VPNDetection 5.3.0

dotnet add package VPNDetection --version 5.3.0
                    
NuGet\Install-Package VPNDetection -Version 5.3.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="VPNDetection" Version="5.3.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="VPNDetection" Version="5.3.0" />
                    
Directory.Packages.props
<PackageReference Include="VPNDetection" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add VPNDetection --version 5.3.0
                    
#r "nuget: VPNDetection, 5.3.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package VPNDetection@5.3.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=VPNDetection&version=5.3.0
                    
Install as a Cake Addin
#tool nuget:?package=VPNDetection&version=5.3.0
                    
Install as a Cake Tool

<img src="https://s3.vpndetection.io/vpndetection-public/brand/mark.svg" alt="VPNDetection" height="28"/> VPNDetection .NET Client Library

NuGet license

The official .NET client library for the VPNDetection API.

The library helps you query VPNDetection's APIs for anonymity detection including VPNs, residential proxies, Tor nodes, hosting servers, CDNs, relays and more.

Getting Started

dotnet add package VPNDetection

Targets .NET 8 and newer.

Usage

No API key needed to start. The free tier answers ip and is_vpn, and allows 1000 requests per day per source address.

using VPNDetection;

using var client = new VpnDetectionClient();

var result = await client.LookupAsync("45.83.91.1");
Console.WriteLine(result.IsVpn);   // True

With an API key

An API key raises your quota, and raises your features on a paid plan. Create one in the console, then pass it in:

using var client = new VpnDetectionClient(new VpnDetectionClientOptions
{
    ApiKey = Environment.GetEnvironmentVariable("VPNDETECTION_API_KEY"),
});

var result = await client.LookupAsync("45.83.91.1");
Console.WriteLine(result.IsVpn);            // True
Console.WriteLine(result.Vpn?.Provider);    // mullvad
Console.WriteLine(result.IsHosting);        // True
Console.WriteLine(result.Hosting?.Provider);

Your own address

var result = await client.MyIpAsync();
Console.WriteLine(result.Ip);   // the address we saw this call come from

Same answer LookupAsync would give for that address, and the same cost against your allowance. It is deliberately not cached: which address you are is the whole question, and a machine that moves between networks would otherwise be told where it used to be.

Your plan and usage

var acct = await client.MyEntitlementAsync();
Console.WriteLine(acct.Plan.Key);         // max
Console.WriteLine(acct.Usage.Requests);   // 580
Console.WriteLine(acct.Usage.WindowEnd);  // when the allowance resets

Usage counts against the anniversary of your subscription, not the calendar month and not the billing period, and it is the same number a lookup is gated on. HardLimit is null on an uncapped plan, which is not the same as zero.

Batch lookup

Look up many addresses at once. Bogons and cached answers are handled locally, and everything else goes to the batch endpoint in chunks of up to 1000 addresses, in parallel:

var results = await client.LookupBatchAsync(new[] { "45.83.91.1", "8.8.8.8", "1.1.1.1" });

foreach (var (ip, answer) in results)
{
    if (!answer.IsSuccess)
    {
        Console.Error.WriteLine($"{ip}: {answer.Error!.Message}");
        continue;
    }
    Console.WriteLine($"{ip}: {answer.Result!.IsVpn}");
}

Results are keyed by address, in the order you first listed each one, so duplicates in your list collapse into a single entry and one address failing never loses the rest: it carries its error as its value, with the status the API would have given that address on its own.

How many chunks are in flight at once, how many times a failed chunk is retried, and how long each attempt at a chunk may take, are configurable per call:

var results = await client.LookupBatchAsync(manyIps, new BatchOptions
{
    Concurrency = 4,
    Retries = 4,
    RequestTimeout = TimeSpan.FromSeconds(10),
});

Caching

Answers are cached by default, so repeat lookups of the same address are free:

using var client = new VpnDetectionClient();

var result = await client.LookupAsync("45.83.91.1");
Console.WriteLine(result.IsVpn);    // True, API request

var result2 = await client.LookupAsync("45.83.91.1");
Console.WriteLine(result2.IsVpn);   // True, no API request, result was cached

You can change the default cache variables (max size, TTL, etc) on initialization, or even disable it:

using var client = new VpnDetectionClient(new VpnDetectionClientOptions
{
    CacheSize = 50_000,
    CacheTtl = TimeSpan.FromHours(6),
});

using var noCache = new VpnDetectionClient(new VpnDetectionClientOptions { CacheEnabled = false });

The cache belongs to the client instance, never to the process, because two keys can be on different plans and so entitled to different fields.

Private and reserved addresses

Private, loopback, link-local, documentation and multicast addresses (and their IPv6 equivalents, including the 6to4 and Teredo ranges) can never be VPN or proxy infrastructure. The library answers them locally, so they cost no request and no quota:

var result = await client.LookupAsync("192.168.1.1");
result.IsBogon;   // True, this answer was computed rather than served
result.IsVpn;     // False

The check is available on the client, which is handy when your inputs are addresses anyway:

client.IsBogon("10.0.0.1");   // True
client.IsBogon("8.8.8.8");    // False

It is also available on its own, if you want it without a client:

VPNDetection.Bogon.IsBogon("10.0.0.1");   // True

Errors

Failures throw a VpnDetectionException carrying a Kind and a Retryable flag:

try
{
    await client.LookupAsync("1.1.1.1");
}
catch (VpnDetectionException e)
{
    Console.Error.WriteLine($"{e.Kind} {e.Retryable} {e.StatusCode}");
}

Kind is one of BadRequest, Unauthorized, Forbidden, RateLimited, QuotaExceeded, ServerError or Network.

