RoutingJSON APIEvery mirrored registry at once · refreshed 4-hourly

IRR Validator

Route objects, as-sets, aut-nums and maintainers across every routing registry we mirror, searched together. Free. No API key. No rate limits on the mirrored registry data. Only live queries to RADB are limited, at RADB’s request.

Look something up

A prefix, an AS number, an as-set, a route-set or a maintainer handle. It works out which you meant.

4,740,918 route objects across 17 registries·oldest refreshed 29m 25s ago
Examples: 193.0.0.0/21 AS3333 AS-RIPENCC 8.8.8.0/24 RIPE-NCC-MNT
JSON Response
Enter a prefix, AS, as-set or maintainer above and click Look up.

What is mirrored

Each registry’s published database dump, re-imported every four hours. A registry whose import fails keeps the objects it already had rather than disappearing.

APNIC
889,208 route · 1,059,587 route6
5,893 sets · 26,160 aut-nums
Updated 27m 52s ago
RADB
1,143,541 route · 198,986 route6
18,874 sets · 10,088 aut-nums
Updated 28m 14s ago
RIPE
470,091 route · 116,215 route6
31,362 sets · 39,995 aut-nums
Updated 28m 25s ago
NTTCOM
285,678 route · 6,113 route6
907 sets · 575 aut-nums
Updated 29m 1s ago
ARIN
154,835 route · 45,715 route6
9,238 sets · 4,349 aut-nums
Updated 29m 6s ago
AFRINIC
123,049 route · 5,178 route6
1,693 sets · 2,803 aut-nums
Updated 29m 2s ago
LEVEL3
68,928 route · 1,532 route6
13,422 sets · 307 aut-nums
Updated 54s ago
TC
33,141 route · 16,519 route6
16,644 sets · 5,328 aut-nums
Updated 29m 16s ago
ALTDB
28,233 route · 8,050 route6
2,447 sets · 2,049 aut-nums
Updated 29m 21s ago
BELL
29,268 route · 94 route6
51 sets · 108 aut-nums
Updated 29m 22s ago
LACNIC
15,017 route · 5,309 route6
2,438 sets · 3,016 aut-nums
Updated 1m 9s ago
REACH
16,738 route · 1,284 route6
5 sets · 2 aut-nums
Updated 29m 21s ago
JPIRR
14,250 route · 1,388 route6
357 sets · 486 aut-nums
Updated 29m 22s ago
CANARIE
1,224 route · 355 route6
123 sets · 177 aut-nums
Updated 29m 25s ago
BBOI
1,224 route · 157 route6
46 sets · 71 aut-nums
Updated 29m 25s ago
PANIX
8 route · 1 route6
4 sets · 1 aut-nums
Updated 29m 25s ago
NESTEGG
2 route · 0 route6
0 sets · 2 aut-nums
Updated 29m 25s ago

API Documentation

The parameters and fields for this tool. Keys, errors, CORS and rate limits work the same for every tool: see the API guide.

GET/v1/irr/{query}

Look a prefix, AS number, as-set, route-set or maintainer handle up across every mirrored registry. The response’s kind field says which of those the input was taken to be, and the rest of the body depends on it.

ParameterTypeDescription
irrstringA prefix (193.0.0.0/21), a bare address, an AS number (AS3333), a set name (AS-RIPENCC, RS-EXAMPLE, AS3333:AS-CUSTOMERS) or a maintainer handle.
livebooleanOptional. Use sparingly. true queries whois.radb.net directly before answering, instead of only reading the mirrored dumps, and updates the mirror if the live objects differ. Every live query is a real session on RADB’s servers, so it is limited, at RADB’s request, to 6 per minute per client (see rate limits) and is meant for checking an object you have just changed, not for polling, scripts or bulk lookups. Past the limit the answer comes from the mirror, with live.skipped set to rate_limited. You rarely need it: without it, RADB is still asked automatically when the dumps have nothing. Lookups answered from the mirror have no rate limit.
# what is registered for a prefix, and by whom curl -s "https://api.notoolkit.com/v1/irr/193.0.0.0/21" | jq . # every route object an AS has registered curl -s "https://api.notoolkit.com/v1/irr/AS3333" | jq '.route_objects' # expand an as-set to the prefix list a filter from it would hold curl -s "https://api.notoolkit.com/v1/irr/AS-RIPENCC" | jq -r '.prefixes.ipv4[]' # or just the member ASes curl -s "https://api.notoolkit.com/v1/irr/AS-RIPENCC" | jq '.expanded_asns' # everything one maintainer is listed on curl -s "https://api.notoolkit.com/v1/irr/RIPE-NCC-MNT" | jq . # a route object registered minutes ago: ask RADB live (sparingly: 6 a minute) curl -s "https://api.notoolkit.com/v1/irr/192.0.2.0/24?live=true" | jq '.live'
POST/

