Network Tools IP address public IP Cloudflare

IP Address

Show your public IP address as seen by HTTP lookups and DeviceHub APIs.

Interactive tool

Run the test

Runs in your browser

Resolves your public IP through DeviceHub when available, and also queries ipify for IPv4. Edge metadata (colo, country, ASN) appears only when the DeviceHub API responds.

Privacy: third-party fallbacks (ipify) see your request IP. Prefer DeviceHub when deployed.

Press Lookup to resolve your public IP.

Ready.

Permission status

Checked in your browser. DeviceHub does not store permission grants.

  • Special permission Not required

Live results

Metrics update as you run the test. Nothing is uploaded.

Loading

Waiting for interactive tool output…

Device information

Labels and capability details reported by your browser.

No device details yet.

Description

About IP Address

Introduction

The DeviceHub IP Address tool is a free online public IP checker that shows how HTTP lookups see your egress address, using DeviceHub’s Cloudflare-backed /api/client-ip when the deployment provides it, and public echo APIs such as ipify when a fallback is required, without installing VPN diagnostic suites or desktop sniffers. Remote workers confirming corporate VPN egress, gamers comparing home versus hotspot paths, support desks collecting addresses for allowlists, educators teaching LAN versus public egress, and developers validating CDN geo hints all open one HTTPS page and read what the web path actually exposes. DeviceHub states limits plainly: IP lookups may use DeviceHub /api/client-ip (Cloudflare) and/or public echo APIs (ipify); when fallbacks run, those third parties see the request and learn your egress IP. This page is not a traceroute laboratory, not an ISP account portal, and not a guarantee that every app on your machine exits through the same address visible in the browser tab. Pair with IPv6 Test when dual-stack reachability is the question, DNS Privacy Check and WebRTC Leak Test when privacy path consistency matters, Connection Information for Network Information API hints, and HTTP Headers when request metadata beside the IP helps triage. Schools bookmark the page because no admin install is required. Capture the address inside the same VPN or split-tunnel profile where the ticket lives, private windows and in-app WebViews often share the system stack, but captive portals and per-app VPNs can diverge. Call-center scripts that demand city-level certainty need education that Cloudflare geo fields are edge estimates, not a legal residence certificate. Fleet administrators rolling out always-on VPN profiles use the readout to prove users left the office NAT. Indie developers filing wrong-region CDN bugs attach DeviceHub IP plus colo hints beside failing API logs. Hotel Wi-Fi and conference networks often CGNAT many guests behind one public address, seeing a shared IP is expected. Mobile carriers rotate public addresses frequently; re-run after airplane-mode toggles when tickets claim sticky IPs. Dual-stack homes may show IPv4 here while IPv6 Test proves a separate v6 path exists, read both tools before concluding the network is IPv4-only. Streaming platforms that rate-limit CGNAT pools benefit from a timestamped IP snapshot before escalation. Parents helping students join online exams use the page to confirm school VPN egress when proctoring allowlists require it.

What this tool does

On load or refresh, IP Address requests DeviceHub /api/client-ip when available and formats the returned public IP plus optional Cloudflare metadata such as colo, country, ASN organization, HTTP protocol, TLS version, and coarse location fields the edge chooses to expose. When the DeviceHub function is unreachable, common on pure local previews without Pages Functions, the client falls back to public echo services like api.ipify.org for IPv4 so you still get a usable address. The page does not rewrite your routing table, does not force a VPN on or off, and does not scrape WHOIS into a full ownership dossier. Copy guidance helps paste addresses into tickets without claiming the tool audited every OS process. Side-by-side rows when both DeviceHub and ipify succeed let you spot transient path differences. Refresh after connecting or disconnecting a VPN to capture before-and-after egress. Optional notes remind you that third-party fallbacks see your request IP whenever those calls run. Geo fields may be null or coarse; absence is useful diagnostic information, not always a broken detector. CGNAT and carrier-grade shared egress mean many subscribers can share one public IPv4, do not treat uniqueness as identity. IPv6-only or IPv6-preferred paths may need IPv6 Test for a clearer dual-stack picture. The tool focuses on browser HTTP egress visibility, not UDP game clients or native apps with separate sockets. When DeviceHub returns an address and ipify agrees, confidence rises that the public IPv4 view is stable for that moment. When they disagree, document timestamps and VPN state rather than assuming one vendor is lying. Browser extensions that force proxy PAC files change observed addresses, disable temporarily when isolating leaks. The UI may label sources explicitly so screenshots remain interpretable weeks later in ticket threads.

