New:Introducing Socket Scanning for VS Code Marketplace Extensions.Learn more →
Get Started

vpndetection-mcp

Package Overview
Dependencies
Maintainers
1
Versions
22
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

vpndetection-mcp

Official MCP server for the VPNDetection API. Gives an LLM agent VPN, proxy, Tor, hosting and CDN detection for any IP address.

latest
Source
npmnpm
Version
6.0.2
Version published
Maintainers
1
Created
Source

VPNDetection VPNDetection MCP Server

npm license

The official Model Context Protocol server for the VPNDetection API.

It gives an AI agent seven read-only tools for anonymity detection: whether an address belongs to a VPN, a residential, datacenter or mobile proxy, a Tor node, a public relay, a hosting provider or a CDN, plus the database catalog and where your organization's license for each one stands.

Getting Started

We host it at https://mcp.vpndetection.io/mcp, and you sign in to it with your VPNDetection account. It also runs on your own machine from npm.

In Claude

In claude.ai, the desktop app or Cowork, add https://mcp.vpndetection.io/mcp as a custom connector and choose Use Claude's published identity when asked. In Claude Code, install our plugin, which adds the server with skills:

/plugin marketplace add vpndetection-io/claude-plugin
/plugin install vpndetection@vpndetection

Either way you sign in with your VPNDetection account, and Claude never sees your API key. The steps, the skills and how to disconnect: docs.vpndetection.io/integrations/claude.

In any other MCP client

Point it at https://mcp.vpndetection.io/mcp. A client that supports MCP authorization signs in the same way. One that doesn't can send a key instead, as Authorization: Bearer your-key.

On your own machine

No API key needed to start. The free tier answers ip and is_vpn, and allows 1000 requests per day per source address.

Add this to your MCP client's config:

{
  "mcpServers": {
    "vpndetection": {
      "command": "npx",
      "args": ["-y", "vpndetection-mcp"]
    }
  }
}

Requires Node.js 22 or newer.

A key unlocks the provider name, the classification databases and the proxy families. Put it in the environment:

{
  "mcpServers": {
    "vpndetection": {
      "command": "npx",
      "args": ["-y", "vpndetection-mcp"],
      "env": { "VPNDETECTION_API_KEY": "your-key" }
    }
  }
}

VPNDETECTION_BASE_URL overrides the endpoint if you need to point somewhere else.

Tools

ToolWhat it answers
lookup_ipClassify one address.
lookup_ipsClassify a whole list of addresses in one call, keyed by address. A long list is batched for you.
my_entitlementWhat this key is entitled to and what it has spent: plan, field tier, requests so far, allowance, and when it resets.
list_databasesEvery database we publish, with its standing for your organization: licensed, expired or unlicensed.
database_metadataA database's columns, sample rows, row count, build date and file sizes.
database_checksumThe published digests for one database file.
list_downloadsYour organization's recent download attempts, refusals included.

Every tool is read-only. There is deliberately no download tool: the databases run to several GB, which is not something an agent should pull into a conversation. Fetch them with the client libraries or the API instead.

There is deliberately no my_ip tool, although every client library has one. Over a hosted transport the address our edge observes belongs to whatever proxied the call - Claude's infrastructure, not the person asking - so the tool would answer confidently and wrongly for the only reading anyone would put on it. my_entitlement has no such problem and is the same answer from any transport, because it describes the credential rather than the connection. A test pins the tool's absence so it cannot be added back by accident.

Usage counts against the anniversary of the subscription, not the calendar month and not the billing period. A null hard_limit means we never stop serving; it is not a limit of zero.

Reading a result

Each lookup comes back with a coverage block beside it:

{
  "result": { "ip": "45.83.91.1", "is_vpn": true },
  "coverage": {
    "included": ["ip", "is_vpn"],
    "not_included": ["is_hosting", "is_tor", "hosting", "tor", "..."],
    "note": "The fields in not_included were not returned, because this API key's plan does not include them. ..."
  }
}

This matters more here than in a normal client library. A field missing from a result means your plan doesn't include it, never "we checked and found nothing" - and a model reading the result on its own will otherwise treat the absence as a negative answer. coverage states the difference explicitly so it can't.

Other Libraries

There are official VPNDetection client libraries available for many languages including PHP, Python, Go, Java, Ruby, and many popular frameworks such as Django, Rails, and Laravel. See our GitHub at https://github.com/vpndetection-io for more.

About VPNDetection

VPN Detection API: Accurate anonymity detection identifying VPNs, residential proxies, hosting servers, Tor nodes, CDNs, relays and more.

VPNDetection

License

This project is licensed under the MIT License.

Keywords

mcp

FAQs

Package last updated on 10 Oct 2026

Related posts