---
title: "RPKI validity of an ASN's registry route objects"
method: GET
path: "/api/v1/network/asn/{asn}/rpki"
tags: ["Sugra NetAtlas"]
---

# RPKI validity of an ASN's registry route objects

`GET /api/v1/network/asn/{asn}/rpki`

The ASN's RIPE Database registry route / route6 objects (inverse origin), each annotated with its RPKI Route Origin Validation verdict (valid / invalid / unknown), plus a summary. NOTE: the RIPE Database 'roa-check' search parameter is a no-op over the JSON REST API (verified live - it adds no annotation to the returned objects), so the verdict is computed per route from RPKI validation (prefix + origin). Complements the single-prefix /prefix/{cidr}/rpki with the AS-wide registry view. Upstream registry: 'global' (all RIRs via GRS, default) | ripe | ripe-nonauth | <rir>-grs.

## Path parameters

- `asn` integer, required — Origin ASN.

## Query parameters

- `source` string — Upstream registry: 'global' (all RIRs via GRS, default) | ripe | ripe-nonauth | <rir>-grs.
- `limit` integer — Max distinct route prefixes validated.

## Response `200`

Successful Response

- NetworkAsnAsnRpkiData
  - `asn` union
    - integer
    - number
  - `count` union
    - integer
    - number
  - `rpki_summary` object, nullable
  - `routes` Route[], nullable
    - `type` string, nullable
    - `primary_key` string, nullable
    - `source` string, nullable
    - `attributes` Attribute[], nullable
      - `name` string, nullable
      - `value` string, nullable
    - `rpki` Rpki
      - `status` string, nullable
      - `validating_roas` NetworkValidatingRoa[], nullable
        - `origin` string, nullable
        - `prefix` string, nullable
        - `validity` string, nullable
        - `max_length` union
          - integer
          - number
  - `partial` boolean, nullable
  - `_meta` AtlasMeta
    - `product` string, required — Always 'Sugra NetAtlas'.
    - `atlas_built_at` string, nullable — UTC ISO-8601 build time of the atlas snapshot that answered; null only when no connector can vouch for one.
    - `privacy_signal_version` string, required — Version of the privacy/default-route signal set.
    - `confidence` string, required — Confidence of the privacy/default-route signal: high, medium or low.
    - `accuracy` string, required — Accuracy class of the answer (e.g. public, city, country, unknown).
    - `sources` string[], required — Sugra-branded upstream families that contributed.
    - `data_time` string, nullable — When the DATA is from (UTC ISO-8601); null when nothing can vouch for it.
    - `response_time` string, required — When Sugra answered (UTC ISO-8601).
    - `partial` boolean, required — True when at least one upstream failed and the answer is incomplete.
    - `geo_confidence` string, nullable — IP-geo responses only: how trustworthy the resolved city/country is (downgrades for anycast/CDN).
    - `served_from` string, nullable — Where the answer came from (local atlas, live proxy, cache).
    - `fallback_reason` string, nullable — Why a fallback path served the answer, when one did.
    - `sources_coverage` unknown
    - `cached` boolean, nullable — True when the answer was served from the response cache (routes that cache whole answers).
    - `atlas_sha256` string, nullable — SHA-256 of the atlas snapshot (sources/coverage).
    - `endpoint_version` string, nullable — Endpoint contract version where a route declares one (sources/coverage: v1).

## Other responses

- `401` — Missing or invalid `x-api-key` header. JSON body with a stable `code` distinguishing `missing_api_key` (no header sent) from `invalid_api_key` (header sent, key not accepted); any other 401 source carries the generic `unauthorized` with its detail as `reason`. Plus `hint`. `plan` is always null on 401 - an unauthenticated request has no plan; quota exhaustion is 429, not 401.
- `422` — Validation Error
- `429` — Daily rate limit exceeded. Check `X-RateLimit-Reset` for the next window.
- `503` — Upstream source is temporarily unavailable. Retry after a short delay.

---

[API](https://skmtc.net/sugra/apis/sugra-api.md) · [All operations](https://skmtc.net/sugra/apis/sugra-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/sugra/sugra-api/revisions/914af3d38c7c/schema)