When to use it

Run IP Address before opening firewall allowlist tickets, after enabling or disabling a VPN, when comparing home fiber versus phone hotspot egress, before DNS Privacy Check or WebRTC Leak Test so you have a baseline public IP, and whenever a CDN or API claims you are in the wrong region. Prefer IPv6 Test when the dispute is dual-stack reachability rather than a single v4 string. Prefer WebRTC Leak Test when candidate IPs may bypass the VPN HTTP path. Prefer Connection Information when effectiveType or downlink hints matter more than the numeric address. Prefer Port Checker or HTTPS Reachability Check when the question is remote host reachability from Cloudflare edge rather than your public identity. Use after hotel or airport Wi-Fi connects when support asks what your IP is right now. Use when teaching students that 192.168.x.x is not what websites see. Use when a game anti-cheat or streaming platform rate-limits a shared CGNAT address and you need proof of browser egress. Avoid treating Cloudflare city fields as courtroom-grade location. Avoid assuming native desktop apps share this exact egress when per-app VPNs exist. Run again after sleep/wake on laptops that reconnect Wi-Fi to different SSIDs. Pair with HTTP Headers when you also need to see what request headers DeviceHub received on the echo path. Use during incident response when rotating VPN exit nodes and you need a quick confirmation the new egress took effect. Use before filing ISP tickets about unexpected foreign geo labels so you attach DeviceHub colo context.

How it works

Browsers cannot invent a public IP from JavaScript alone without asking a server that observes the TCP/TLS connection. DeviceHub’s /api/client-ip reads Cloudflare request metadata such as CF-Connecting-IP and related cf object fields, then returns JSON for the page to display. That path keeps richer edge metadata on DeviceHub infrastructure when you are deployed to Cloudflare Pages. Public echo APIs such as ipify accept a CORS request from the browser and return the address they saw, simple and useful, but those operators necessarily observe the request. DeviceHub documents both behaviors so users understand privacy tradeoffs instead of marketing impossible “IP check with zero network contact.” Secure HTTPS hosts DeviceHub consistently. No microphone, camera, or clipboard permission is required for IP lookup, permissions remain none. Extensions that force traffic through proxies change what servers observe, valuable when diagnosing VPN-on-but-IP-unchanged reports. Remote support must capture the user machine path, not the agent’s office egress. Nothing builds an advertising profile from a casual check, but you should still treat public IPs as sensitive network identifiers when pasting into public forums. IPv4-mapped presentation quirks are normalized for display rather than turned into a full IP algebra lecture. DNS resolution of echo hostnames still depends on your resolver path, separate from the IP number returned after connect. Cloudflare colo codes identify approximate Points of Presence that terminated the request, which helps CDN disputes more than street addresses. ASN organization strings name the network operator Cloudflare associates with the address at lookup time and can lag reassignments. TLS version and HTTP protocol fields describe the connection to DeviceHub, not every other site you browse afterward.

Step-by-step instructions

  1. Open IP Address over HTTPS on the exact network path under test, home Wi-Fi, VPN profile, or mobile hotspot, not a different machine belonging to support staff.
  2. Wait for DeviceHub /api/client-ip and any configured fallbacks to finish; half-loaded screenshots mislead tickets about missing geo fields.
  3. Record the primary public IP and note the source label (DeviceHub versus ipify) so escalations distinguish edge metadata from third-party echo.
  4. If VPN privacy is the concern, continue to DNS Privacy Check and WebRTC Leak Test with this IP as the HTTP-path baseline.
  5. If dual-stack matters, open IPv6 Test and compare whether api64 returns an IPv6 literal while this page showed IPv4.
  6. Copy only necessary fields into tickets; redact if policy forbids sharing public IPs publicly, and mention that third parties see fallback requests when ipify ran.

