IP Verification API for Fraud Prevention & Geo-Compliance
Verify IP addresses in real time — detect proxies, geo-locate users, and assess risk scores for fraud prevention and geo-compliance workflows.
Overview
The IP Verification API enables businesses to geo-locate IP addresses, detect proxies and VPNs, and assess risk scores. Use it for fraud prevention, geo-compliance, and user location verification.
What Can You Verify With IP Verification API?
Key details returned across all IP Verification API endpoints, ready to power your KYC and onboarding workflows.
Proxy Type
Classification of the connection type (e.g. None, VPN, DCH for data-centre hosting, RES for residential proxy, etc.).
Country Code
ISO 3166-1 alpha-2 country code for the IP address.
Country Name
Full country name corresponding to the country code.
Region Name
State or region within the country where the IP is geolocated.
City Name
City within the region where the IP is geolocated.
City Risk Score
Risk score (0–100) for the geolocated city, based on cybersecurity threat intelligence and historical crime/fraud data for that city. Higher scores indicate greater risk.
Proxy Type Risk Score
Risk score (0–100) for the detected proxy type. A score of 0 means a clean residential or direct connection; higher scores indicate proxy/VPN or data-centre traffic associated with fraud.
IP Verification API Flow – Sample Request and Response
Send simple inputs. Get rich, verified data in seconds.
Geo-locate and risk-score an IP address in real time — detect proxies, VPNs, and assess fraud risk.
Key Features
Everything you need to integrate and scale
IP Geolocation
Resolve IP addresses to country, region, and city for location-based decisions.
Proxy & VPN Detection
Identify proxy type and category to flag suspicious connection sources.
Risk Scoring
Get city-level and proxy-type risk scores for fraud assessment.
Real-Time Processing
Instant IP intelligence for inline fraud checks during transactions.
Who Should Use This API?
Primary Use Cases
How to Integrate
Get started in minutes with our simple integration process
- 1
Sign Up
Sign up in minutes with your mobile number (OTP verify).
- 2
Verify Identity
Complete your basic KYC with PAN and address details to verify your identity.
- 3
Test APIs Live
Load funds into your wallet and test the verification APIs live — evaluate before you integrate.
- 4
Integrate with AI
Ready to build? Visit our AI hub for free plugins & tools to integrate faster.
- 5
Go Live
Start verifying IP addresses in production.
Frequently Asked Questions
What details are returned?+
The API returns IP address, proxy type, country code and name, region, city, city risk score, and proxy-type risk score.
Can it detect VPNs?+
Yes. The API identifies proxy type including VPN, residential proxy, data center proxy, and other classifications.
How is the risk score calculated?+
Risk scores are based on factors like cybersecurity threats, proxy type classification, and historical threat intelligence for the city and connection type.
Is this suitable for real-time fraud checks?+
Yes. The API is designed for inline transaction-level fraud checks with sub-second response times.
How do I get started?+
Four steps: sign up at the developer console page, verify your identity with PAN and address details, load your wallet to test the APIs live, then integrate and go live. Sandbox credentials are issued immediately — you can call your first endpoint before any paperwork clears.
What is EPS?+
EPS (Eko Platform Services) is the technology arm of Eko — the developer tools, AI tooling and APIs that power modern fintech integration, from money transfer and AePS to identity verification.
What are the different ways to integrate with Eko EPS?+
Three paths, pick whichever suits your stack:
- Call the REST APIs directly.
- Use our official Node.js, Python, PHP, Go or Java SDKs to skip request-signing boilerplate.
- Let an AI coding agent build it via our MCP server and agent skills.
For multi-step flows (onboard a sender, then transfer) start from a transaction-flow recipe rather than wiring single endpoints together yourself.
How does API authentication work?+
Each request carries your static developer_key header plus a per-request secret-key header — an HMAC-SHA256 signature of the current timestamp, keyed by your access key. The access key itself is never sent over the wire. You receive UAT keys on signup and production keys after KYC.
The How Authentication Works guide has the full signing recipe in five languages plus an in-browser playground that generates and verifies a real secret-key against your own access key.
Is there a sandbox environment for testing?+
Yes. A full sandbox is available immediately on signup — test your integration end-to-end before going live, no commitment required. For offline work you can also run our mock server (npx -y @ekoindia/eps-mock-server) and get canned responses with no network calls at all.
What are the sandbox and production base URLs?+
Sandbox and production share the same paths and differ only by base URL:
- UAT / Sandbox —
https://staging.eko.in/ekoapi/v3 - Production —
https://api.eko.in/ekoicici/v3
A common cause of failures is calling the sandbox URL with live credentials, or vice-versa — make sure the base URL matches the keys you are using.
Do I need to whitelist my server IP?+
Production API access may require your static public (server) IP to be whitelisted. If your calls work from Postman but fail or time out from your own server, that is almost always the cause — share your static public IP with us so we can whitelist it.
Can an AI coding agent build the integration for me?+
Yes — that is the fastest path. Point your agent (Claude Code, Codex, Cursor, Copilot, …) at our MCP server and it can look up any endpoint, generate correctly-signed requests, and scaffold the integration in your own stack. Install it in one step from the AI hub, or start from a ready-made prompt.
We also publish an OpenAPI 3.1 spec, a Postman collection and per-agent context packs (AGENTS.md, CLAUDE.md, .cursorrules) so an agent has the ground truth instead of guessing.
What response times can I expect?+
Most verification APIs return in real time with sub-second responses, and 99th-percentile latency stays under two seconds across verification endpoints. Transaction APIs (DMT, AePS, BBPS) respond within seconds.
Can the API handle high volumes?+
Yes. The API is designed to handle large-scale volumes reliably without performance degradation.
How is API usage billed?+
Usage is billed per successful API call with no minimum commitment. Volume-based pricing tiers are available — see the pricing calculator for indicative rates, or contact our team for a custom quote.
Get API Access
Sign up now and start integrating in minutes. Our team will help you go live quickly.
- Sandbox access in minutes
- Dedicated integration support
- Comprehensive documentation
- Reliable, high-volume workflows
Get IP Verification API Access
Get started in 10 minutes