Cần API key không?
Không. GET tới URL HTTPS công khai.
Tra IP công cộng của kết nối này, hoặc bất kỳ IPv4/IPv6, dưới dạng JSON ipkit.v1 ổn định. Base https://ipkit.dev. Không cần khóa.
IPKit chạy trên Cloudflare edge. HTML và JSON dùng chung pipeline. Trang này mô tả HTTP API theo đúng code. Không có SLA; hãy dùng vừa phải.
Mọi lookup trên https://ipkit.dev. Path phân biệt hoa thường. IPv6 trên URL đôi khi cần quote hoặc percent-encode.
Lookup routes accept GET, HEAD, and OPTIONS. HEAD returns the same status and headers with an empty body. POST and other methods are not part of the lookup API. Clients do not send an API key; arbitrary lookups still need the operator-configured IPREGISTRY_API_KEY Worker secret.
There is no plaintext-only route and no endpoint that returns a single field. Read ip from the ipkit.v1 object (for example jq -r .ip). Lookups of private, loopback, link-local, CGNAT, multicast, unspecified, documentation, and other reserved IPv4/IPv6 ranges (including IPv4-mapped IPv6 such as ::ffff:10.0.0.1) return 400 RESERVED_IP. Current-IP detection of this connection is not subject to that check.
Chỉ / chọn HTML hay JSON. /{ip} và /api/* luôn trả JSON.
Successful lookups return Content-Type application/json; charset=utf-8, pretty-printed with two-space indent and a trailing newline. Field names stay in English. null means that value was not supplied. Locations are network estimates, not a street address or identity.
source is "ipregistry" when the configured intelligence provider succeeded. It is "cloudflare" when the record is built from Cloudflare request metadata (used for the current IP if the provider is missing or fails). Cloudflare metadata describes the connecting client only; it is never used as geolocation for a different target IP. Cloudflare-sourced records fill location.countryCode from request.cf.country or CF-IPCountry and location.country from that code when a name is known. Several network fields stay null, security flags are null, and security.risk is "unknown". If IPREGISTRY_API_KEY is unset, arbitrary lookups return 503 instead of guessing the caller’s country.
Illustrative ipkit.v1 object for 8.8.8.8. Values change with the address and data source; clients must tolerate nulls.
{
"schema": "ipkit.v1",
"ip": "8.8.8.8",
"type": "IPv4",
"source": "ipregistry",
"location": {
"continent": "North America",
"country": "United States",
"countryCode": "US",
"region": "California",
"regionCode": "CA",
"city": "Mountain View",
"postalCode": null,
"latitude": 37.386,
"longitude": -122.0838,
"timezone": "America/Los_Angeles"
},
"network": {
"asn": "AS15169",
"organization": "Google LLC",
"domain": "google.com",
"route": "8.8.8.0/24",
"usage": "hosting",
"carrier": null
},
"security": {
"proxy": false,
"vpn": false,
"tor": false,
"relay": false,
"cloud": true,
"threat": false,
"risk": "medium"
}
}Failures return JSON { "error": string, "code": string } with Cache-Control: no-store. error is a human-readable message; code is a stable machine token.
Mọi phản hồi JSON (kể cả lỗi) có Access-Control-Allow-Origin: *. Preflight OPTIONS (204) trên /, /{ip}, /api/my-ip và /api/ip/{ip} (GET, HEAD, OPTIONS; Max-Age 86400). HTML từ / không phải JSON CORS.
300 request / 60 giây cho mỗi IP client. Không có SLA. Dùng hợp lý: công cụ công cộng miễn phí, không phải API hợp đồng.
Current-IP JSON (negotiated / and /api/my-ip) is Cache-Control: private, no-store so one client’s address is not reused for another. Specific-IP lookups (/{ip} and /api/ip/{ip}) are Cache-Control: public, max-age=300, s-maxage=3600, stale-while-revalidate=86400. Error responses are no-store. / JSON also varies on Accept and CF-Connecting-IP.
No authentication. HTTPS only. Parse schema and handle nulls and error objects.
Current public IP (curl)
curl https://ipkit.devLook up an address
curl https://ipkit.dev/8.8.8.8IPv6 in the path (quote colons)
curl "https://ipkit.dev/2001:4860:4860::8888"Always-JSON current IP
curl https://ipkit.dev/api/my-ipJavaScript fetch
const response = await fetch('https://ipkit.dev', {
headers: { Accept: 'application/json' },
});
const data = await response.json();
console.log(data.ip, data.location.countryCode);Python
import json, urllib.request
with urllib.request.urlopen('https://ipkit.dev') as response:
data = json.load(response)
print(data['ip'], data['location']['countryCode'])Shell one-liner (scripts / DDNS)
curl -sS https://ipkit.dev | jq -r .ipIPKit xử lý địa chỉ được yêu cầu và metadata HTTP tại Cloudflare edge. Không có database IP khách. Vị trí là ước lượng mạng. Xem chính sách quyền riêng tư.
Không. GET tới URL HTTPS công khai.
Không có text/plain. Parse JSON: curl -sS https://ipkit.dev | jq -r .ip
Accept có text/html. Dùng ?format=json hoặc /api/my-ip.
Không. /{ip} và /api/ip/{ip} từ chối dải private/reserved bằng 400 RESERVED_IP. GET / và /api/my-ip vẫn trả client đang kết nối.
Thông báo "IP intelligence is not configured for arbitrary lookups." nghĩa là tài khoản Cloudflare phục vụ ipkit.dev chưa đặt Worker secret IPREGISTRY_API_KEY. Tra IP hiện tại vẫn chạy.