VPNDetection

io.github.vpndetection-iov5.3.6Updated Oct 3, 2026

VPN, proxy, Tor, hosting and CDN detection for any IP address, from the VPNDetection API.

VerifiedStreamable HTTPWeb executableWeb Search & ScrapingSecurity & Monitoring

Overview

AI-generated overview

Lets an assistant classify IP addresses as VPN, proxy, Tor, hosting or CDN, and inspect the provider's detection databases and license status.

What it does
Wraps the VPNDetection API in seven read-only tools. lookup_ip classifies a single address and lookup_ips classifies a list in one batched call. my_entitlement reports the plan, field tier, requests used, allowance and reset date; list_databases, database_metadata, database_checksum and list_downloads cover the published databases and your organization's download attempts. Results include a coverage block stating which fields the plan did not return.
When to use it
Useful when an assistant needs to judge whether an IP is anonymized traffic, for fraud, abuse or access checks, or to see which detection databases your organization is licensed for. It is read-only, so it fits lookups and reporting rather than enforcement actions.
Requirements
Either the hosted endpoint at mcp.vpndetection.io, signed in with a VPNDetection account, or the npm package vpndetection-mcp run locally with Node.js 22 or newer. The free tier answers ip and is_vpn with 1000 requests per day per source address and needs no key; VPNDETECTION_API_KEY unlocks provider names, classification databases and proxy families. VPNDETECTION_BASE_URL overrides the endpoint.
Before you install
The API key is a credential: keep it in the environment rather than in shared configs. Lookups send the addresses you query to VPNDetection, a third party, so avoid submitting addresses you consider sensitive. Usage counts against the subscription anniversary, and a null hard_limit means no cap rather than zero. A field absent from a result means the plan excludes it, not that nothing was found.

Installation

In SourceWeft

  1. Open VPNDetection in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.

Other MCP clients

Add this to your client's mcpServers config.

{
  "mcpServers": {
    "mcp": {
      "type": "http",
      "url": "https://mcp.vpndetection.io/mcp"
    }
  }
}

README

[VPNDetection] VPNDetection MCP Server

[npm] [license]

The official Model Context Protocol server for the VPNDetection API.

It gives an AI agent seven read-only tools for anonymity detection: whether an address belongs to a VPN, a residential, datacenter or mobile proxy, a Tor node, a public relay, a hosting provider or a CDN, plus the database catalog and where your organization's license for each one stands.

Getting Started

We host it at https://mcp.vpndetection.io/mcp, and you sign in to it with your VPNDetection account. It also runs on your own machine from npm.

In Claude

In claude.ai, the desktop app or Cowork, add https://mcp.vpndetection.io/mcp as a custom connector and choose Use Claude's published identity when asked. In Claude Code, install our plugin, which adds the server with skills:

console
/plugin marketplace add vpndetection-io/claude-plugin/plugin install vpndetection@vpndetection

Either way you sign in with your VPNDetection account, and Claude never sees your API key. The steps, the skills and how to disconnect: docs.vpndetection.io/integrations/claude.

In any other MCP client

Point it at https://mcp.vpndetection.io/mcp. A client that supports MCP authorization signs in the same way. One that doesn't can send a key instead, as Authorization: Bearer your-key.

On your own machine

No API key needed to start. The free tier answers ip and is_vpn, and allows 1000 requests per day per source address.

Add this to your MCP client's config:

json
{  "mcpServers": {    "vpndetection": {      "command": "npx",      "args": ["-y", "vpndetection-mcp"]    }  }}

Requires Node.js 22 or newer.

A key unlocks the provider name, the classification databases and the proxy families. Put it in the environment:

json
{  "mcpServers": {    "vpndetection": {      "command": "npx",      "args": ["-y", "vpndetection-mcp"],      "env": { "VPNDETECTION_API_KEY": "your-key" }    }  }}

VPNDETECTION_BASE_URL overrides the endpoint if you need to point somewhere else.

Tools

ToolWhat it answers
lookup_ipClassify one address.
lookup_ipsClassify a whole list of addresses in one call, keyed by address. A long list is batched for you.
my_entitlementWhat this key is entitled to and what it has spent: plan, field tier, requests so far, allowance, and when it resets.
list_databasesEvery database we publish, with its standing for your organization: licensed, expired or unlicensed.
database_metadataA database's columns, sample rows, row count, build date and file sizes.
database_checksumThe published digests for one database file.
list_downloadsYour organization's recent download attempts, refusals included.

Every tool is read-only. There is deliberately no download tool: the databases run to several GB, which is not something an agent should pull into a conversation. Fetch them with the client libraries or the API instead.

There is deliberately no my_ip tool, although every client library has one. Over a hosted transport the address our edge observes belongs to whatever proxied the call - Claude's infrastructure, not the person asking - so the tool would answer confidently and wrongly for the only reading anyone would put on it. my_entitlement has no such problem and is the same answer from any transport, because it describes the credential rather than the connection. A test pins the tool's absence so it cannot be added back by accident.

Usage counts against the anniversary of the subscription, not the calendar month and not the billing period. A null hard_limit means we never stop serving; it is not a limit of zero.

Reading a result

Each lookup comes back with a coverage block beside it:

json
{  "result": { "ip": "45.83.91.1", "is_vpn": true },  "coverage": {    "included": ["ip", "is_vpn"],    "not_included": ["is_hosting", "is_tor", "hosting", "tor", "..."],    "note": "The fields in not_included were not returned, because this API key's plan does not include them. ..."  }}

This matters more here than in a normal client library. A field missing from a result means your plan doesn't include it, never "we checked and found nothing" - and a model reading the result on its own will otherwise treat the absence as a negative answer. coverage states the difference explicitly so it can't.

Other Libraries

There are official VPNDetection client libraries available for many languages including PHP, Python, Go, Java, Ruby, and many popular frameworks such as Django, Rails, and Laravel. See our GitHub at https://github.com/vpndetection-io for more.

About VPNDetection

VPN Detection API: Accurate anonymity detection identifying VPNs, residential proxies, hosting servers, Tor nodes, CDNs, relays and more.

[VPNDetection]

License

This project is licensed under the MIT License.

Source: README.md at commit 7f270f4

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v5.3.6LatestOct 3, 2026