공개 JSON API

IPKit HTTP API

이 연결의 공인 IP 또는 임의 IPv4/IPv6를 안정적인 ipkit.v1 JSON으로 조회합니다. 기본 URL https://ipkit.dev. API 키 없음.

IPKit는 Cloudflare 에지에서 동작합니다. HTML과 JSON은 같은 조회 파이프라인입니다. 코드 기준 HTTP API를 설명합니다. SLA는 없으며 합리적으로 사용해 주세요.

기본 URL과 엔드포인트

모두 https://ipkit.dev 입니다. 경로는 대소문자를 구분합니다. IPv6는 셸에 따라 따옴표나 퍼센트 인코딩이 필요할 수 있습니다.

GET, HEAD /
Current public IP of the connecting client. Browsers (Accept: text/html) get the homepage HTML; curl and most scripts get JSON. Force JSON with ?format=json or use /api/my-ip.
GET, HEAD /{ip}
Look up a specific public IPv4 or IPv6 address. Always JSON, even in a browser. Example: /8.8.8.8. Invalid syntax returns 400 INVALID_IP. Private and reserved ranges return 400 RESERVED_IP. Requires the Worker secret IPREGISTRY_API_KEY; otherwise 503 LOOKUP_UNAVAILABLE.
GET, HEAD /api/my-ip
Current public IP, always JSON. This is the URL the website itself fetches.
GET, HEAD /api/ip/{ip}
Look up a specific public address, always JSON. Same validation and provider requirement as /{ip}. Encode the address (especially IPv6) when building the path, for example /api/ip/8.8.8.8.
OPTIONS /, /{ip}, /api/my-ip, /api/ip/{ip}
CORS preflight on every public JSON lookup URL. Returns 204 with Access-Control-Allow-Origin: *, Allow-Methods GET, HEAD, OPTIONS, and Access-Control-Max-Age 86400.

Lookup routes accept GET, HEAD, and OPTIONS. HEAD returns the same status and headers with an empty body. POST and other methods are not part of the lookup API. Clients do not send an API key; arbitrary lookups still need the operator-configured IPREGISTRY_API_KEY Worker secret.

There is no plaintext-only route and no endpoint that returns a single field. Read ip from the ipkit.v1 object (for example jq -r .ip). Lookups of private, loopback, link-local, CGNAT, multicast, unspecified, documentation, and other reserved IPv4/IPv6 ranges (including IPv4-mapped IPv6 such as ::ffff:10.0.0.1) return 400 RESERVED_IP. Current-IP detection of this connection is not subject to that check.

콘텐츠 협상

HTML과 JSON을 고르는 것은 / 뿐입니다. /{ip}와 /api/*는 항상 JSON입니다.

?format=json
JSON ipkit.v1, even when Accept includes text/html.
?format=html
HTML homepage, even when the client would otherwise get JSON (for example curl).
Accept includes text/html
HTML homepage. Typical browsers send this.
HTML crawler User-Agent
Googlebot, Bingbot, Baidu, Sogou, and 360Spider receive HTML on / so they index the page instead of JSON.
Otherwise
JSON. curl’s default Accept is */*, and fetch() defaults to */*, so both receive JSON from / without extra headers.

ipkit.v1 응답 스키마

Successful lookups return Content-Type application/json; charset=utf-8, pretty-printed with two-space indent and a trailing newline. Field names stay in English. null means that value was not supplied. Locations are network estimates, not a street address or identity.

source is "ipregistry" when the configured intelligence provider succeeded. It is "cloudflare" when the record is built from Cloudflare request metadata (used for the current IP if the provider is missing or fails). Cloudflare metadata describes the connecting client only; it is never used as geolocation for a different target IP. Cloudflare-sourced records fill location.countryCode from request.cf.country or CF-IPCountry and location.country from that code when a name is known. Several network fields stay null, security flags are null, and security.risk is "unknown". If IPREGISTRY_API_KEY is unset, arbitrary lookups return 503 instead of guessing the caller’s country.

