---
title: "Operator self-published geolocation for an IP/prefix (RIPE DB geoloc/geofeed)"
method: GET
path: "/api/v1/network/geofeed/{resource}"
tags: ["Sugra NetAtlas"]
---

# Operator self-published geolocation for an IP/prefix (RIPE DB geoloc/geofeed)

`GET /api/v1/network/geofeed/{resource}`

Operator self-declared geolocation for an IP or prefix, read from the covering inet[6]num in the RIPE Database: country, geoloc (lat/lon, RFC 9092), the geofeed URL (RFC 8805 pointer), and language. This is first-party operator data - higher trust than a GeoIP guess where it exists, but self-declared and unverified. Picks the most-specific covering object that carries a geo signal. The geofeed URL is returned for client-side resolution; the server does not fetch it (the URL is operator-controlled - an SSRF surface). Upstream registry: 'global' (all RIRs via GRS, default) | ripe | ripe-nonauth | <rir>-grs.

## Path parameters

- `resource` string, required — IPv4/IPv6 address or CIDR prefix.

## Query parameters

- `source` string — Upstream registry: 'global' (all RIRs via GRS, default) | ripe | ripe-nonauth | <rir>-grs.

## Response `200`

Successful Response

- NetworkGeofeedResourceData
  - `resource` string, nullable
  - `query` string, nullable
  - `covering_inetnum` string, nullable
  - `country` string, nullable
  - `geoloc` unknown
  - `geofeed_url` unknown
  - `language` unknown
  - `source` string, nullable
  - `note` string, nullable
  - `_meta` AtlasMeta
    - `product` string, required — Always 'Sugra NetAtlas'.
    - `atlas_built_at` string, nullable — UTC ISO-8601 build time of the atlas snapshot that answered; null only when no connector can vouch for one.
    - `privacy_signal_version` string, required — Version of the privacy/default-route signal set.
    - `confidence` string, required — Confidence of the privacy/default-route signal: high, medium or low.
    - `accuracy` string, required — Accuracy class of the answer (e.g. public, city, country, unknown).
    - `sources` string[], required — Sugra-branded upstream families that contributed.
    - `data_time` string, nullable — When the DATA is from (UTC ISO-8601); null when nothing can vouch for it.
    - `response_time` string, required — When Sugra answered (UTC ISO-8601).
    - `partial` boolean, required — True when at least one upstream failed and the answer is incomplete.
    - `geo_confidence` string, nullable — IP-geo responses only: how trustworthy the resolved city/country is (downgrades for anycast/CDN).
    - `served_from` string, nullable — Where the answer came from (local atlas, live proxy, cache).
    - `fallback_reason` string, nullable — Why a fallback path served the answer, when one did.
    - `sources_coverage` unknown
    - `cached` boolean, nullable — True when the answer was served from the response cache (routes that cache whole answers).
    - `atlas_sha256` string, nullable — SHA-256 of the atlas snapshot (sources/coverage).
    - `endpoint_version` string, nullable — Endpoint contract version where a route declares one (sources/coverage: v1).

## Other responses

- `401` — Missing or invalid `x-api-key` header. JSON body with a stable `code` distinguishing `missing_api_key` (no header sent) from `invalid_api_key` (header sent, key not accepted); any other 401 source carries the generic `unauthorized` with its detail as `reason`. Plus `hint`. `plan` is always null on 401 - an unauthenticated request has no plan; quota exhaustion is 429, not 401.
- `422` — Validation Error
- `429` — Daily rate limit exceeded. Check `X-RateLimit-Reset` for the next window.
- `503` — Upstream source is temporarily unavailable. Retry after a short delay.

---

[API](https://skmtc.net/sugra/apis/sugra-api.md) · [All operations](https://skmtc.net/sugra/apis/sugra-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/sugra/sugra-api/revisions/914af3d38c7c/schema)
