn't be a surprise. If you're consistently running close to the limit, upgrade any time from your dashboard — no code or API key changes needed.
Why is Watch-IP cheaper than other IP geolocation APIs?
Visitor geolocation reads edge request data and derives regional enrichment locally, which keeps its cost — and price — well under most providers' equivalent tiers. Server-side IP lookup is bundled into the same plan and price rather than sold separately: each plan includes both a request cap and an IP lookup allowance drawn from that plan's shared monthly pool.
Besides location, what else does the API return?
Visitor geolocation and IP lookup responses include regional enrichment where source data is available. Eligible plans also include list-based security indicators. Email checks return a separate, domain-level result. Latency varies by request and enabled features.
Can I look up an arbitrary IP address, not just my own site's visitors?
Yes. GET /v1/geo remains visitor self-lookup only, resolving the IP that's actually connecting, client-side. For arbitrary-IP lookup, GET /v1/lookup/{ip} (single) and POST /v1/lookup (batch, up to 100 IPs per call) are server-to-server endpoints authenticated with a secret key instead of your publishable one — the key stays on your backend and is never shipped to a browser. Both are backed by a third-party IP geolocation database rather than our own real-time network data, with a different response shape and no verified relative-accuracy ranking — see data sources for the specific provider and required attribution — and usage is priced per IP looked up, drawn from your plan's shared monthly pool 1-for-1 with a geo request (see your plan's IP lookup allowance above for the separate cap on total lookups). Because this endpoint looks up IPs your customer supplies rather than the visitor calling on their own behalf, it makes Watch-IP a processor of that third-party data on your behalf — see the DPA for what that means for your own compliance obligations.
Can you detect impossible travel / account takeover for my users?
POST /v1/risk/check compares a supplied IP’s third-party-resolved location with a stored user baseline and returns low/medium/high risk and an impossibleTravel flag. It uses a backend Bearer secret key — the same secret key you already use for IP lookup, on the same plan. There's no separate risk plan or price: each check counts as one request against your existing plan's monthly cap. You can also delete a stored baseline at any time via DELETE /v1/risk/baseline. VPN changes and mobile routing can cause false positives.
Can you flag disposable or throwaway email addresses on my signup form?
Yes. POST /v1/email/validate uses a publishable, origin-locked key to check syntax, known disposable domains, whether the domain has a mail server, likely typos and role addresses, and returns an accept, review or reject verdict with reasons. From your backend, POST /v1/email/batch checks up to 100 addresses per call, list jobs handle up to 100,000, and POST /v1/signup/check adds the signing-up IP's network signals. Each checked address counts as one request against your plan's monthly cap (a list job charges each distinct address once). None of these contact the mailbox, so they do not verify mailbox existence, ownership or deliverability.
Is my API key a secret I need to protect?
It depends on the key type. Publishable keys — used for GET /v1/geo and POST /v1/email/validate — are meant to ship in page source, like a Stripe or Google Maps publishable key; the access control is origin-locking: each key only works from the domains you register, and CORS is only granted to a matching origin. Secret keys — used for IP lookup, bulk email, signup and impossible-travel checks — must stay on your backend and never appear in browser code.
Is there an SDK, or do I have to call the API directly?
SDK source packages exist for JavaScript/TypeScript, Python, PHP, Go, and Flutter/Dart. Verify registry availability and endpoint support before use. GET /v1/geo always locates the connecting caller; a backend call does not locate your website visitor. Use secret-key lookup for a supplied IP.
Can I get the visitor's hostname (reverse DNS)?
Yes, but it's opt-in: add ?include=hostname to the request (or include: ["hostname"] in the SDK) and the response gains a hostname field, resolved via a DNS-over-HTTPS PTR lookup. It's null when there's no PTR record. Unlike the always-on enrichment fields above, this does a real network lookup inside the request, so it's left off by default rather than adding latency to every call.
Can you tell me if a visitor is using a VPN, Tor, or is a known threat?
Eligible plans include list-based isVpn, isTor, isDatacenter, isThreat, and isSanctionedNetwork flags on both visitor geolocation and IP lookup responses; Free omits security. IPv4 supports list and ASN matching. IPv6 supports VPN, datacenter and threat ranges plus ASN matching, but has no Tor coverage. Production coverage depends on available feeds. False means no match in available data, not a guarantee of safety; these signals are not definitive sanctions screening.
Can the API tell me which privacy law (GDPR, CCPA, LGPD...) applies to a visitor?
Yes — every response includes a compliance object: isGDPR (EU/EEA + UK), usPrivacyLaw (the applicable US state law, e.g. CCPA/CPRA or VCDPA, keyed off the visitor's state), isLGPD (Brazil), a derived requiresCookieConsent flag, a coarse dataResidencyZone, and isEmbargoedCountry (OFAC comprehensive country embargoes). It's included at no extra cost on every plan, the same as currency and calling code. It's a first-pass jurisdiction signal computed from the visitor's location, not legal advice — always confirm compliance requirements with your own counsel.
Can the API suggest the right locale to render my UI in?
Yes — every response includes a locale object: suggestedLocale is a BCP47 locale that combines the visitor's country with their browser's own Accept-Language header, preferring a language actually spoken there (e.g. an Accept-Language of "fr" from a Canadian visitor yields "fr-CA", not "fr-FR"), falling back to the country's default locale when nothing in the header matches. The same object also includes measurementSystem (metric/imperial), firstDayOfWeek, and dateFormat, so you don't have to re-derive regional formatting conventions yourself. It's included at no extra cost on every plan.
Can the API tell me if today is a public holiday for a visitor?
Yes — every response includes a holiday object: isPublicHolidayToday, todayHolidayName, and nextHoliday (date and name) for the visitor's country, computed from a curated static table (currently ~40 countries — G20 + the EU/EEA + UK) sourced from Nager.Date and refreshed on a manual, once-or-twice-a-year cadence rather than a request-time computation. It's null for countries outside that list, and only counts nationwide public holidays, not state/province-only observances. Included at no extra cost on every plan; more countries are addable on request.
Can the API tell me whether a visitor's state requires age verification for adult content?
Static mappings provide age and jurisdiction hints based on approximate IP location. They do not verify identity or age; confirm applicable requirements independently.