schema
Always "ipkit.v1" so clients can detect breaking changes.
ip
The public address that was detected (current connection) or requested (lookup).
type
"IPv4" or "IPv6".
source
"ipregistry" when the configured intelligence provider succeeded; "cloudflare" when the record is built from Cloudflare edge metadata only.
location.continent
Continent name when the provider supplies one; otherwise null.
location.country
Country name. For source=ipregistry, the provider’s name. For source=cloudflare, the English name derived from Cloudflare’s ISO country code (request.cf.country or CF-IPCountry). Null when the code is missing, XX (unknown), T1 (Tor), or otherwise unnamed.
location.countryCode
ISO 3166-1 alpha-2 code when known. Cloudflare supplies this for the connecting client. XX is stored as null. T1 (Tor) is kept as T1.
location.region
Region or state name at network granularity, or null.
location.regionCode
Region code when available, or null.
location.city
City at network granularity when the provider has one, or null.
location.postalCode
Postal code when the provider has one, or null. Not a street address.
location.latitude
Estimated latitude as a number, or null.
location.longitude
Estimated longitude as a number, or null.
location.timezone
IANA timezone id tied to the geolocation guess, or null.
network.asn
Autonomous system as "ASnnnn", or null.
network.organization
ISP or organization name for that ASN, or null.
network.domain
Network or company domain when the provider has one, or null.
network.route
Announced prefix/route when available, or null.
network.usage
Connection or company usage type from the provider (for example hosting), or null.
network.carrier
Mobile carrier name when the provider has one, or null.
security.proxy
Whether the provider flags a proxy; null when unknown (typical for source=cloudflare).
security.vpn
Whether the provider flags a VPN, or null.
security.tor
Whether the provider flags a Tor exit, or null.
security.relay
Whether the provider flags a privacy relay, or null.
security.cloud
Whether the provider flags a cloud provider, or null.
security.threat
Whether the provider flags a threat, or null. A signal, not proof.
security.risk
"low", "medium", "high", or "unknown". Derived from provider flags when present; "unknown" for cloudflare-sourced records. Not a fraud score and not sole proof for blocking.

Example response

Illustrative ipkit.v1 object for 8.8.8.8. Values change with the address and data source; clients must tolerate nulls.

{
  "schema": "ipkit.v1",
  "ip": "8.8.8.8",
  "type": "IPv4",
  "source": "ipregistry",
  "location": {
    "continent": "North America",
    "country": "United States",
    "countryCode": "US",
    "region": "California",
    "regionCode": "CA",
    "city": "Mountain View",
    "postalCode": null,
    "latitude": 37.386,
    "longitude": -122.0838,
    "timezone": "America/Los_Angeles"
  },
  "network": {
    "asn": "AS15169",
    "organization": "Google LLC",
    "domain": "google.com",
    "route": "8.8.8.0/24",
    "usage": "hosting",
    "carrier": null
  },
  "security": {
    "proxy": false,
    "vpn": false,
    "tor": false,
    "relay": false,
    "cloud": true,
    "threat": false,
    "risk": "medium"
  }
}

오류와 상태 코드

Failures return JSON { "error": string, "code": string } with Cache-Control: no-store. error is a human-readable message; code is a stable machine token.

