You need to resolve a user’s location from an IP address, gate features by region, and flag risky traffic—this week. By the end of this guide you will query the Geo Tracking API’s Geolocation endpoint from Python, parse the response you actually need (lat/lon, city, ISP, threat signals), and ship with working auth and billing on Zyla API Hub.
What the Geo Tracking API provides
The Geo Tracking API returns geolocation details for a given IP address. It includes:
- Country, region, city, timezone
- Latitude and longitude
- ISP, organization, and hostname
- Continent and currency context
- Security signals (proxy/VPN/Tor presence, threat level)
Common implementations: regional content controls, fraud screening, locale-aware UX (timezone and currency), order risk evaluation, and location-based logging or analytics.
Auth and billing on Zyla API Hub
Zyla API Hub uses a subscription + quota model across its catalog of more than 10,000 public APIs. Authentication is via a single API key sent as an Authorization: Bearer header. For your first API on Zyla, you can start with a 7-day trial or 50 requests (No Free Plan beyond that). Check the API page for current access options and pricing.
Key points:
- One account and one API key for every API on Zyla.
- No pay-per-call; plans are subscription + quota.
- Apply the same Authorization: Bearer YOUR_API_KEY header for each request.
You can browse the marketplace at zylalabs.com or go directly to the Geo Tracking API listing to subscribe.
Getting started on Zyla API Hub
- Open the Geo Tracking API page.
- Click Subscribe (or Start Free Trial if available) to activate access.
- Copy your API key from your dashboard.
When you’re ready to implement, pass your key as Authorization: Bearer YOUR_API_KEY on each request.
Endpoint: Geolocation
The Geo Tracking API exposes a single Geolocation endpoint for IP-to-geo resolution.
- Method: GET
- URL: https://zylalabs.com/api/2556/geo-tracking-api/6048/geolocation
- Required query parameter:
- ip (string): the IP address to resolve
Official cURL example
curl -s -X GET "https://zylalabs.com/api/2556/geo-tracking-api/6048/geolocation?ip=181.188.132.167" \
-H "Authorization: Bearer YOUR_API_KEY"
Official sample JSON response
{
"status": "success",
"country": "BO",
"countryCode": "BO",
"region": "La Paz Department",
"regionName": "Santa Cruz Department",
"city": "La Paz",
"zip": "",
"lat": -17.7834,
"lon": -63.1822,
"timezone": "America/La_Paz",
"isp": "Telefónica Celular de Bolivia S.A.",
"org": "AS27882 Telefónica Celular de Bolivia S.A.",
"as": "AS27882 Telefónica Celular de Bolivia S.A.",
"query": "181.188.132.167",
"areaCode": "",
"dmaCode": "",
"inEU": 0,
"euVATrate": false,
"continentCode": "SA",
"continentName": "South America",
"locationAccuracyRadius": "5",
"currencyCode": "BOB",
"currencySymbol": "$b",
"currencySymbol_UTF8": "$b",
"currencyConverter": 6.9324,
"flag": "🇧🇴",
"callingCode": "591",
"languageCode": null,
"security": {
"is_proxy": false,
"proxy_type": null,
"is_tor": false,
"is_tor_exit": false,
"threat_level": "Low",
"threat_score": "0",
"is_abuser": false,
"is_attacker": false,
"is_bogon": false,
"is_cloud_provider": false,
"is_relay": false,
"is_vpn": false,
"is_anonymous": false,
"is_threat": false
},
"hostname": "scz-181-188-132-00167.tigo.bo",
"classType": "class B",
"application": "Medium networks"
}
Field highlights you’ll likely use:
- lat, lon: coordinates in decimal degrees.
- country, countryCode, region, regionName, city: textual geodata for policy and personalization.
- timezone: IANA timezone string for locale-aware scheduling and formatting.
- isp, org, as, hostname: network ownership and routing context.
- security.*: boolean flags and threat metadata for risk scoring.
- currencyCode and currencyConverter: currency context, useful for display and conversions.
Python integration
The following Python example calls the Geolocation endpoint, handles auth, checks the API’s status field, and extracts the most practical fields for feature gating and logging.
import os
import requests
API_KEY = os.getenv("ZYLA_API_KEY", "YOUR_API_KEY")
BASE_URL = "https://zylalabs.com/api/2556/geo-tracking-api/6048/geolocation"
def geolocate_ip(ip: str) -> dict:
headers = {
"Authorization": f"Bearer {API_KEY}"
}
params = {"ip": ip}
# Tune timeouts to your environment; using (connect, read)
resp = requests.get(BASE_URL, headers=headers, params=params, timeout=(5, 10))
resp.raise_for_status()
data = resp.json()
# The API returns a "status" field; check it before trusting fields
if data.get("status") != "success":
raise RuntimeError(f"Geo lookup failed for {ip}: {data}")
return {
"ip": data.get("query"),
"country": data.get("country"),
"countryCode": data.get("countryCode"),
"region": data.get("region"),
"regionName": data.get("regionName"),
"city": data.get("city"),
"lat": data.get("lat"),
"lon": data.get("lon"),
"timezone": data.get("timezone"),
"isp": data.get("isp"),
"org": data.get("org"),
"as": data.get("as"),
"hostname": data.get("hostname"),
"security": data.get("security", {}),
"currencyCode": data.get("currencyCode"),
"currencyConverter": data.get("currencyConverter"),
}
if __name__ == "__main__":
target_ip = "181.188.132.167"
try:
result = geolocate_ip(target_ip)
print("Resolved geodata:")
for k, v in result.items():
print(f" {k}: {v}")
