IP Geolocation Accuracy Benchmark: 17 Providers Against GPS Ground Truth
How far from the real location of a device is the location an IP geolocation API reports for its address? This running benchmark measures 17 providers against the positions that visitors of ipapi.is share from their own devices, with stricter ground truth, bot exclusion and a study design that the company running it cannot tilt in its own favour.
This study is live. Data collection started on October 1st, 2026. The results below are recomputed from the live dataset every ten minutes. You can take part from any page on ipapi.is, or right here:
It continues our first geolocation accuracy study (January to June 2026, ten providers). That study taught us as much about study design as about geolocation, so before adding seven providers we rebuilt how samples are collected, cleaned and evaluated.
What changed since the first study
- All providers are asked at the same moment. The first study looked addresses up only when the results were computed, which could be long after the position was shared, and repeated failed lookups later still. Addresses get reassigned and databases change in the meantime, so the providers did not always answer the same question. Now every provider is asked within seconds of the submission. A failed lookup is retried for up to six hours.
- Bots are excluded with our signup bot detection. Every submission carries the same telemetry and single-use challenge token as an account signup on ipapi.is, and has to pass the same classifier. Only submissions classified as human, with a verified token, enter the dataset.
- No single provider decides what is clean. The first study removed VPN, proxy and datacenter addresses using ipapi.is's own flags. An address that ipapi.is wrongly considered residential stayed in, and an address only ipapi.is flagged was removed, both to our advantage. Now an address is excluded only when at least two of the 17 providers flag it.
- A foreign answer next to the border is a wrong answer, not a proxy. The first study treated a country consensus that disagreed with the device as a residential proxy. A visitor in Basel whose ISP is placed in Zurich is not tunnelling, so the rule now also requires the answers to be more than 300 km away.
- The ground truth is held out from ipapi.is. The first study's positions now serve as a regression test for our own database builds, and visitors can send us location corrections. Both are knowledge only ipapi.is has. Networks that appear in either are excluded.
- Stricter positions. The browser is given several seconds to improve on its first fix, positions less accurate than 500 m are dropped (the first study allowed 1,000 m), and positions that look spoofed are dropped too.
- One sample per household and device. Repeat submissions from the same connection or the same device no longer count several times.
- Uncertainty is reported. Every median comes with a 95% confidence interval, every share with a Wilson score interval. An answer without coordinates counts as wrong instead of being left out, so not answering cannot improve a score.
- Only aggregates are published. The providers' answers are public to anyone who asks them, so a participant's distances to them would reveal where they were. Individual samples stay on our server.
Methodology
Taking part
Visitors of ipapi.is see a small dialog that explains the study and asks for their location once. If they agree, the browser's Geolocation API is watched for up to 30 seconds. It stops at the first fix accurate to 50 m, after five fixes, or eight seconds after the first one, and the most accurate fix is kept. We store the position, its accuracy, the IP address, the browser's user agent and its clock's UTC offset, plus the bot detection's verdict and a device fingerprint that is used to remove duplicates. The IP address is looked up at the 17 providers, and the position, rounded to about 100 m, at an OpenStreetMap geocoder. Nothing else leaves our server. Declining hides the dialog for 30 days; taking part hides it for good.
Ground truth
Phones with GPS report positions accurate to a few metres, and laptops positioned by nearby Wi-Fi networks to tens of metres. When neither is available, browsers fall back to locating the device by its IP address, which is exactly what this study measures and must not be used as ground truth. Positions that report an accuracy worse than 500 m are excluded.
The country of a position is determined by reverse geocoding it with OpenStreetMap data, rounded to about 100 m. This is the ground truth for country accuracy.
Cleaning
A submission enters the results only if it passes every one of these checks, in this order:
- Bot detection. The signup classifier must call the submission human, its challenge token must verify, and the browser must not be driven through the Chrome DevTools protocol. The one signup input left out is the country of the IP address, because that comes from ipapi.is's own geolocation and would remove exactly the visitors whose country we get wrong.