400 INVALID_IP
The path is not a syntactically valid IPv4 or IPv6 address. error is "Invalid IP address."
400 RESERVED_IP
The target on /{ip} or /api/ip/{ip} is a private, loopback, link-local, CGNAT, multicast, unspecified, documentation, or other reserved IPv4/IPv6 address, including IPv4-mapped IPv6 (for example ::ffff:10.0.0.1). error is "Private or reserved IP address." Current-IP GET / and /api/my-ip are not rejected this way.
429 RATE_LIMITED
The connecting client IP exceeded the lookup limit. error is "Too many lookups. Please retry in one minute." Retry-After is 60.
502 LOOKUP_UNAVAILABLE
The intelligence provider failed or timed out (about 6 seconds). error is "The IP data provider is temporarily unavailable."
503 LOOKUP_UNAVAILABLE
For /{ip} and /api/ip/{ip} this usually means the Worker secret IPREGISTRY_API_KEY is missing or empty on the Cloudflare account that serves ipkit.dev. error is then "IP intelligence is not configured for arbitrary lookups." That is operator configuration, not a client error. Set the secret in the dashboard (Workers & Pages → ipkit → Settings → Variables and Secrets) or with wrangler secret put IPREGISTRY_API_KEY. Current-IP GET / and /api/my-ip still succeed from Cloudflare metadata. The same status and code are also used when Ipregistry rate-limits IPKit; then error is "The IP data provider is temporarily unavailable."
500 LOOKUP_UNAVAILABLE
Unexpected lookup failure. error is "Unexpected lookup failure."

CORS

오류를 포함한 모든 JSON 조회 응답에 Access-Control-Allow-Origin: * 가 있습니다. OPTIONS 프리플라이트(204)는 /, /{ip}, /api/my-ip, /api/ip/{ip} 에서 GET, HEAD, OPTIONS, Max-Age 86400. / 의 HTML은 CORS JSON이 아닙니다.

속도 제한

연결 클라이언트 IP당 60초에 300회. SLA 없음. 합리적 사용을 부탁합니다. 무료 공개 도구이며 계약 API가 아닙니다.

캐시

Current-IP JSON (negotiated / and /api/my-ip) is Cache-Control: private, no-store so one client’s address is not reused for another. Specific-IP lookups (/{ip} and /api/ip/{ip}) are Cache-Control: public, max-age=300, s-maxage=3600, stale-while-revalidate=86400. Error responses are no-store. / JSON also varies on Accept and CF-Connecting-IP.

복사할 예제

No authentication. HTTPS only. Parse schema and handle nulls and error objects.

Current public IP (curl)

curl https://ipkit.dev

Look up an address

curl https://ipkit.dev/8.8.8.8

IPv6 in the path (quote colons)

curl "https://ipkit.dev/2001:4860:4860::8888"

Always-JSON current IP

curl https://ipkit.dev/api/my-ip

JavaScript fetch

const response = await fetch('https://ipkit.dev', {
  headers: { Accept: 'application/json' },
});
const data = await response.json();
console.log(data.ip, data.location.countryCode);

Python

import json, urllib.request

with urllib.request.urlopen('https://ipkit.dev') as response:
    data = json.load(response)
print(data['ip'], data['location']['countryCode'])

Shell one-liner (scripts / DDNS)

curl -sS https://ipkit.dev | jq -r .ip

개인정보

조회를 위해 요청 주소와 일반 요청 메타데이터를 Cloudflare 에지에서 처리합니다. 방문자 IP 앱 DB는 없습니다. 위치는 네트워크 추정입니다. 개인정보 처리방침을 보세요.

개인정보 처리방침

FAQ

API 키가 필요하나요?

아니요. 공개 HTTPS URL에 GET 하면 됩니다.

IP 문자열만 필요하면?

text/plain 없음. JSON 파싱: curl -sS https://ipkit.dev | jq -r .ip

브라우저에서 / 가 HTML인 이유는?

Accept에 text/html이 있어서입니다. ?format=json 또는 /api/my-ip 를 쓰세요.

사설 주소는?

아니요. /{ip}와 /api/ip/{ip}는 사설/예약 대역을 400 RESERVED_IP 로 거부합니다. GET / 와 /api/my-ip 는 연결 클라이언트를 반환합니다.

/8.8.8.8 이 503인 이유는?

메시지 "IP intelligence is not configured for arbitrary lookups." 는 ipkit.dev 를 서빙하는 Cloudflare 계정에 Worker 시크릿 IPREGISTRY_API_KEY 가 없다는 뜻입니다. 현재 IP 조회는 계속 동작합니다.