Integrations

Edge checks

One call per visitor from your edge, and the policy your Worker enforces.

Check a visitor

POST/v1/edge/check
API keyCounts as 2 requests

Parameters

  • ipstringRequired

    Client IP as seen at your edge.

  • sitestring

    Your site id from the dashboard. Without it the response has no site.

  • user_agentstring

    User-Agent header of the request.

  • ja4string

    JA4 TLS fingerprint of the client.

  • headersobject

    Request headers, for the consistency check.

  • headless_flagsobject

    Automation tells collected in the browser, such as webdriver.

  • request_idstring

    Your own id for the request, kept with the verdict.

Response fields

  • classstring

    verified_bot, malicious_automation, ai_agent, tor, vpn, proxy, relay, hosting or human.

  • agentobject

    The Agentscan verdict: class, confidence, action and signals.

  • networkobject

    networkClass, anonymized, riskScore, provider, vpnProvider, country, asn, asnName and evidence. provider and vpnProvider are Starter and above; null on Free.

  • network.vpnProviderstring | null

    VPN service on a vpn address (NordVPN, Mullvad...), when known. Starter and above; null on Free.

  • siteobject | null

    Your site's id, mode and policyVersion; null when the site is unknown or not yours.

  • lockedstring[]

    Dotted paths of the fields sent as null on this plan. Absent on Starter and above.

  • planRequiredstring

    Plan that includes the locked fields. Absent on Starter and above.

curl -X POST https://ipscanner.io/v1/edge/check \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "site": "site_4fQ8nZ2kLm7xR1vT9cBw",
    "ip": "203.0.113.7",
    "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 Safari/605.1.15",
    "ja4": "t13d1516h2_8daaf6152771_02713d6af862",
    "request_id": "8c1f2a3b4d5e6f70-AMS"
  }'
Response
{
  "class": "vpn",
  "agent": {
    "class": "human",
    "confidence": 0.6,
    "action": "allow",
    "signals": {
      "network_origin": "vpn",
      "anonymized": true,
      "headless": false
    }
  },
  "network": {
    "networkClass": "vpn",
    "anonymized": true,
    "riskScore": 90,
    "provider": "M247 Europe SRL",
    "vpnProvider": "NordVPN",
    "country": "NL",
    "asn": 9009,
    "asnName": "M247 Europe SRL",
    "evidence": [
      "vpn_server_list"
    ]
  },
  "site": {
    "id": "site_4fQ8nZ2kLm7xR1vT9cBw",
    "mode": "monitor",
    "policyVersion": 3
  }
}

Read a site's policy

GET/v1/sites/{id}/policy
API keyNot metered

Parameters

  • idstringpathRequired

    Site id, such as site_4fQ8nZ2kLm7xR1vT9cBw.

Response fields

  • sitestring

    The site id.

  • modestring

    monitor or enforce.

  • policyobject

    allow, flag or block per traffic class. A class that is missing means allow.

  • versioninteger

    Goes up by one each time the policy or mode changes.

  • updatedAtstring

    When the site last changed.

curl https://ipscanner.io/v1/sites/site_4fQ8nZ2kLm7xR1vT9cBw/policy \
  -H "Authorization: Bearer YOUR_API_KEY"
Response
{
  "site": "site_4fQ8nZ2kLm7xR1vT9cBw",
  "mode": "enforce",
  "policy": {
    "malicious_automation": "block",
    "ai_agent": "flag",
    "verified_bot": "allow"
  },
  "version": 3,
  "updatedAt": "2026-10-08T09:30:00Z"
}