NoToolkit API
Six of the tools answer JSON at one endpoint. No API key, no account, and no API rate limits you’ll ever reasonably hit. This page covers what they all have in common; each tool’s page documents its own parameters and fields.
One URL, six tools
Every lookup goes to https://notoolkit.com/. The parameter you send decides which tool answers.
| Tool | Parameters | Takes | Example |
|---|---|---|---|
| IP → ASN Lookup | ip | An IPv4 or IPv6 address or prefix. | /?ip=8.8.8.8 |
| ASN Lookup | asn, prefixes | An AS number. prefixes=true adds the prefix lists. | /?asn=AS13335 |
| RPKI Validator | rpki, origin | A prefix, with the origin AS to validate. A lone AS lists its ROAs. | /?rpki=1.1.1.0/24&origin=AS13335 |
| ASPA Validator | aspa, direction | An AS path, neighbor first. A lone AS shows its ASPA. | /?aspa=3356+13335 |
| IRR Validator | irr, live | A prefix, AS number, as-set or maintainer. | /?irr=AS-EXAMPLE |
| MAC Address Lookup | mac | A full or partial MAC address. | /?mac=00:1B:63:84:45:E6 |
How requests and responses work
These hold for every tool on the endpoint.
| GET | Parameters in the query string. HEAD is answered the same way, without a body. |
| POST | A JSON object with the same parameter names as keys, e.g. {"rpki":"1.1.1.0/24","origin":"AS13335"}. Bodies are limited to 512 bytes. The ASPA tool also takes its path as an array of AS numbers. |
| One lookup | Send one lookup per request. If a request carries more than one, only one is answered, in this order: rpki, aspa, irr, mac, ip, asn. The exception: with rpki, an asn is read as the origin to validate. |
| AS numbers | 13335 and AS13335 both work, in any case. AS0 is not a valid query. |
| Booleans | true, 1, yes and on all mean true, for prefixes and live. |
| Path | Only the root. An API parameter sent to any other path gets a 404. The old /api/ip-to-asn and /api/asn-lookup aliases still answer, with a message_to_user asking you to move to /. |
| Format | UTF-8 JSON with Content-Type: application/json. Most responses start with query, echoing what you sent. |
| Errors | An object with an error string, and usually the query too: {"error":"Invalid ASN: foo"}. The HTTP status says what kind of error it is. |
| Freshness | Answers from mirrored data say how old it is: prefix_last_updated on IP lookups, the rpki block on RPKI and ASPA answers, and live on IRR answers that asked RADB. |
| CORS | Access-Control-Allow-Origin: * on every API response, and preflight OPTIONS requests are answered, so a page on any site can call the API directly. |
| Status | Meaning |
|---|---|
200 | An answer. That includes answers like RPKI invalid or ASPA unknown: the verdict is in the body, not the status. |
400 | The input is not something the tool can read, or no lookup parameter was sent. The error says what was wrong. |
404 | Nothing matched: no route covers the address, no data exists for the AS, no IRR object or MAC assignment was found. Also returned for API calls to a path other than /. |
503 | The database is unreachable, or the data a tool needs has not loaded yet. Retry after a short wait. |
Where answers come from
Answers come from data we mirror and index ourselves. Only two things reach out to someone else’s server during a lookup: the RIR WHOIS for an AS we have not looked up in 14 days, and the IRR tool’s live queries to RADB.
| Tool | Source | Refreshed |
|---|---|---|
| IP → ASN, ASN | RouteViews BGP tables; RIR WHOIS for registrant details | Every 4 hours; WHOIS cached 14 days |
| RPKI, ASPA | ROAs and ASPAs validated by our own Routinator | Every 10 minutes |
| IRR | The published dumps of every mirrored registry, plus live RADB queries | Dumps every 4 hours; RADB live on a miss or live=true |
| MAC | The IEEE registries | Daily |
No API rate limits you’ll ever reasonably hit
There are none on any lookup answered from our own data, which is every lookup but one kind.
| Today | No enforced rate limit on IP → ASN, ASN, RPKI, ASPA or MAC lookups, or on IRR lookups answered from the mirrored registry data. |
| Courtesy | Please keep bulk jobs under 100 requests per second. It is not enforced, but there is real hardware behind this, and high-volume use is expected and welcome below that. |
| Future | If abuse ever makes a limit necessary, it will sit well above normal use and be documented on this page. |
When the IRR tool asks whois.radb.net live, that is a real session on RADB’s servers, not
ours. RADB limits how hard any one client may query it, and these limits exist at RADB’s
request. They apply to nothing else: IRR answers from the mirrored dumps are not limited.
| Live query | Limit |
|---|---|
Requested with live=true | 6 a minute per client |
| Automatic, when the dumps have nothing | 20 a minute per client |
| Every client together | A site-wide ceiling |
| A name RADB did not know either | Not asked about again for 15 minutes |
Past a limit you still get a 200 with an answer from the mirrored dumps, and
live.skipped is rate_limited. The API never answers 429.
API Questions
Do I need an API key or an account?
https://notoolkit.com/ and you get JSON back.Is the API rate limited?
Why are live IRR queries limited?
live=true, RADB is still asked
automatically when the mirrored dumps have nothing. Use it to confirm an object you have just changed, not
for polling or bulk lookups.
Can I call the API from a web page?
Access-Control-Allow-Origin: * and preflight
OPTIONS requests are answered, so a browser on any site can call it directly.