Back to Browse

Mcp MCP Server

Developer ToolsModerate5.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

VPN, proxy, Tor, hosting and CDN detection for any IP address, from the VPNDetection API.

About

VPN, proxy, Tor, hosting and CDN detection for any IP address, from the VPNDetection API.

Remote endpoints: streamable-http: https://mcp.vpndetection.io/mcp

Security Report

5.2
Moderate5.2Moderate Risk

This is a well-engineered MCP server for the VPNDetection API with strong security practices. Authentication is properly handled via API keys (stored in environment variables, not hardcoded), all tools are read-only with appropriate scope, and input validation is thorough using Zod schemas. The codebase shows careful attention to error handling, preventing information leakage, and explicit design decisions (e.g., deliberately omitting a `my_ip` tool to prevent misuse over hosted transports). Minor code quality findings around broad exception handling and logging do not materially impact security. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.

5 files analyzed · 7 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Your VPNDetection API key; lookups answer without one, with fewer fieldsRequired

Environment variable: VPNDETECTION_API_KEY

Overrides the API endpointOptional

Environment variable: VPNDETECTION_BASE_URL

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

VPNDetection MCP Server

npm license

The official Model Context Protocol server for the VPNDetection API.

It gives an AI agent seven read-only tools for anonymity detection: whether an address belongs to a VPN, a residential, datacenter or mobile proxy, a Tor node, a public relay, a hosting provider or a CDN, plus the database catalog and where your organization's license for each one stands.

Getting Started

We host it at https://mcp.vpndetection.io/mcp, and you sign in to it with your VPNDetection account. It also runs on your own machine from npm.

In Claude

In claude.ai, the desktop app or Cowork, add https://mcp.vpndetection.io/mcp as a custom connector and choose Use Claude's published identity when asked. In Claude Code, install our plugin, which adds the server with skills:

/plugin marketplace add vpndetection-io/claude-plugin
/plugin install vpndetection@vpndetection

Either way you sign in with your VPNDetection account, and Claude never sees your API key. The steps, the skills and how to disconnect: docs.vpndetection.io/integrations/claude.

In any other MCP client

Point it at https://mcp.vpndetection.io/mcp. A client that supports MCP authorization signs in the same way. One that doesn't can send a key instead, as Authorization: Bearer your-key.

On your own machine

No API key needed to start. The free tier answers ip and is_vpn, and allows 1000 requests per day per source address.

Add this to your MCP client's config:

{
  "mcpServers": {
    "vpndetection": {
      "command": "npx",
      "args": ["-y", "vpndetection-mcp"]
    }
  }
}

Requires Node.js 22 or newer.

A key unlocks the provider name, the classification databases and the proxy families. Put it in the environment:

{
  "mcpServers": {
    "vpndetection": {
      "command": "npx",
      "args": ["-y", "vpndetection-mcp"],
      "env": { "VPNDETECTION_API_KEY": "your-key" }
    }
  }
}

VPNDETECTION_BASE_URL overrides the endpoint if you need to point somewhere else.

Tools

ToolWhat it answers
lookup_ipClassify one address.
lookup_ipsClassify a whole list of addresses in one call, keyed by address. A long list is batched for you.
my_entitlementWhat this key is entitled to and what it has spent: plan, field tier, requests so far, allowance, and when it resets.
list_databasesEvery database we publish, with its standing for your organization: licensed, expired or unlicensed.
database_metadataA database's columns, sample rows, row count, build date and file sizes.
database_checksumThe published digests for one database file.
list_downloadsYour organization's recent download attempts, refusals included.

Every tool is read-only. There is deliberately no download tool: the databases run to several GB, which is not something an agent should pull into a conversation. Fetch them with the client libraries or the API instead.

There is deliberately no my_ip tool, although every client library has one. Over a hosted transport the address our edge observes belongs to whatever proxied the call - Claude's infrastructure, not the person asking - so the tool would answer confidently and wrongly for the only reading anyone would put on it. my_entitlement has no such problem and is the same answer from any transport, because it describes the credential rather than the connection. A test pins the tool's absence so it cannot be added back by accident.

Usage counts against the anniversary of the subscription, not the calendar month and not the billing period. A null hard_limit means we never stop serving; it is not a limit of zero.

Reading a result

Each lookup comes back with a coverage block beside it:

{
  "result": { "ip": "45.83.91.1", "is_vpn": true },
  "coverage": {
    "included": ["ip", "is_vpn"],
    "not_included": ["is_hosting", "is_tor", "hosting", "tor", "..."],
    "note": "The fields in not_included were not returned, because this API key's plan does not include them. ..."
  }
}

This matters more here than in a normal client library. A field missing from a result means your plan doesn't include it, never "we checked and found nothing" - and a model reading the result on its own will otherwise treat the absence as a negative answer. coverage states the difference explicitly so it can't.

Other Libraries

There are official VPNDetection client libraries available for many languages including PHP, Python, Go, Java, Ruby, and many popular frameworks such as Django, Rails, and Laravel. See our GitHub at https://github.com/vpndetection-io for more.

About VPNDetection

VPN Detection API: Accurate anonymity detection identifying VPNs, residential proxies, hosting servers, Tor nodes, CDNs, relays and more.

License

This project is licensed under the MIT License.

Reviews

No reviews yet

Be the first to review this server!