FlowRunner
PricingContact
Theme
Start Free

IPGeolocation.io

Analytics & Data

Look up geolocation, currency, ASN, company, and network data for any IP address with ipgeolocation.io. Agents localize content and score risk from a single lookup.

12 actions API key available
Firewall exports a sustained burst of blocked requests from one address
Lookup IP Security returns the threat score and the Tor, VPN and known-attacker flags
Lookup ASN identifies the announcing network and whether it belongs to a cloud provider
Lookup Abuse Contact returns the registered abuse address for that range
Agent confirms the range does not belong to an existing customer's network
Draft abuse report is posted to the security channel with the evidence attached
Security lead sends the report, edits it, or drops it

What This Integration Enables

ipgeolocation.io is the option to reach for when the question is not only where an address is but what it belongs to and what time it is there. One geolocation call returns location, currency, company, ASN and network alongside the time zone. A separate security call returns a threat score with flags for Tor, proxy, residential proxy, VPN, relay, anonymizer, known attacker, bot, spam and cloud provider, each with a provider name and a confidence score. A third set of calls handles time properly: full time zone detail with DST transitions, conversion between two places addressed as IANA names, coordinates, city names, IATA or ICAO airport codes or UN/LOCODEs, and sun and moon data including golden hour windows over a range of up to 90 days.

That combination makes it the practical pick for time-aware operations. FlowRunner agents use it to route work to the region that is awake, to hold a send until a reasonable local hour, and to schedule field work against daylight rather than clock time. The user agent parser separates real visitors from bots by reporting malformed and scripted strings as Hacker. Bulk variants handle up to 50,000 entries per request for geolocation, security screening and user agent parsing, so the same logic runs over a live request or over a quarter of logs.

Without FlowRunner

Three vendors for one question Geolocation, threat data and ASN ownership come from separate tools with separate keys
Abuse reports written by hand Someone looks up the responsible operator in a WHOIS console and drafts the mail
Scheduling logic guesses the offset Time zone maths is hardcoded per region and breaks twice a year on DST transitions

With FlowRunner

One lookup answers the whole question Location, currency, ASN, company and threat posture all resolve from the same address
Report assembled with its evidence The abuse contact, the threat flags and the offending range arrive together as a draft
Offsets read from the source DST state and transition dates come back with the time zone, so scheduling follows the real calendar

Use Case Scenarios

Follow-the-sun routing that actually follows the sun

An inbound support ticket arrives at 03:00 in the region that owns the account. The agent resolves the requester's address with Lookup IP Geolocation, reads the time zone with its current DST state from Get Time Zone, and routes the ticket to the on-call team whose local business hours are open right now rather than to the account's nominal region. When the ticket needs the account owner specifically, Convert Time Between Time Zones works out what the handoff time is in both places and the agent schedules the callback into a slot that is civil at both ends before writing it back to Zendesk.

Screening a checkout queue in batches

A payments team wants to know which of last week's declined checkouts came from anonymizing infrastructure. The agent pulls the distinct addresses, runs Lookup IP Security In Bulk over the set, and gets one security object per address with the threat score, the proxy and VPN provider names and their confidence values. It joins the result back to the Stripe records and produces a queue ordered by threat score. Nothing is blocked. The output is a ranked review list, because a proxy is evidence, not a verdict.

Daylight-aware field scheduling

A crew scheduling flow needs to place outdoor inspections inside usable light. For each site the agent calls Get Astronomy Time Series across the next 90 days and reads sunrise, sunset, day length and the civil twilight window per day. It builds the schedule against real daylight for that latitude and season, which matters far more at high latitudes than a fixed nine-to-five, then writes the shifts back to the scheduling system and posts the week's plan to Slack.

Human-in-Loop Highlight

The irreversible act on this connector is not a lookup, it is an accusation. Lookup Abuse Contact hands the agent the registered abuse mailbox for the network operator responsible for a range, and sending an abuse report to that mailbox is an outbound claim against a named organization that cannot be unsent. It is also frequently wrong in an expensive way, because the announcing ASN is often a large cloud provider that hosts one of your own customers. So the agent assembles the case and stops. It posts to the security channel: "Address 203.0.113.44, 2,140 blocked requests in six hours. Threat score 88, flagged as known attacker and VPN. ASN 64512, announced by CloudCo, abuse contact [email protected]. No matching customer network. Draft report attached. Send, edit, or drop?" A person makes the call. This is the digital andon cord in its plainest form: the agent did every piece of work up to the point where the consequence leaves the building, and then it stopped.

