ipinfo.app
A suite of free IP address utilities. Look up ASNs, check your IP, detect proxies, query IP-to-country data, and more.
https://ipinfo.app/Opens ChatGPT on the web or desktop and asks it to use the WebMCP tools available here.
Connect straight to this server’s public endpoint.
https://mcp.ipinfo.app/mcpWe add this server to your workspace, then open Studio — saved access, one connection to many servers, with a history of what ran.
Last probed Sep 14, 2026 · mcp.ipinfo.app
13tools discovered
Triage an IP address
Answer "is this IP safe?" for a single address. Returns TWO INDEPENDENT axes: network type (residential / mobile / business / hosting / vpn / privacy_relay / tor / bogon) and risk (clean / suspicious / flagged / unknown), plus the specific evidence behind each. Use this first for any "should I be worried about this IP" question — it replaces chaining six separate lookups. Keep the two axes separate when you report: a flagged residential IP is a compromised home machine (block the /32), while a f
Triage many IP addresses
Triage up to 100 addresses in one call and return a table ranked worst-first. Use this whenever you have a list of IPs from a log, an alert, or a firewall export — one bulk call is far cheaper than a loop of ip_triage, and the ranking puts the addresses worth investigating at the top. Costs one quota unit per IP. Batches larger than 10 addresses use first-party data only (no third-party enrichment) to protect a shared quota; the output states when that happened. Follow up on individual addresses
Full context dossier for an IP
Deep detail for one address when ip_triage is not enough: reverse DNS and what the PTR pattern implies, inferred point-of-presence from carrier rDNS, the full covering-prefix routing view, the announcing AS with its registry record, and the network abuse contact. Use this when you need to report an abuse case, understand where an address physically sits, or explain why a classification came out the way it did. For the safe/unsafe question itself, use ip_triage.
Find an ASN
Resolve a free-form query to AS numbers. Accepts an organisation name ("Cloudflare"), a CIDR, a bare IP, or an AS number — the type is auto-detected, so pass whatever you have. Use this when you know who but not which AS number. Returns at most 25 matches; follow up with asn_lookup or asn_reputation once you have picked one.
Look up an ASN
Who operates an AS number: organisation, registry record, announced prefix counts, the curated network kind (hosting / residential / mobile / business / education / transit), and a curated description of what the network actually does where one exists. Use this for "who is AS13335?". For "should I worry about AS13335?" use asn_reputation, and before blocking anything use blocking_advice.
Assess an ASN's reputation
Answer "is this whole network bad?" — Spamhaus ASN-DROP membership, the count of FBI IC3 indicators attributed to the AS, the curated network kind, and how big the network is. Use this when repeated abuse comes from one AS and you are considering a network-wide response. It deliberately reports how many addresses and prefixes an ASN-wide block would affect, and warns when the AS is a consumer ISP where such a block would hit real users. For the actual block recommendation and rule text, use bloc
Recommend a blocking scope, with blast radius
Answer "I want to block this — at what scope, and what will it break?" Accepts an IP, a CIDR, or an AS number. Returns a recommended scope (single address / prefix / ASN), the number of addresses and prefixes that scope covers, a warning when the target is a consumer ISP or shared infrastructure where a wide block would hit uninvolved users, and paste-ready firewall rules. ALWAYS use this before recommending an ASN-wide block — it will refuse to recommend one for a residential or mobile network
Look up a BGP prefix
Who announces a prefix, how widely it is seen, and whether more than one AS originates it (MOAS). Use this to check whether a prefix is announced by the AS you expect — a MOAS result can be legitimate (anycast, multi-homing) or can indicate a route hijack, and the tool reports which origins are involved so you can judge. Also useful for confirming a block scope before applying it.
FBI IC3 advisory provenance
Look up FBI IC3 advisory indicators for an IP or an ASN, with the advisory titles, publication dates, and source URLs. Use this when you need to know WHY an address is associated with reported criminal activity and to cite the source. CRITICAL when reporting these results: IC3 advisories list victim and sinkhole addresses as well as attacker infrastructure, so a listing is provenance rather than a verdict — never describe a listed address as malicious on this basis alone. For an overall safe/uns
Gather classification evidence for an ASN
Build the evidence pack needed to decide what kind of network an ASN is — hosting, residential, mobile, transit, education, business, government, or vpn. Returns the RIPE RIS view (announced prefixes, addresses, and observed neighbours), the AS's registry record with registration dates, who each sampled prefix is actually REGISTERED to, and sampled reverse DNS with a reverse-zone delegation check. It deliberately returns evidence rather than a verdict: the name, the registry handle, and PeeringD
Build a curation worklist
Triage a batch of AS numbers into a worklist: which are announced, which already have a curated kind, which already have a written description card, and which are reserved or unallocated. Use this to find the ASNs actually worth researching before spending asn_evidence calls on them. Accepts an explicit list or a contiguous range. Capped at 100 ASNs per call.
Check a classification against the curation rules
Given a kind and a confidence you have determined for an ASN, decide whether it may be added to the curated lists in apps/ipinfo/data/, and render the exact entry line if so. Enforces the rules that are mechanical rather than judgement: only `high` confidence enters a list; only the safe-to-grow kinds (education, residential, hosting, mobile, vpn) grow from research, because business, government and transit are deliberately small sets curated from production traffic; an ASN already in any list i
Data freshness and source health
Report how old the underlying datasets are and which sources are currently reachable. COSTS NO QUOTA — call it freely. Use it before relying on a time-sensitive answer (is this a Tor exit? is this proxy range current?), when a result looks surprising, or whenever you are about to state a classification as fact. Classification data is baked into an image at build time with no scheduled refresh, so it can lag; this tool is how you find out by how much.
Get your MCP into directories
A working endpoint is step one. Directory coverage is the coordinated launch across ChatGPT, Claude, Cursor, the MCP Registry, and community indexes.
Directory coverage for brandsA suite of free IP address utilities. Look up ASNs, check your IP, detect proxies, query IP-to-country data, and more.
Use the MCP endpoint listed on this page in your MCP client configuration. One-click install pills support Claude, Cursor, VS Code, and other hosts. Copy the remote MCP URL if your client needs a manual entry.
Operate Ipinfo? Verify ownership to take over this directory entry.
This server appears in the MCPBundles directory. Verify you operate it to take over the listing — name, description, logo, contact email, and skill content. We email a 6-digit code to a maintainer address your server publishes in /.well-known/security.txt or /.well-known/mcpbundles.json. Free, takes about a minute.
MCPBundles probed 13 tools on the live server. The tool list on this page reflects what was discovered at the last refresh — connect your client to see the full set available to your session.
No provider sign-in was required during MCPBundles' probe. Your client may still need MCPBundles credentials depending on how you connect.
MCPBundles is an independent platform built on the open Model Context Protocol standard. Not affiliated with Anthropic PBC or Claude.