Add VPN and Tor signals to visitor geolocation
Understand when a visitor's connection matches a known VPN network, Tor exit node, datacenter/hosting network, or other supported network category. Watch-IP adds these indicators to eligible GET /v1/geo responses so your application can weigh them alongside other context.
Eligible plans
security is included on the Starter, Growth, Scale, and Enterprise plans. It's omitted entirely from the response on the Free plan — not sent as a misleading all-false object — so check for its presence before reading any field from it.
IPv4 and IPv6 coverage differ
IPv4 connections are checked against Tor, VPN, datacenter, threat, and sanctioned-network lists. IPv6 connections are checked against everything except Tor — there is currently no free IPv6 Tor exit-list source, so isTor is always false for an IPv6 connection regardless of whether it's actually a Tor exit. Do not describe IPv6 coverage as equivalent to IPv4.
Omitted, false, and true are different states
An omitted security object means your plan doesn't include this data, not that the connection was checked and found clean. A false value on an included field means no match in Watch-IP's currently loaded lists — not a confirmed-safe verdict, since list-based detection can't see everything. Never render an unevaluated or false result as "Clean," "Safe," or "Verified."
Sources and updates
The lists behind these fields are compiled and stored in our own storage and refreshed on a schedule. A cold start blocks briefly on its first lookup; once loaded, a request is served from an in-memory cache while a refresh runs in the background, so a slow or failed refresh degrades to stale or empty data rather than a broken response.
A sample review workflow
Treat isVpn or isDatacenter as one input to a manual-review queue alongside account history and other signals, not a sole basis for blocking a visitor outright. Pairing it with a disposable-email check on the same signup event, for example, is a reasonable way to route a small number of signups to review instead of rejecting every VPN user.
What this does not do
These fields do not identify residential proxies, do not verify identity, and are not a comprehensive threat or anonymity-detection product — they're a small set of list-based indicators.
Security response fields
- isTor
- Known Tor exit node, from the currently loaded IPv4 exit list. Always false for IPv6.
- isVpn
- Known commercial VPN provider network, IPv4 and IPv6.
- isDatacenter
- Datacenter/hosting network — a superset of VPN, since many VPN exits run on hosting infrastructure.
- isThreat
- On a known malicious IP range or a known-threat ASN, IPv4 and IPv6.
- isSanctionedNetwork
- On a Watch-IP-maintained list of state-sanctioned telecom/hosting network operators, reviewed quarterly — a softer, lower-confidence signal than the other fields, not sanctions-compliance screening.
Read the security fields safely
Browser JavaScript
const response = await fetch('https://api.watch-ip.com/v1/geo', {
headers: { 'X-Api-Key': 'YOUR_PUBLISHABLE_KEY' },
});
const geo = await response.json();
if (!geo.security) {
// Your plan doesn't include security data — don't assume anything about this connection.
} else if (geo.security.isVpn || geo.security.isDatacenter) {
// A list match — one input to your own review logic, not a block by itself.
} else {
// No match in the currently loaded lists — not a guarantee the connection is safe.
}Always branch on whether `security` is present before reading a field from it — an absent object and a present-but-false field mean different things.
Frequently asked questions
Does it detect residential proxies?
No. Current lists cover known commercial VPN, Tor, datacenter, and threat/sanctioned networks — not the broader category of residential-proxy services, which route through real consumer IP addresses and are much harder to list-match.
What does false mean?
No match in the lists Watch-IP currently has loaded. It is not a positive statement that the connection is safe, since a list can't cover every VPN, exit node, or malicious network in existence.
Is IPv6 Tor covered?
No. isTor is always false for an IPv6 connection today — there's no free IPv6 Tor exit-list source in the current implementation. Every other field does cover IPv6.
Are these checks available for arbitrary IPs?
Yes. The same security block is available on GET/POST /v1/lookup for a supplied IP, not just GET /v1/geo for the connecting browser — gated by the same plan eligibility either way.
Can I block solely on a flag?
You can, but a single list-based flag is a weak basis for an automatic block on its own — false positives happen, and legitimate users route through VPNs and shared networks for ordinary reasons. Most integrations use these fields as one input to a review decision.
Related pages
- Visitor geolocationCall GET /v1/geo from the browser with a publishable key.
- GET /v1/geo referenceFull field reference for the visitor geolocation endpoint.
- Signup abuse preventionCombine email and IP signals into a signup accept, review or reject decision.
- PricingPlans and limits for the visitor and lookup APIs.
- VPN detection limitsWhat a list-based VPN, Tor, or datacenter flag can and can't tell you.