The same lookup with a JSON body.

curl -s -X POST https://api.notoolkit.com/v1/irr \ -H 'Content-Type: application/json' \ -d '{"irr":"AS-RIPENCC"}' | jq .
GETResponse fields
FieldDescription
kindprefix, asn, set, mntner or text: how the input was read.
sourcesThe registries that contributed to this answer.
exact_objectskind=prefix: route objects for exactly this prefix, each with its origin AS, registry, description and maintainers.
covering_objectskind=prefix: route objects for less specifics that cover it. A prefix with none of its own may still be covered by one of these.
registered_originskind=prefix: the origin ASes registered for the exact prefix: what a filter built from the IRR would permit.
route_objectskind=asn: every prefix registered with this AS as its origin. route_count is the true total when the list is truncated.
expanded_asnskind=set: the flat list of AS numbers the set resolves to, following nested sets across every registry.
prefixeskind=set: the prefix list a filter built from the set would hold, deduplicated across registries and split into ipv4 and ipv6. prefix_count gives the per-family totals and prefix_total the sum; prefixes_truncated says whether the cone ran past the response ceiling.
member_ofkind=set: the sets that name this one as a member.
livePresent when RADB was asked directly. reason is requested (you sent live=true) or not_found (the dumps had nothing). added, updated and withdrawn count what the live answer changed; complete is false if RADB’s answer was cut short, in which case nothing is marked withdrawn. skipped says why no query ran (rate_limited, checked_recently).
live_fetched_atOn any object: when it was fetched live from RADB, or null if it came from a mirrored dump. Live objects are kept until a newer dump of their registry replaces them.

Common Questions

What is the IRR?
A set of databases where operators record what they intend to announce and who may announce it, as RPSL objects: route and route6 for prefixes, as-set for groups of ASes, aut-num for the ASes themselves, and mntner for the handles that maintain them. Most of the prefix filters between networks are still generated from this data, which is why a missing or wrong object shows up as “my route isn’t propagating”.
Why is the same prefix registered twice?
Because the IRR is not one database. The same prefix is routinely registered in several registries, occasionally with different origin ASes, and objects nobody cleaned up outlive the arrangements that justified them. Nothing here picks a winner: every registry’s copy is shown with the registry it came from, because that is part of the answer. A prefix registered in one registry with the right origin and in another with an old one will pass some networks’ filters and fail others.
What does expanding an as-set do?
An as-set lists members, and those members are usually other as-sets, and that nesting is how customer cones are written. Expanding one follows it all the way down to the member AS numbers, then takes the second step to the prefix list those ASes have route objects for. That is the same thing bgpq4 produces, and the thing you actually need when a customer hands you an as-set. Members are followed across registries, because a set defined in RADB routinely names one that only exists in RIPE.
How does this relate to RPKI?
They answer the same question with different authority. A ROA is cryptographically signed and traces to an RIR trust anchor; an IRR route object is an ordinary database record, as trustworthy as the registry it sits in and whoever last touched it. In practice you need both: filters are still built from the IRR, and RPKI is what catches the cases where the IRR is wrong. The looking glass shows both for every path.
How current is the data?
Each registry’s published dump is re-imported every four hours, and most registries regenerate those dumps daily. The cards above say when each one was last loaded. When a lookup finds nothing in the dumps, it asks RADB’s whois server directly, which mirrors every registry here within minutes, and keeps what it finds until a newer dump includes it. Tick Live query RADB (or send live=true) to check live even when the dumps do have an answer; anything that differs is updated here too. Objects that came from a live query are marked live.