// ipinfo.app

ASN API Reference

autonomous system lookup · ip prefix data · firewall config generation

// Overview
Free, no-auth API for Autonomous System lookups. Returns ASN details, CIDR prefix lists, and ready-to-use firewall configs for any AS number. Data sourced from iptoasn.com via the internal Atlas service, updated daily.
// Base URL
https://asn.ipinfo.app
// Errors

All errors return JSON with error, request, and status fields.

{
  "error":   "We can't find a result for your query.",
  "request": "99999",
  "status":  404
}
400 Bad Request 404 Not Found 410 Gone 429 Rate Limited 502 Atlas Unavailable
// ASN Details
GET /api/json/details/{asn}
Returns summary data for an Autonomous System: org name, total prefix count, IPv4/IPv6 address space size, and subnet mask distribution.
ParameterTypeDescription
{asn}integerAS number in the URL path. Accepts bare integer (13335) or AS-prefixed (AS13335).
Example Request
GET /api/json/details/AS13335
Response 200
{
  "asn":     13335,
  "name":    "CLOUDFLARENET - Cloudflare",
  "iprec":   5600,
  "v4size":  1476096,
  "v6size":  78455046144,
  "smaskv4": { "24": 2240, "20": 167, ... },
  "smaskv6": { "48": 5200, "32": 8,   ... }
}

Note: v6size is counted in /64 equivalents. The time field from the legacy API has been removed.

// Domain Lookup
GET /api/json/domain/{domain}
Resolves a hostname via DNS (A and AAAA in parallel), then looks each resolved IP up against Atlas to identify the hosting ASN(s). Useful for answering "who hosts example.com?" without needing to run dig + a follow-up ASN search yourself. Reserved or non-public TLDs (.local, .internal, .test, .example, etc.) are refused.
ParameterTypeDescription
{domain}stringPublic hostname (e.g. cloudflare.com). Also accepts ?domain= as a query parameter.
Example Request
GET /api/json/domain/cloudflare.com
Response 200
{
  "domain":    "cloudflare.com",
  "addresses": [
    {
      "ip":           "104.16.132.229",
      "version":      4,
      "asn":          13335,
      "name":         "CLOUDFLARENET",
      "kind":         "hosting",
      "country_code": "US",
      "country":      "United States"
    },
    ...
  ],
  "asns": [
    { "asn": 13335, "name": "CLOUDFLARENET", "kind": "hosting",
      "ips": ["104.16.132.229", ...] }
  ]
}

Cached server-side for 1 hour. IPs that don't map to a known ASN (private space, unannounced blocks) are still returned in addresses with asn: null; only public ASNs appear in the deduplicated asns array.

200 OK 400 Invalid / reserved domain 404 No A/AAAA records 429 Rate limited (20 req/min) 502 Resolver failure
// My ASN
GET /api/json/myasn
Resolves the caller's IP address to its owning ASN. Useful for showing visitors their own network information.
Response 200
{
  "ip":   "1.1.1.1",
  "asn":  13335,
  "name": "CLOUDFLARENET - Cloudflare"
}
// CIDR List
GET /api/json/list/{asn}
Returns the complete flat list of CIDR prefixes for an ASN, with both IPv4 and IPv6 entries. Use this when you need raw prefix strings without any format-specific wrapping. Prefixes are automatically aggregated — adjacent announcements are collapsed into the minimal covering set before being returned.
Example Requests
GET /api/json/list/AS13335      ↳ JSON { name, type, list }
GET /api/text/list/AS13335      ↳ plain text, one CIDR per line
GET /api/download/list/AS13335  ↳ download as list_13335.txt
Response 200 (JSON)
{
  "name": "CLOUDFLARENET - Cloudflare",
  "type": "ipList",
  "list": [
    "104.16.0.0/12",
    "172.64.0.0/13",
    "2606:4700::/32",
    ...
  ]
}
// Format Endpoints
Each format is available in three URL trees. Replace {asn} with a bare integer (13335) or AS-prefixed form (AS13335).

/api/json/<format>/{asn} — JSON envelope { name, type, list } where list is an array of config strings
/api/text/<format>/{asn} — plain text, one line per entry
/api/download/<format>/{asn} — plain text with Content-Disposition: attachment for direct file download

The raw format is JSON-only (no text or download variant).

{asn} may also be an IRR as-set such as AS-CLOUDFLARE or AS13335:AS-CLOUDFLARE — see IRR as-set source.