- Accuracy. The position is accurate to 500 m or better.
- Spoofing. The position is not one of Chrome DevTools' sensor presets, has more than three decimal places (hand-typed positions rarely do), and the device clock's time zone is within 3.5 hours of the position's solar time.
- Anonymizers. Fewer than two providers flag the address as a VPN, Tor exit, hosting provider or relay such as iCloud Private Relay. Residential proxy flags are not used: some providers flag ordinary home connections as proxies.
- Tunnels. When at least eight providers answered, two thirds of them agree on a country that is not the device's, and their median answer is more than 300 km away, the visitor is almost certainly behind a VPN or proxy nobody flagged. Such samples are excluded.
- Held-out networks. The address is not in a network (an IPv4 /24 or IPv6 /48) that appears in the first study or in a location correction sent to ipapi.is.
- Duplicates. Only the first sample of a household (the IPv4 address or IPv6 /64) counts, and of a device within 1 km of an earlier position.
On top of that, an address can take part at most three times a day, and the study accepts at most 500 samples a day. The live cleaning funnel is in the results.
Providers
Every provider is asked through its public web API, with an API key where it issues one. Some vendors also sell downloadable databases, which can differ from their web API. This benchmark measures the API.
| Provider | Endpoint | Note |
|---|---|---|
| ipapi.is | api.ipapi.is | Ours |
| ipinfo.io | ipinfo.io/{ip} | |
| maxmind.com | geoip.maxmind.com/geoip/v2.1/insights | GeoIP Insights web service |
| ipdata.co | api.ipdata.co | |
| ip-api.com | ip-api.com/json | Free endpoint |
| iplocate.io | iplocate.io/api/lookup | |
| ipwho.is | ipwho.is | Free endpoint |
| ipgeolocation.io | api.ipgeolocation.io/v2/ipgeo | |
| freeipapi.com | freeipapi.com/api/json | |
| ipbase.com | api.ipbase.com/v2/info | |
| db-ip.com | api.db-ip.com/v2 | |
| proxycheck.io | proxycheck.io/v3 | |
| ipregistry.co | api.ipregistry.co | |
| bigdatacloud.com | api-bdc.net/data/ip-geolocation-full | |
| ip-api.io | ip-api.io/api/v1/ip | |
| abstractapi.com | ip-intelligence.abstractapi.com/v1 | Quota-limited: a random subset of up to 20 samples a day |
| iplocation.net | api.iplocation.net/v2 | Quota-limited: a random subset of up to 5 samples a day |
Metrics
For each sample and provider we compute the great-circle distance between the device and the provider's answer. Per provider we report the median distance with a distribution-free 95% confidence interval, the 75th and 90th percentiles, the share of answers within 10, 25, 50 and 100 km, and country accuracy, all shares with Wilson score intervals. An answer without coordinates counts as infinitely far away. A lookup that failed even after retries, or that a quota-limited provider was not asked, is left out for that provider only. Groups with fewer than ten answers are not evaluated.
Conflict of interest. ipapi.is runs this study and is one of the providers. That is why the rules above were fixed before the first sample arrived, why no rule depends on ipapi.is's data alone, and why the results are computed and published automatically. If ipapi.is ranks badly, this page will say so.
Results
Loading the live results…
Limitations
- Who takes part. Visitors of ipapi.is are developers and security people more than average internet users, and they are not spread evenly over the world. The continent filter shows how much the ranking depends on where samples come from.
- Undetected proxies. A residential proxy that no provider flags and that exits in the visitor's own country cannot be told apart from a real connection. Such samples stay in and make every provider look worse by the same amount.
- One API per vendor. We measure each provider's web API on our plan. A different product or plan of the same vendor can answer differently.
- Small groups. With few samples, the intervals are wide, and two providers whose intervals overlap should not be considered different.
Data
The aggregated results behind this page are public as JSON at
https://ipapi.is/app/geoStudy/results, under the same
terms as the article. Individual samples are not published.