Agent processes routinely
Detects exception requiring judgment
Clear match Continues automatically
Ambiguous Routes to human via preferred channel
Human decides
Agent resumes with decision

Agent Capabilities

12 actions

IP Intelligence

6
  • Lookup IP Geolocation Returns geolocation, currency, ASN, company, network and time zone data for a single IPv4 address, IPv6 address or domain name. Leave the address empty to look up the caller IP. Optional modules for security, abuse contact, user agent, hostname, geo accuracy and DMA code are paid-plan features that cost extra credits, and the Fields and Excludes options trim the response on every plan.
  • Lookup IP Geolocation In Bulk Looks up geolocation for up to 50,000 addresses or domain names in one request, returning a result object per entry. Requires a paid plan. Credits are charged per valid entry, and bogon, private and malformed addresses are not charged. Used for log backfills and audience enrichment.
  • Lookup IP Security Returns threat intelligence for a single address, including a threat score and flags for Tor, proxy, residential proxy, VPN, relay, anonymizer, known attacker, bot, spam and cloud provider usage, with provider names and confidence scores. Each lookup costs 2 credits. Used to rank a review queue rather than to auto-block.
  • Lookup IP Security In Bulk Screens up to 50,000 addresses for proxy, VPN, Tor, bot and attacker activity in one request. Used to score signup, checkout or login logs in batches after the fact.
  • Lookup ASN Returns Autonomous System details for an ASN or for the ASN announcing a given address, including organization, country, ASN type, domain, RIR, allocation date and IPv4 and IPv6 route counts, and optionally expands BGP peers, upstreams, downstreams, announced routes and the raw WHOIS record. Used to answer who actually owns the network before anyone acts on it.
  • Lookup Abuse Contact Returns the registry abuse contact responsible for an address: the abuse-handling CIDR range, contact name, organization, kind, registered address, emails and phone numbers. Used to address a takedown or abuse report to the correct operator instead of guessing.

Time Zone

2
  • Get Time Zone Returns the current date, time and full time zone detail for a location, including UTC offset, DST state, DST start and end transitions, abbreviations, week number and unix time. The location can be an IANA name, coordinates, a city address, an address, an IATA or ICAO airport code, or a UN/LOCODE. Used before anything is scheduled or sent into a local hour.
  • Convert Time Between Time Zones Converts a timestamp from one place to another and returns the original time, the converted time and the offset difference in hours and minutes. Source and target may each be given as IANA names, coordinates, city addresses, IATA or ICAO codes or UN/LOCODEs, using the same style on both sides. Omit the time to convert the current moment.

Astronomy

2
  • Get Astronomy Data Returns sun and moon data for one date and location: sunrise, sunset, solar noon, day length, moonrise, moonset, moon phase and illumination, altitude, azimuth and distance for both bodies, and the civil, nautical, astronomical, blue hour and golden hour windows. Used to plan work that depends on light rather than on the clock.
  • Get Astronomy Time Series Returns a day-by-day array of the same sun and moon data across a date range of up to 90 days, past or future, at one location. Used to build daylight-aware schedules and seasonal calendars in a single call.

User Agent

2
  • Parse User Agent Parses a User-Agent string into structured browser, rendering engine, operating system and device detail with name, type, version and major version for each. Device types include Desktop, Mobile, Tablet, TV, Game Console and Robot, and malformed or scripted strings are reported as Hacker, which makes this a practical bot and crawler signal.
  • Parse User Agents In Bulk Parses up to 50,000 User-Agent strings in one request, one structured result per string. Requires a paid plan and charges one credit per string. Used to classify traffic logs and split real visitors from bots and crawlers in batches.

Frequently Asked Questions

What can FlowRunner do with IPGeolocation.io?

FlowRunner agents can run Lookup IP Geolocation, Lookup IP Geolocation In Bulk, and Lookup IP Security in IPGeolocation.io, plus 9 more actions.

Does connecting IPGeolocation.io to FlowRunner require OAuth?

No. IPGeolocation.io connects to FlowRunner with an API key, no OAuth flow required.

Can IPGeolocation.io trigger a FlowRunner workflow automatically?

IPGeolocation.io doesn't currently expose triggers in FlowRunner. It connects as an action step inside workflows started by another trigger.

Start building with IPGeolocation.io

$100 in credits. No card required. Connect in minutes.