# Example usage:
# if result["security"].get("is_proxy") or result["security"].get("is_vpn"):
# flag user/session for additional verification.
except Exception as e:
# Production: integrate with your logging/alerting
print(f"Geolocation error: {e}")
Production notes that will save you time
- Auth header: Always send Authorization: Bearer YOUR_API_KEY. Don’t append the key as a query parameter to the Geolocation endpoint.
- Timeouts: Network calls to external services can stall; set reasonable connect/read timeouts. In Python requests, pass timeout=(connect, read).
- Caching: Many IPs repeat across sessions. Cache lookups per IP (e.g., in Redis) with a TTL appropriate for your risk posture. This reduces latency and preserves quota.
- Timezone: timezone returns an IANA string (e.g., America/La_Paz). Use it directly with libraries like Python’s zoneinfo for time calculations and formatting.
- Coordinates: lat/lon are decimal degrees. If you display them on a map, project accordingly and handle missing fields defensively.
- Security flags: Treat is_proxy, is_vpn, is_tor, and threat_level as signal, not sole proof. Combine with your own heuristics before enforcement.
- Data completeness: Some fields (zip, areaCode, dmaCode, languageCode) can be empty or null. Always null-check before use.
- Usage planning: Zyla uses subscription + quota. For your first API on Zyla you can start with a 7-day trial or 50 requests. Track your usage and scale your plan as needed.
Common geolocation use cases you can ship this week
- Fraud and abuse checks:
- Block or challenge signups when security.is_proxy, security.is_vpn, or security.is_tor is true.
- Score logins higher-risk when region mismatches past behavior.
- Regional feature gating:
- Enable/disable features by countryCode or continentName.
- Redirect to localized content by city/region for high-traffic markets.
- Locale and currency:
- Apply timezone for scheduled notifications and date formatting.
- Use currencyCode and currencyConverter to display approximate local pricing (clearly mark as indicative rates).
- Operational analytics:
- Augment logs with country, regionName, isp for traffic reporting and capacity planning.
Calling the API from AI agents via MCP
Every API on Zyla can also be called from MCP-compatible tools (e.g., Claude Code, Cursor, Windsurf). Use the MCP endpoint at: MCP.
High-level steps:
- Configure your MCP client with the Zyla MCP endpoint: https://mcp.zylalabs.com/mcp?apikey=YOUR_API_KEY
- Authorize using your Zyla API key.
- From your MCP-compatible environment, call the Geo Tracking API’s Geolocation endpoint by specifying the same request path and parameters described above.
This lets AI coding agents orchestrate calls to the Geolocation endpoint within your development workflow while reusing the same API key.
Troubleshooting checklist
- 401/403 errors: Verify you subscribed on the Geo Tracking API page and are sending Authorization: Bearer YOUR_API_KEY.
- Unexpected fields: Not all properties are guaranteed. Guard against null or empty strings, especially for zip, areaCode, dmaCode, languageCode.
- Response handling: Check data["status"] == "success" before consuming fields.
- Throughput: Add caching per IP and backoff/retry logic for transient network issues. Monitor your subscription usage to avoid hitting quota.
Quick reference
- Marketplace: zylalabs.com
- Geo Tracking API page: Geo Tracking API
- Auth: Authorization: Bearer YOUR_API_KEY
- Endpoint (GET): https://zylalabs.com/api/2556/geo-tracking-api/6048/geolocation?ip=YOUR_IP
- First API access: 7-day trial or 50 requests (No Free Plan). See the API page for details.
FAQ
How do I authenticate?
Send Authorization: Bearer YOUR_API_KEY with every request. Obtain your key after subscribing on the API page.
What is the exact endpoint for IP geolocation?
GET https://zylalabs.com/api/2556/geo-tracking-api/6048/geolocation with the required ip query parameter.
Which fields indicate risky traffic?
Use the security object: is_proxy, is_vpn, is_tor, is_tor_exit, and threat_level. Combine these with your own risk rules before enforcement.
What units and formats should I expect?
lat/lon are decimal degrees; timezone is an IANA string (e.g., America/La_Paz). Some textual fields may be empty or null—check before use.
Is there a free plan?
There is no Free Plan. For your first API on Zyla, you can start with a 7-day trial or 50 requests. See the API page for current options.
Ready to integrate? Create your account, subscribe to the Geo Tracking API, and get your API key now: Register.