All firewall formats return aggregated prefix lists (the bgp-* router-filter formats deliberately do not). BGP routing tables often contain disaggregated announcements — a single logical block split into many smaller prefixes for traffic engineering. We collapse adjacent and overlapping CIDRs into the minimal covering set so you get fewer, cleaner firewall rules. The aggregation is lossless: we never add addresses that aren't actually announced by the AS.
// ipset
GET /api/json/ipset/{asn}
Linux ipset hash:net commands. Creates two named sets — {asn}-4 (inet/IPv4) and {asn}-6 (inet6/IPv6) — then adds every prefix to the appropriate set. Suitable for use with iptables -m set --match-set.
Example Requests
GET /api/json/ipset/AS13335      ↳ JSON { name, type, list }
GET /api/text/ipset/AS13335      ↳ plain text, one command per line
GET /api/download/ipset/AS13335  ↳ download as ipset_13335.txt
Response 200 (JSON)
{
  "name": "CLOUDFLARENET",
  "type": "ipset",
  "list": [
    "ipset -N 13335-4 hash:net family inet",
    "ipset -N 13335-6 hash:net family inet6",
    "ipset -A 13335-4 104.16.0.0/12",
    "ipset -A 13335-4 172.64.0.0/13",
    "ipset -A 13335-6 2606:4700::/32",
    ...
  ]
}
// iptables
GET /api/json/iptables/{asn}
iptables INPUT DROP rules. IPv4 prefixes use iptables; IPv6 prefixes use ip6tables. Append directly to your existing INPUT chain.
Example Requests
GET /api/json/iptables/AS13335
GET /api/text/iptables/AS13335
GET /api/download/iptables/AS13335  ↳ iptables_13335.txt
Response 200 (JSON)
{
  "name": "CLOUDFLARENET",
  "type": "iptables",
  "list": [
    "iptables -A INPUT -s 104.16.0.0/12 -j DROP",
    "iptables -A INPUT -s 172.64.0.0/13 -j DROP",
    "ip6tables -A INPUT -s 2606:4700::/32 -j DROP",
    ...
  ]
}
// nginx
GET /api/json/nginx/{asn}
nginx deny directives. Paste these lines into an nginx geo or map block, or directly into a location context to block all prefixes belonging to the AS.
Example Requests
GET /api/json/nginx/AS13335
GET /api/text/nginx/AS13335
GET /api/download/nginx/AS13335  ↳ nginx_13335.txt
Response 200 (JSON)
{
  "name": "CLOUDFLARENET",
  "type": "nginx",
  "list": [
    "deny 104.16.0.0/12;",
    "deny 172.64.0.0/13;",
    "deny 2606:4700::/32;",
    ...
  ]
}
// cisco
GET /api/json/cisco/{asn}
Cisco ASA object network statements. IPv4 entries use dotted-decimal subnet masks; IPv6 entries use CIDR notation. Objects are named {asn}-4-SN0, {asn}-4-SN1, …, {asn}-6-SN0, …
Example Requests
GET /api/json/cisco/AS13335
GET /api/text/cisco/AS13335
GET /api/download/cisco/AS13335  ↳ cisco_13335.txt
Response 200 (JSON)
{
  "name": "CLOUDFLARENET",
  "type": "cisco",
  "list": [
    "object network 13335-4-SN0",
    " subnet 104.16.0.0 255.240.0.0",
    "object network 13335-4-SN1",
    " subnet 172.64.0.0 255.248.0.0",
    "object network 13335-6-SN0",
    " subnet 2606:4700::/32",
    ...
  ]
}
// juniper
GET /api/json/juniper/{asn}
Juniper JunOS set policy-options prefix-list statements. IPv4 prefixes go into the {asn}v4 list; IPv6 prefixes go into {asn}v6.
Example Requests
GET /api/json/juniper/AS13335
GET /api/text/juniper/AS13335
GET /api/download/juniper/AS13335  ↳ juniper_13335.txt
Response 200 (JSON)
{
  "name": "CLOUDFLARENET",
  "type": "juniper",
  "list": [
    "set policy-options prefix-list 13335v4 104.16.0.0/12",
    "set policy-options prefix-list 13335v4 172.64.0.0/13",
    "set policy-options prefix-list 13335v6 2606:4700::/32",
    ...
  ]
}
// htaccess
GET /api/json/htaccess/{asn}
Apache .htaccess deny rules using mod_access_compat (Apache 2.4+ with compatibility module). The list always starts with Order Deny,Allow.
Example Requests
GET /api/json/htaccess/AS13335
GET /api/text/htaccess/AS13335
GET /api/download/htaccess/AS13335  ↳ htaccess_13335.txt
Response 200 (JSON)
{
  "name": "CLOUDFLARENET",
  "type": "htaccess",
  "list": [
    "Order Deny,Allow",
    "Deny from 104.16.0.0/12",
    "Deny from 172.64.0.0/13",
    "Deny from 2606:4700::/32",
    ...
  ]
}
// ipblackhole
GET /api/json/ipblackhole/{asn}
Linux kernel blackhole (null-route) add commands. Silently drops all traffic to the AS by installing static blackhole routes in the kernel routing table. Also used in BGP RTBH (Remotely Triggered Black Hole) setups.
Example Requests
GET /api/json/ipblackhole/AS13335
GET /api/text/ipblackhole/AS13335
GET /api/download/ipblackhole/AS13335  ↳ ipblackhole_13335.txt
Response 200 (JSON)
{
  "name": "CLOUDFLARENET",
  "type": "ip blackhole",
  "list": [
    "ip route add blackhole 104.16.0.0/12",
    "ip route add blackhole 172.64.0.0/13",
    "ip route add blackhole 2606:4700::/32",
    ...
  ]
}
// ipblackholerem
GET /api/json/ipblackholerem/{asn}
Linux kernel blackhole (null-route) del commands. Removes the static blackhole routes previously added with the ipblackhole format. Download filename uses ipblackhole_remove_ prefix to match the original PHP app convention.
Example Requests
GET /api/json/ipblackholerem/AS13335
GET /api/text/ipblackholerem/AS13335
GET /api/download/ipblackholerem/AS13335  ↳ ipblackhole_remove_13335.txt
Response 200 (JSON)
{
  "name": "CLOUDFLARENET",
  "type": "ip blackhole remove",
  "list": [
    "ip route del blackhole 104.16.0.0/12",
    "ip route del blackhole 172.64.0.0/13",
    "ip route del blackhole 2606:4700::/32",
    ...
  ]
}
// raw
GET /api/json/raw/{asn}
Structured per-CIDR breakdown returning an object for each prefix with the IP address, dotted-decimal subnet mask, prefix length, and IP version. IPv6 subnet masks are the string "FALSE" (no dotted-decimal representation). JSON-only — no /text/ or /download/ variant.
Example Request
GET /api/json/raw/AS13335
Response 200
{
  "name": "CLOUDFLARENET",
  "type": "raw",
  "list": [
    {
      "ip":         "104.16.0.0",
      "subnetMask": "255.240.0.0",
      "cidr":       "12",
      "type":       4
    },
    {
      "ip":         "2606:4700::",
      "subnetMask": "FALSE",
      "cidr":       "32",
      "type":       6
    },
    ...
  ]
}

