Quick start
Example output below uses 192.0.2.1, a reserved documentation address that never belongs to a real device. When you run these commands you will see your own IP.
$ curl iseeu.cc
192.0.2.1
$ curl -s iseeu.cc/json | jq '{ip, country: .location.country, asn: .network.asn, tls: .tls.version}'
{
"ip": "192.0.2.1",
"country": "US",
"asn": 7922,
"tls": "TLSv1.3"
}
The home URL decides what to return from your Accept header: browsers ask for text/html and get the page; curl, wget, HTTPie, PowerShell and HTTP libraries do not, and get a single line with your IP address and a newline.
Endpoints
| Path | Returns |
|---|---|
| / | Your IP as plain text (non-browser clients) or the web page (browsers) |
| /ip | Your IP as plain text, always |
| /json | Everything: IP, location, network, TLS, HTTP, parsed User-Agent, request headers, server time |
| /geo | IP, location, ASN, organization and Cloudflare data center |
| /tls | TLS version, cipher, ClientHello size, cipher and extension hashes, HTTP version |
| /ua | Your User-Agent, parsed into browser, engine, OS, device and client type |
| /headers | Request headers you sent, and the ones Cloudflare added |
| /api/rdap?q= | RDAP registration data for a domain, IP address or CIDR, or AS number, from the registry IANA lists for it: a summary plus the raw RDAP JSON |
| /api/headers-check?url= | Response headers of a public URL (redirects followed, body never read) with a security grade |
| /mcp | MCP server (Streamable HTTP, stateless) — see below |
Add ?format=text (or send Accept: text/plain) to any JSON endpoint for flat key: value lines, handy with grep. curl "iseeu.cc/ua?format=text" prints only the User-Agent string. The machine-readable description is at /openapi.json (OpenAPI 3.1).
The /json object
An example response (again with the reserved example address 192.0.2.1):
{
"ip": "192.0.2.1",
"ipVersion": 4,
"location": {
"country": "US", "countryName": "United States",
"region": "Texas", "regionCode": "TX", "city": "Austin",
"postalCode": "78701", "metroCode": "635", "continent": "NA",
"isEU": false, "latitude": 30.27, "longitude": -97.74,
"timezone": "America/Chicago"
},
"network": { "asn": 7922, "asOrganization": "Comcast Cable", "colo": "DFW",
"clientTcpRttMs": 22, "clientQuicRttMs": null, "deliveryRateBps": null },
"tls": { "version": "TLSv1.3", "cipher": "AEAD-AES128-GCM-SHA256", "clientHelloLength": 508,
"clientCiphersSha1": "…", "clientExtensionsSha1": "…" },
"http": { "protocol": "HTTP/2", "method": "GET", "priority": null, "acceptEncoding": "gzip, br" },
"userAgent": { "raw": "curl/8.9.1", "browser": {…}, "engine": {…}, "os": {…},
"device": {…}, "cpu": {…}, "kind": "cli", "bot": { "name": "curl", "kind": "cli", "operator": null } },
"headers": { "accept": "*/*", "host": "iseeu.cc", "user-agent": "curl/8.9.1" },
"edgeHeaders": { "cf-ray": "…", "cf-ipcountry": "US", … },
"time": { "server": "2026-10-08T12:00:00.000Z", "serverMs": 1791460800000 },
"meta": { "docs": "https://iseeu.cc/api/", "privacy": "https://iseeu.cc/privacy/", "simulated": false }
}
Missing values are null, never omitted, so the shape is stable. Location and network data come from Cloudflare's IP intelligence for the address you connected from; they describe your provider's network, not a street address. tls.clientCiphersSha1 and clientExtensionsSha1 are Cloudflare's hashes of your ClientHello, not JA3 or JA4. Chrome randomises the order of its TLS extensions, so its extensions hash usually changes between connections; the cipher hash is the steadier of the two. userAgent.kind is one of browser, search-crawler, ai-crawler, ai-assistant, social-preview, http-library, cli, headless-browser, monitoring, bot or unknown.
