Model Context Protocol
Give Claude, Cursor, VS Code or any MCP client the whole IPScanner engine. Your agent can ask whether an address is a VPN or Tor exit, check that Googlebot is really Google, seal an age-gate decision, and read the guides it needs to wire the API into your code.
8 of 21 tools work before you sign up. The free plan is 30,000 requests a month.
New signup from 185.220.101.1. Should we let it through?
{ "target": "185.220.101.1" }"classification": "tor","anonymized": true,"isTor": true,"confidence": 1
No. It is a Tor exit node, so the person behind it is anonymized. Refuse the signup or ask for a verified email.
Setup
The server is hosted, so there is nothing to install or keep running. Point your client at the URL and pass your API key as a Bearer header. Skip the header and it still connects, with the keyless tools.
Run in your terminal
claude mcp add --transport http ipscanner https://ipscanner.io/api/mcp \
--header "Authorization: Bearer YOUR_API_KEY"Leave out --header to start keyless. Run /mcp inside Claude Code to check the connection.
Tools
Each metered tool spends one request from the same monthly allowance as the REST API. Everything marked free costs nothing, even at 100%.
What kind of network an address belongs to, where it is and who runs it.
Everything at once for an IP, CIDR, hostname or URL: class, confidence, purity, geo, ASN, WHOIS.
Network class, anonymized flag and risk score.
The same verdict framed as proxy, Tor included.
Country down to postal code, coordinates and timezone.
The autonomous system that owns the address.
Registrar, dates, nameservers and status for a domain.
Up to a thousand addresses in one call, summarised by class.
Human, verified crawler, AI agent or malicious automation.
A verdict and an allow, flag or block action for one request.
Is that really Googlebot? Checked against what the operator publishes.
The verified crawlers in effect for your account.
Location attestation with a hash-chained audit log.
Apply a jurisdiction policy and seal the decision into your audit log.
The policy table: Utah, UK, Australia, EU and the default.
Recompute every hash and report the first broken link, if any.
Signed evidence CSV for a date range.
Public reference data and your own allowance.
Find a network by name or number, or list the largest.
Prefixes, address count and network type for one ASN.
Plan, requests used, requests left and the reset date.
What your coding agent reads before it writes the integration.
Every guide with a one-line summary.
One guide as Markdown, with code for Node, Next.js, Python and Go.
Full-text search across the guides.
A ready request for any endpoint in six languages.
Implementation guides
The guides are written for the model as much as for you: which endpoint to pick, how to find the real client IP behind a proxy, why a cloud address is not a VPN, what to do with each 429. They carry working code for Node, Next.js, Python and Go.
Quickstart
Base URL, the keyless demo, your first keyed call and what comes back.
Authentication and key handling
Bearer keys, where to keep them, and the two 401 codes.
Reading networkClass correctly
What each network class means, why hosting is not VPN, and a decision table.
Build a VPN and proxy gate
Server-side gate for signup, login or checkout with client-IP extraction, timeouts and caching, in Node, Next.js, Python and Go.
Agentscan: bot and AI-agent defense
Edge snippet plus server-side check, the four verdict classes and the allow/flag/block action.
Verify a crawler claim
Is this address really Googlebot or GPTBot? Outcomes and why unverifiable is not spoofed.
Provenance: location attestation and audit trail
Age and geo gates with per-jurisdiction policy, a hash-chained audit log and evidence export.
Bulk lookups
POST /v1/ip/bulk, the per-plan batch cap and reading the NDJSON stream.
Rate limits, quota and errors
The pooled monthly allowance, rate-limit headers, the three 429 reasons and a retry strategy.
The integrate_ipscanner prompt
Pick a use case and your stack. The prompt tells the agent which guides to read, what to look for in your project, and the rules the integration has to follow: key server-side only, a timeout, a failure policy, tests.
In Claude Code
/mcp__ipscanner__integrate_ipscanner signup_gate "Next.js 15"Without a key
With a key
Questions
Create a key, paste one config block, and ask your first question.