Note: cidr is the prefix length as a string. type is 4 or 6.

// tsv
GET /api/json/tsv/{asn}
Tab-separated values with a header row. Four columns: IP Address, Subnet Mask, CIDR (prefix length), Type (4 or 6). IPv6 subnet masks are FALSE.
Example Requests
GET /api/json/tsv/AS13335
GET /api/text/tsv/AS13335
GET /api/download/tsv/AS13335  ↳ tsv_13335.txt
Response 200 (JSON)
{
  "name": "CLOUDFLARENET",
  "type": "tsv",
  "list": [
    "IP Address\tSubnet Mask\tCIDR\tType",
    "104.16.0.0\t255.240.0.0\t12\t4",
    "172.64.0.0\t255.248.0.0\t13\t4",
    "2606:4700::\tFALSE\t32\t6",
    ...
  ]
}
// csv
GET /api/json/csv/{asn}
Comma-separated values with a header row. Four columns: IP Address, Subnet Mask, CIDR (prefix length), Type (4 or 6). IPv6 subnet masks are FALSE.
Example Requests
GET /api/json/csv/AS13335
GET /api/text/csv/AS13335
GET /api/download/csv/AS13335  ↳ csv_13335.txt
Response 200 (JSON)
{
  "name": "CLOUDFLARENET",
  "type": "csv",
  "list": [
    "IP Address,Subnet Mask,CIDR,Type",
    "104.16.0.0,255.240.0.0,12,4",
    "172.64.0.0,255.248.0.0,13,4",
    "2606:4700::,FALSE,32,6",
    ...
  ]
}
// BGP prefix filters
GET /api/text/{bgp-cisco|bgp-junos|bgp-bird|bgp-plain}/{asn|as-set}
Router prefix filters in the style of bgpq4. Unlike the firewall formats these use the exact prefixes, not an aggregate: a filter built from an aggregate would reject the more-specifics the network really announces. One list per address family.