Common uses
Check that a VPN or proxy is active before a job runs. Compare the exit country with the one you expect and stop if it is wrong:
country=$(curl -s "iseeu.cc/geo?format=text" | awk -F': ' '$1=="country"{print $2}')
[ "$country" = "DE" ] || { echo "VPN not in Germany (got $country)"; exit 1; }
Find a server's public address from inside a container, a CI runner or a cloud function, where the network interface only shows a private address. curl -s iseeu.cc is enough, and the trailing newline makes it safe to use in shell substitution.
See what your HTTP client really sends. Libraries add, rename and reorder headers. Call /headers from your code to see the exact set, or /tls to confirm which TLS version and cipher your runtime negotiates.
From other languages:
// JavaScript (browser or Node 18+)
const me = await (await fetch("https://iseeu.cc/json")).json();
# Python
import requests; me = requests.get("https://iseeu.cc/json", timeout=5).json()
// Go
resp, _ := http.Get("https://iseeu.cc/ip")
# PowerShell
(Invoke-RestMethod https://iseeu.cc/json).location.country
Lookups that leave iseeu.cc
/api/rdap and /api/headers-check make one outbound request each, so they have their own, lower limit: 10 calls a minute per IP address, answered with 429 and Retry-After: 60 beyond that. RDAP queries only ever go to servers listed in IANA's bootstrap registry. The headers check accepts public http/https URLs on ports 80 and 443, refuses private and reserved addresses, follows up to five redirects and gives up after five seconds. Neither endpoint stores the query.
curl -s "iseeu.cc/api/rdap?q=AS64496" | jq .summary
curl -s "iseeu.cc/api/headers-check?url=https://example.com/" | jq '.grade | {grade, score}'
Limits and fair use
- 60 requests per minute per IP address. Over that you get
429withRetry-After: 60. The limit is counted per Cloudflare location, so it is approximate. - Responses are never cached (
Cache-Control: no-store) and carryAccess-Control-Allow-Origin: *, so browser JavaScript on any site can call them. - Commercial use is fine. Please don't put
/jsonbehind a page that every one of your visitors loads; at that scale, contact us first. - If 60 requests a minute is genuinely not enough for what you are building, tell us about it via the contact page.
MCP server for AI agents
https://iseeu.cc/mcp is a remote Model Context Protocol server over Streamable HTTP. It is stateless and needs no authentication. Every tool is read-only; dns_lookup and rdap_lookup share the 10-a-minute limit for outbound lookups.
| Tool | Input | What it does |
|---|---|---|
| whoami | include_headers? | Public IP, location, ASN and organization, Cloudflare data center, TLS and HTTP version, client type of the machine calling the server |
| check_headers | headers? (name → value) | Reviews a header set the way bot-detection does: missing User-Agent or Accept-Language, Chrome without Client Hints, mismatched versions or platforms, proxy headers that leak an IP, DNT and GPC. Omit the input to check the call's own headers. |
| parse_ua | user_agent? | Parses a User-Agent into browser, engine, OS, device and CPU, and classifies crawlers, AI agents, CLIs and libraries |
| dns_lookup | name, type? | A, AAAA, MX, TXT, NS, CNAME, CAA or SOA records through Cloudflare's resolver over DNS-over-HTTPS, with TTLs and the DNSSEC flag |
| rdap_lookup | query, include_raw? | Registration summary for a domain, IP address or AS number from the authoritative RDAP server |
Connect
# Claude Code
claude mcp add --transport http iseeu https://iseeu.cc/mcp
# Cursor, Windsurf, VS Code and other JSON configs
{ "mcpServers": { "iseeu": { "url": "https://iseeu.cc/mcp" } } }
An honest note on whoami: it reports whichever machine sends the HTTP request to /mcp. For desktop and command-line agents that is your own network, which makes it useful for checking whether a proxy or VPN is in effect. For assistants that run in the cloud, it is the provider's server.
Discovery files
- /llms.txt — a short plain-text guide for language models
- /.well-known/mcp/server-card.json — MCP server card
- /openapi.json — OpenAPI 3.1 description of the HTTP endpoints
Privacy
The API keeps no logs and no database. Responses are built from the request in memory and discarded; we count calls per endpoint without IP addresses. Details are on the privacy page.
The API is provided as is, without uptime guarantees. Location and network data can be wrong. Don't use it as the only signal for security or fraud decisions.