All toolsJSON APISix tools · One endpoint

NoToolkit API

Six of the tools answer JSON at one endpoint. No API key, no account, and no API rate limits you’ll ever reasonably hit. This page covers what they all have in common; each tool’s page documents its own parameters and fields.

One URL, six tools

Every lookup goes to https://notoolkit.com/. The parameter you send decides which tool answers.

ToolParametersTakesExample
IP → ASN LookupipAn IPv4 or IPv6 address or prefix./?ip=8.8.8.8
ASN Lookupasn, prefixesAn AS number. prefixes=true adds the prefix lists./?asn=AS13335
RPKI Validatorrpki, originA prefix, with the origin AS to validate. A lone AS lists its ROAs./?rpki=1.1.1.0/24&origin=AS13335
ASPA Validatoraspa, directionAn AS path, neighbor first. A lone AS shows its ASPA./?aspa=3356+13335
IRR Validatorirr, liveA prefix, AS number, as-set or maintainer./?irr=AS-EXAMPLE
MAC Address LookupmacA full or partial MAC address./?mac=00:1B:63:84:45:E6
# the same lookup, three ways curl -s "https://notoolkit.com/?ip=8.8.8.8" curl -s -I "https://notoolkit.com/?ip=8.8.8.8" # HEAD: headers only curl -s -X POST https://notoolkit.com/ -H 'Content-Type: application/json' -d '{"ip":"8.8.8.8"}'

How requests and responses work

These hold for every tool on the endpoint.

GETSending a request
GETParameters in the query string. HEAD is answered the same way, without a body.
POSTA JSON object with the same parameter names as keys, e.g. {"rpki":"1.1.1.0/24","origin":"AS13335"}. Bodies are limited to 512 bytes. The ASPA tool also takes its path as an array of AS numbers.
One lookupSend one lookup per request. If a request carries more than one, only one is answered, in this order: rpki, aspa, irr, mac, ip, asn. The exception: with rpki, an asn is read as the origin to validate.
AS numbers13335 and AS13335 both work, in any case. AS0 is not a valid query.
Booleanstrue, 1, yes and on all mean true, for prefixes and live.
PathOnly the root. An API parameter sent to any other path gets a 404. The old /api/ip-to-asn and /api/asn-lookup aliases still answer, with a message_to_user asking you to move to /.
JSONWhat comes back
FormatUTF-8 JSON with Content-Type: application/json. Most responses start with query, echoing what you sent.
ErrorsAn object with an error string, and usually the query too: {"error":"Invalid ASN: foo"}. The HTTP status says what kind of error it is.
FreshnessAnswers from mirrored data say how old it is: prefix_last_updated on IP lookups, the rpki block on RPKI and ASPA answers, and live on IRR answers that asked RADB.
CORSAccess-Control-Allow-Origin: * on every API response, and preflight OPTIONS requests are answered, so a page on any site can call the API directly.
HTTPStatus codes
StatusMeaning
200An answer. That includes answers like RPKI invalid or ASPA unknown: the verdict is in the body, not the status.
400The input is not something the tool can read, or no lookup parameter was sent. The error says what was wrong.
404Nothing matched: no route covers the address, no data exists for the AS, no IRR object or MAC assignment was found. Also returned for API calls to a path other than /.
503The database is unreachable, or the data a tool needs has not loaded yet. Retry after a short wait.

Where answers come from

Answers come from data we mirror and index ourselves. Only two things reach out to someone else’s server during a lookup: the RIR WHOIS for an AS we have not looked up in 14 days, and the IRR tool’s live queries to RADB.

ToolSourceRefreshed
IP → ASN, ASNRouteViews BGP tables; RIR WHOIS for registrant detailsEvery 4 hours; WHOIS cached 14 days
RPKI, ASPAROAs and ASPAs validated by our own RoutinatorEvery 10 minutes
IRRThe published dumps of every mirrored registry, plus live RADB queriesDumps every 4 hours; RADB live on a miss or live=true
MACThe IEEE registriesDaily

No API rate limits you’ll ever reasonably hit

There are none on any lookup answered from our own data, which is every lookup but one kind.

TodayNo enforced rate limit on IP → ASN, ASN, RPKI, ASPA or MAC lookups, or on IRR lookups answered from the mirrored registry data.
CourtesyPlease keep bulk jobs under 100 requests per second. It is not enforced, but there is real hardware behind this, and high-volume use is expected and welcome below that.
FutureIf abuse ever makes a limit necessary, it will sit well above normal use and be documented on this page.
IRRThe one exception: live queries to RADB

When the IRR tool asks whois.radb.net live, that is a real session on RADB’s servers, not ours. RADB limits how hard any one client may query it, and these limits exist at RADB’s request. They apply to nothing else: IRR answers from the mirrored dumps are not limited.

Live queryLimit
Requested with live=true6 a minute per client
Automatic, when the dumps have nothing20 a minute per client
Every client togetherA site-wide ceiling
A name RADB did not know eitherNot asked about again for 15 minutes

Past a limit you still get a 200 with an answer from the mirrored dumps, and live.skipped is rate_limited. The API never answers 429.

API Questions

Do I need an API key or an account?
No. There is no key, no account and no sign-up. Send a request to https://notoolkit.com/ and you get JSON back.
Is the API rate limited?
Not today, and not at any rate you’ll ever reasonably hit. Please keep bulk jobs under 100 requests per second as a courtesy. If abuse ever makes a limit necessary, it will sit well above normal use and be documented above. The one limit that exists is on the IRR tool’s live queries to RADB, at RADB’s request; IRR answers from the mirrored registry data are not limited.
Why are live IRR queries limited?
Every live query is a real whois session on RADB’s servers, not ours. RADB limits how hard any one client may query it, and our live lookups are limited at RADB’s request so this site stays a well-behaved client. You rarely need to ask for one: without live=true, RADB is still asked automatically when the mirrored dumps have nothing. Use it to confirm an object you have just changed, not for polling or bulk lookups.
Can I call the API from a web page?
Yes. Every API response carries Access-Control-Allow-Origin: * and preflight OPTIONS requests are answered, so a browser on any site can call it directly.
Why don’t the looking glass and the DNS, SMTP, SSL and STIR/SHAKEN tests have an API?
The DNS, SMTP, SSL and STIR/SHAKEN tests open connections from our servers to hosts and URLs you name, so they run from their pages only. The looking glass has no API yet while it settles. If you have a good use case for either, let us know at info at notoolkit dot com.
Something is wrong, or I need something the API doesn’t do.
Email info at notoolkit dot com with the request you sent and what came back.