Note that RateLimited and QuotaExceeded both arrive as HTTP 429 and are not the same thing. A rate limit is when the API faces extreme traffic bursts and so retrying later works; but a spent quota needs your allowance raised or the window to roll over. The library retries rate limits for you, but not if your quota is exceeded.

Each attempt is abandoned after 30 seconds by default (RequestTimeout on the options), which fails as a retryable Network error. One call can set its own, longer or shorter:

var result = await client.LookupAsync("45.83.91.1", new LookupOptions { RequestTimeout = TimeSpan.FromSeconds(5) });

Database downloads

If your key carries the db.download scope, the licensed databases are available through client.Database. A license covers a database FAMILY, so the ids below come from its versions. DownloadAsync fetches one to a path, streaming it straight to disk so that nothing bigger than a chunk is ever held in memory; or take the bytes, or the time-limited link to run the transfer yourself:

var databases = await client.Database.ListAsync();
var id = databases[0].Versions[0].Id;                                            // "vpn_ip_extended_v1"

var written = await client.Database.DownloadAsync(id, DatabaseFormat.Mmdb, $"{id}.mmdb");
var bytes = await client.Database.DownloadBytesAsync("cdn_ip_v1", DatabaseFormat.Csvgz);
var url = await client.Database.DownloadUrlAsync(id, DatabaseFormat.Mmdb);

DownloadBytesAsync holds the whole file in memory, and the catalog runs from cdn_ip_v1 at 10 KB to resproxy_ip_90d_v1 at 1.79 GB, so use DownloadAsync for anything you have not measured.

Sign in with OAuth (device flow)

A program running on the person's own machine can let them sign in with a browser and pick one of their API keys, instead of asking them to paste it:

using var client = new VpnDetectionClient();

var device = await client.Oauth.DeviceAuthorizationAsync(
    "your-client-id", new DeviceAuthorizationOptions { Scope = "account.read apikeys.read apikeys.reveal" });
Console.WriteLine($"Open {device.VerificationUri} and enter {device.UserCode}");

var token = await client.Oauth.PollDeviceTokenAsync("your-client-id", device);
if (token.Apikey is null)
{
    throw new InvalidOperationException("no API key came back: none was picked, or it can't be shown again");
}
using var keyed = new VpnDetectionClient(new VpnDetectionClientOptions { ApiKey = token.Apikey });

A denied sign-in throws OauthAccessDeniedException and a code that ran out OauthExpiredTokenException. Client IDs are issued on request from support@vpndetection.io, and client.Oauth.RevokeAsync("your-client-id", token.RefreshToken) signs the machine out again.

Dependency injection

The client takes an HttpClient, so it registers as a typed client and picks up your handler pipeline, pooling and resilience policies:

services.AddSingleton(new VpnDetectionClientOptions { ApiKey = builder.Configuration["VpnDetection:ApiKey"] });
services.AddHttpClient<VpnDetectionClient>()
    .ConfigurePrimaryHttpMessageHandler(() => new HttpClientHandler { AllowAutoRedirect = false });

AllowAutoRedirect = false matters: the database download endpoint answers 302 with the link this library hands back, and .NET's default handler would follow it and fetch the whole database instead. A client that follows redirects is refused with a clear error rather than quietly downloading gigabytes.

A borrowed HttpClient keeps its own Timeout, so RequestTimeout on the options does not apply to it; a per-call RequestTimeout still does.

Absent is not false

Only Ip and IsVpn come back on every plan. The rest are bool?, where null means "not in your plan" rather than "checked, and no".

result.IsHosting ?? false   // when you only want the flag
result.IsHosting is null    // not in your plan

Other Libraries

There are official VPNDetection client libraries available for many languages including PHP, Python, Go, Java, Ruby, and many popular frameworks such as Django, Rails, and Laravel. See our GitHub at https://github.com/vpndetection-io for more.

About VPNDetection

VPN Detection API: Accurate anonymity detection identifying VPNs, residential proxies, hosting servers, Tor nodes, CDNs, relays and more.

<img src="https://s3.vpndetection.io/vpndetection-public/brand/mark.svg" alt="VPNDetection" height="64"/>

License

This project is licensed under the MIT License.

Product Compatible and additional computed target framework versions.
.NET net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 was computed.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages (1)

Showing the top 1 NuGet packages that depend on VPNDetection:

Package Downloads
VPNDetection.AspNetCore

The official ASP.NET Core middleware for the VPNDetection API. Classifies the visitor behind each request - VPN, residential proxy, Tor, hosting, CDN, relay - and puts the answer on HttpContext. Blocking is opt-in.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
5.3.0 45 9/27/2026
5.2.4 104 9/23/2026
5.2.3 76 9/22/2026
5.2.2 85 9/22/2026
5.2.1 121 9/16/2026
5.2.0 95 9/16/2026
5.1.0 95 9/15/2026
5.0.0 113 9/15/2026
4.0.0 108 9/13/2026
3.2.0 111 9/13/2026
3.1.0 90 9/13/2026
3.0.0 101 9/13/2026
2.0.0 90 9/13/2026
1.4.0 124 9/9/2026
1.3.0 106 9/9/2026
1.2.0 102 9/9/2026
1.1.1 104 9/5/2026
1.0.0 118 9/4/2026