bgp-cisco — IOS ip prefix-list / ipv6 prefix-list, cleared first; an empty family gets a deny entry because IOS treats an undefined list as permit-any.
bgp-junos — policy-options prefix-list NAME-v4/-v6 (a route-filter-list with upto when max lengths apply).
bgp-bird — BIRD 2 define NAME_V4 = [ ... ];, max lengths as {min,max}.
bgp-plain — one prefix per line.

Every output starts with comment lines naming the source and the prefix count, and a TRUNCATED line whenever the upstream list was cut. Query options: ?af=4|6 (one family), ?name=LIST (list name, like bgpq4 -l), ?source=roa and ?rpki= (see RPKI). The JSON tree adds source, count, truncated and entries: [{prefix, max_length}].
Example Requests
GET /api/text/bgp-cisco/AS13335
GET /api/text/bgp-junos/AS13335?af=6
GET /api/text/bgp-bird/AS13335:AS-CLOUDFLARE?name=CLOUDFLARE
GET /api/download/bgp-plain/AS-FOO  ↳ bgp-plain_AS-FOO.txt
Response 200 (text, bgp-cisco)
! Cisco IOS prefix-list for AS2906 — announced prefixes (observed BGP)
! 519 prefixes; generated by asn.ipinfo.app from Atlas
no ip prefix-list AS2906
ip prefix-list AS2906 permit 9.187.0.0/16
ip prefix-list AS2906 permit 9.187.0.0/17
ip prefix-list AS2906 permit 9.187.128.0/17
...
Response 200 (text, bgp-bird?source=roa)
# BIRD 2 prefix set for AS2906 — RPKI ROAs
# 23 ROAs; generated by asn.ipinfo.app from Atlas
# from ROAs: prefixes AS2906 is AUTHORISED to originate, not what it announces
define AS2906_V4 = [
    9.187.0.0/16{16,24},
    9.188.0.0/16{16,24},
...
// IRR as-set source
GET /api/{json|text|download}/{format}/{as-set}
Any format accepts an IRR as-set in place of the AS number — plain (AS-HURRICANE) or hierarchical (AS13335:AS-CLOUDFLARE), case-insensitive. The set is expanded recursively across the public IRR databases and the list is every route/route6 object whose origin is in the expansion — what bgpq4 AS-FOO builds. These are registered prefixes, not observed announcements. An unknown set answers 200 with an empty list and a comment saying so; ?af=4|6 applies. Firewall formats also get X-Prefix-Count / X-Prefix-Truncated headers. Browse a set at /lists/AS-FOO.
// RPKI: ROA lists & filtering
GET /api/text/{format}/{asn}?source=roa  |  ?rpki=valid  |  ?rpki=not-invalid
?source=roa — the prefixes this AS's ROAs authorise, with their max length (le / upto / {min,max} in the BGP formats), instead of what it announces. Labelled "from ROAs" in the output header.
?rpki=valid — only announcements that are RPKI-valid (RFC 6811).
?rpki=not-invalid — drop RPKI-invalid announcements, keep the rest.

ASN sources only. Answers 503 when the RPKI dataset is unavailable rather than an unfiltered list.
Example Requests
GET /api/text/bgp-bird/AS13335?source=roa
GET /api/text/nginx/AS13335?rpki=valid
GET /api/json/list/AS13335?rpki=not-invalid
// Removed Endpoints (410 Gone)
The following endpoints depended on CockroachDB historical snapshots which are no longer maintained. They return 410 Gone. Historical data is still available at asn-legacy.ipinfo.app.
EndpointWasStatus
/api/json/archive/…Historical CIDR snapshot for a specific timestamp410
/api/json/archiveRaw/…Raw archived record410
/api/json/growth/…IP space growth over time410
/api/json/growthSplit/…Growth split by IP version410
/api/json/snapshots/…List of available archive timestamps410
/api/json/peersv4/…IPv4 BGP peer list410
/api/json/peersv6/…IPv6 BGP peer list410
/api/json/directPeers*/…Direct peer adjacencies410
/api/json/peerWordlist*/…Peer ASN wordlists for brute-forcing410