RoutingJSON APIValidated by Routinator · refreshed every 10 minutes

ASPA Validator

Check an AS path against every published ASPA, find out whether it is valley-free, and see exactly which hop leaked it. Free. No API key. No API rate limits you’ll ever reasonably hit.

Verify an AS path

Paste a path the way your router prints it: neighbor first, origin last. Say whether the route came from a provider or from a customer or peer. Enter a single AS to see the ASPA it publishes.

3,397 validated ASPAs·refreshed 9m 15s ago·validated by Routinator alongside 1,012,908 ROA payloads
Received from
Examples: 3356 13335 6939 3356 15169 3356 13335 from a peer with an AS_SET ASPA of AS13335
JSON Response
Enter an AS path above and click Verify to see the response.

API Documentation

The parameters and fields for this tool. Keys, errors, CORS and rate limits work the same for every tool: see the API guide.

GET/?aspa={as_path}&direction={downstream|upstream}

Verify an AS path against the current validated ASPA set. Both procedures are always run; direction picks which one is reported as state. A lone AS number instead returns the ASPA that AS publishes and the ASes that name it as a provider.

ParameterTypeDescription
aspastringThe AS path, neighbor first and origin last, as a router prints it. Separate ASes with spaces, commas or >; AS prefixes and prepends are fine; an AS_SET is written {64512,64513}. Or a single AS number.
directionstringOptional. downstream (default) for a route received from a provider; upstream for one received from a customer, a lateral peer or a route server. provider, customer and peer are accepted too.
# verify a path received from a provider curl -s "https://notoolkit.com/?aspa=3356+1299+13335" | jq '{state, reason}' # the same path, as though a customer had sent it curl -s "https://notoolkit.com/?aspa=3356+1299+13335&direction=upstream" | jq .state # the ASPA an AS publishes, and who names it as a provider curl -s "https://notoolkit.com/?aspa=AS13335" | jq .
POST/

The same lookup with a JSON body. The path may be a string or an array of AS numbers. Bodies are limited to 512 bytes.

curl -s -X POST https://notoolkit.com/ \ -H 'Content-Type: application/json' \ -d '{"aspa":[3356,1299,13335],"direction":"downstream"}' | jq .
GETResponse fields: a path
FieldDescription
as_pathThe path as read, normalized: "3356 1299 13335".
compressed_pathThe ASes verification ran on, neighbor first, with prepends collapsed. AS_SET members are not included.
neighbor_asn, origin_asnThe first and last AS. origin_asn is null when the path ends in an AS_SET.
directionWhich procedure state and reason report.
statevalid, invalid or unknown.
reasonA sentence explaining the state. For invalid it names the hop, and where it can, the AS that leaked the route.
upstream, downstreamBoth procedures’ state and reason, whichever you asked for.
rampsThe draft’s max_up, min_up, max_down and min_down: how far the path reads as climbing from the origin and descending to the neighbor.
hopsOne entry per hop, in the order the route travelled (origin first): sender, receiver, and whether each one’s ASPA names the other as a provider: receiver_is_provider and sender_is_provider, each provider+, not-provider+ or no-attestation.
aspasEvery AS on the path, neighbor first, with published, its providers and trust anchor. A provider of 0 (AS0) means the AS declares it has none.
rpkiHow many ASPAs the set holds, when it was refreshed, and whether that copy is stale.
GETResponse fields: a single AS
FieldDescription
publishedWhether this AS publishes a valid ASPA.
providersThe providers it names (provider_count of them), and its trust anchor in ta.
customersASes whose ASPA names this AS as a provider, up to 1,000; customer_count is the true total and customers_truncated says whether the list was cut.

Common Questions

What is ASPA?
Autonomous System Provider Authorization: a signed RPKI object in which an AS lists its upstream transit providers. Route origin validation only checks the last AS on a path; ASPA checks the rest of it. With providers published, a receiver can tell whether a path is valley-free: whether the route only climbed customer-to-provider, crossed at most one peering link at the top, and then only came down. A path that goes down and then up again was leaked somewhere along the way.
Upstream or downstream: which do I pick?
Whichever matches who sent you the route. From one of your providers, use downstream: the path may climb, peer once, and descend. From a customer, a lateral peer or a route server, use upstream: the path may only climb, because anything else means someone passed you a route they should have kept. The tool runs both every time and shows the other one underneath, so you can see how the same path reads either way.
Why is my path Unknown?
Nothing on it contradicts a published ASPA, but at least one AS along it has not published one, so the hops through it cannot be checked. That is the normal result while adoption grows and it is not a sign of a problem. The reason names the ASes whose missing ASPA left it undecided. Networks that filter on ASPA drop Invalid paths and accept Unknown ones.
My path is Invalid. Is it really a leak?
Either it is, or an ASPA on the path is missing a provider. The reason says which hop broke the rule and, when the shape allows, which AS passed the route on. If that AS is yours, check that your ASPA lists every provider you have, including the backup transit you only use during an outage. A provider missing from your ASPA makes every path through it look like a leak.
How do I publish an ASPA?
Through your RIR’s hosted RPKI, or your own delegated CA, the same place you create ROAs. List every transit provider for your AS, for both IPv4 and IPv6. Do not list peers, customers or route servers. An AS with no providers at all, like a tier 1, publishes an ASPA naming only AS0. Once it validates, enter your AS above to see it.
Where does the data come from?
From Routinator, running here as part of NoToolkit with ASPA enabled. It validates the ASPA objects from all five RIR trust anchors along with the ROAs, and the set is mirrored every ten minutes. Verification follows draft-ietf-sidrops-aspa-verification. The one check it cannot make for you is that the first AS on the path is the neighbor you actually got the route from. Only your router knows that.