Every host answering on the web's two ports.
Each address that answered a TLS handshake or an HTTP request on TCP port 443 or 80, with the certificate it presented (its names, issuer, validity and SHA-256 fingerprint, and whether it is self-signed or browser-trusted), the JA3S of its TLS handshake, and the status, Server header, redirect, cookie names and page title of its first response. A port that was open but never answered isn't in the file.
Schema at a glance.
See documentation →The database's schema and metadata are documented carefully. It is published as CSVGZ.
| ip | port | tls_ok | session_ok | status_code | server | location | title | set_cookie_names | cert_subject_cn | cert_subject_o | cert_issuer_dn | cert_sans | cert_not_before | cert_not_after | cert_fp_sha256 | cert_self_signed | cert_browser_trusted | ja3s | tls_version | tls_cipher | http_version | first_seen | last_seen |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3.96.111.78 | 443 | 1 | 1 | 403 | awselb/2.0 | 403 Forbidden | welbi.host | C=US, O=Amazon, CN=Amazon RSA 2048 M04 | *.versions.welbi.host *.welbi.host welbi.host | 2025-11-26 | 2026-12-25 | a95efbc9c08135682c273fbe992c21fbad4b8f1e641783143e1492d7b594ba01 | 1 | f4febc55ea12b31ae17cfb7e614afda8 | TLSv1.3 | TLS_AES_128_GCM_SHA256 | HTTP/2.0 | 2026-07-27 | 2026-10-06 | ||||
| 47.253.191.243 | 443 | 1 | 1 | 200 | nginx/1.24.0 (Ubuntu) | GSG-Tech Domain Updated | GSG-Tech | NEXT_LOCALE | www.xmgsgroup.com | C=US, O=DigiCert Inc, OU=www.digicert.com, CN=RapidSSL TLS RSA CA G1 | www.xmgsgroup.com xmgsgroup.com | 2026-01-29 | 2027-01-28 | aac71a22da91e561811b6d1a3a2d36842717e370298d8db9b623db04d744e9ef | 1 | 15af977ce25de452b96affa2addb1036 | TLSv1.3 | TLS_AES_256_GCM_SHA384 | HTTP/1.1 | 2026-07-14 | 2026-10-05 | |||
| 163.172.175.84 | 443 | 1 | 1 | 404 | TRAEFIK DEFAULT CERT | CN=TRAEFIK DEFAULT CERT | b102bf897b8e5c96318a582ab2773b6b.bcda50b5da922719fe1b66c6ec80d252.traefik.default | 2026-10-06 | 2027-10-06 | d5a99cf7a629007e9107c86c4c9b35856f8366633f72e4374e5941a0a1dec00d | 1 | 475c9302dc42b2751db9edcac3b74891 | TLSv1.3 | TLS_CHACHA20_POLY1305_SHA256 | HTTP/2.0 | 2026-07-17 | 2026-10-03 | ||||||
| 38.59.242.153 | 80 | 1 | 308 | Caddy | https://38.59.242.153/ | HTTP/1.1 | 2026-07-13 | 2026-10-02 | |||||||||||||||
| 51.38.39.174 | 80 | 1 | 200 | Apache/2.4.58 (Ubuntu) | Apache2 Ubuntu Default Page: It works | HTTP/1.1 | 2026-07-12 | 2026-10-03 |
Downloading it from code.
Database API reference →One call gets you the current Web IP build. Every official client wraps it three ways: straight to disk, a time-limited link you hand to your own runner, or bytes in memory. A file written to disk lands only once the whole transfer has arrived, and checksums() returns the published digests to verify it against.
download()downloadUrl()downloadBytes()metadata()checksums()import osfrom internetdata import InternetDataclient = InternetData(os.environ["INTERNETDATA_API_KEY"])# what is in today's build, without moving the filemeta = client.database.metadata("web_ip_v1")client.database.download("web_ip_v1", "csvgz", "./web_ip_v1.csv.gz")sums = client.database.checksums("web_ip_v1", "csvgz")print(meta.updated, meta.entries, sums["sha256"])
Getting your hands on it.
The file is the product. Teams join Web IP against traffic they already log, inside their own infrastructure, and never send an address anywhere to get an answer.
Attack-surface audit
Find your own hosts answering on 443 and 80: expired and self-signed certificates, default pages, and admin panels that should never face the internet.
Infrastructure pivots
Group hosts by certificate fingerprint, by the names a certificate covers or by the JA3S of their TLS stack, to follow one operator's servers across addresses.
Brand monitoring
Search certificate names and page titles for your brand, and find the hosts presenting it that are not yours.
An official client for every major language.
All SDKs on GitHub →Twelve official clients for the languages you ship in, each wrapping the database endpoints — list what you are licensed for, poll a build, follow the download redirect, verify what landed. Install commands are in the docs.
No loose ends.
Why are the TLS columns empty on some rows?
A row on port 80 is plain HTTP, with no TLS handshake, so tls_ok, every cert_ column, ja3s, tls_version and tls_cipher are empty there. On 443 they're filled whenever the handshake completed.
Does every row have an HTTP response?
Every row answered something. On 443 a host can complete the TLS handshake and then send no HTTP response: its session_ok and HTTP columns are empty, and its certificate is still there.
Are redirects followed?
No. status_code, server, location and title come from the first response, so a redirect carries the Location it points to rather than the page behind it.
Are cookie values in the file?
No. set_cookie_names lists the names of the cookies a response set, never their values.
What does cert_browser_trusted mean?
1 when the certificate's chain validates to a root that browsers trust. A self-signed certificate or one from a private CA leaves it empty, and cert_self_signed tells those two apart.
How often is it rebuilt?
Weekly, from what each host answered in the last 30 days; first_seen and last_seen are relative to a rolling 90-day window. The metadata call answers when the current build landed and how many rows it holds, before you fetch it.
Which formats does a build ship in?
Gzipped CSV. Each row is one address and port, so a prefix tree would not make it smaller. Poll the metadata call first and fetch only when the build has changed.
What if a row looks wrong?
Send it to us and we'll tell you what we hold on it, when we last saw it and how. Corrections land in the next build.
Test the real build first.
An evaluation license puts a full current build in your hands — every row, every column, no sampling — so you can measure it against your own traffic before anyone talks about terms.