Common problems

Local development without Cloudflare Functions shows missing colo/ASN until you deploy, fallback IPv4 still works via ipify. VPNs that leak HTTP differently from system proxy settings confuse users who expected one address everywhere. CGNAT makes neighbors share IPv4 space, so someone-else-has-my-IP tickets are often misunderstanding shared egress. Aggressive privacy extensions that block third-party fetches can fail ipify while DeviceHub still works, or vice versa. Treating city fields as GPS coordinates creates false confidence. IPv6-only clients may need different echo behavior; use IPv6 Test rather than forcing every answer into one IPv4 row. Captive portals that intercept HTTP until login can break lookups until you authenticate to the venue Wi-Fi. Corporate SSL inspection does not usually change the public IP number but can affect TLS metadata fields. Comparing a phone LTE IP with a laptop Wi-Fi IP from the same household is expected divergence, not a DeviceHub defect. Browser caches rarely apply to no-store IP JSON, but stale screenshots in tickets do, always note the capture time. Split-tunnel VPNs that exempt the DeviceHub domain show the home IP while other sites exit elsewhere, document the destination hostname when filing VPN bugs.

Privacy explanation

Discovering a public IP always involves a server that sees your connection. DeviceHub /api/client-ip keeps that observation on DeviceHub’s Cloudflare deployment when available. When fallbacks such as ipify run, those third parties see the request and your egress IP, DeviceHub states this honestly instead of hiding it. The page does not request microphone, camera, MIDI, USB, or clipboard permissions. Closing the tab ends the view; nothing keeps polling afterward. Shared PCs are fine; still avoid pasting full IP plus precise timestamps into public social media if your threat model cares. Screenshotting results for JIRA is your choice. Geolocation fields from the edge are coarse network estimates, not consent for tracking. Prefer DeviceHub-primary resolution when deployed so fewer third parties observe the lookup, and treat any fallback call as an explicit privacy trade for convenience. Public IPs can correlate with subscriber accounts at an ISP, handle them like other network identifiers in your organization’s data classification policy.

Runtime principles

Built for the browser

What happens when you run this test — without downloads or accounts.

  1. 01

    Runs in your browser

    IP Address uses standard web APIs — no install, extension, or desktop app required.

  2. 02

    Reads what the browser allows

    Results come from events and capability signals the web platform exposes for this session.

  3. 03

    Private by default

    Input and diagnostic values stay in your browser session for display — nothing is sold as media.

Compatibility

Supported browsers

Expected support for modern engines. Individual APIs may still vary by device.

  • Chrome

    supported

    Latest stable

  • Firefox

    supported

    Latest stable

  • Safari

    supported

    Latest stable

  • Edge

    supported

    Latest stable

Devices

Supported devices

Hardware and form factors this browser test is designed to exercise.

  • Wi‑Fi connections

    Browser network hints when the Network Information API exists.

  • Ethernet

    Desktop sessions with stable connectivity signals.

  • Cellular

    Mobile browsers that expose connection type hints.

Privacy

Your data stays with you

IP Address is built privacy-first. Diagnostics run in your browser session whenever web APIs allow.

Read our privacy policy

Troubleshooting

Common problems

Quick fixes before you dig into FAQs.

DeviceHub edge fields are missing
Local Astro preview without Cloudflare Pages Functions may lack /api/client-ip. The tool can fall back to ipify for IPv4; deploy to Cloudflare Pages for colo, country, and ASN metadata.
ipify and DeviceHub disagree
VPNs, split tunnels, and carrier CGNAT can change egress between requests. Re-run both lookups on the same path and note each row source.
I only see IPv4
Many paths and fallbacks are IPv4-first. Use IPv6 Test for dual-stack echo reachability instead of expecting every IP Address row to be IPv6.

FAQ

Frequently asked questions

Structured answers for users and FAQ rich results.

Browse FAQs
Where does my public IP come from?
DeviceHub prefers GET /api/client-ip on Cloudflare when deployed. If that edge API is unavailable, the page may fall back to public echo APIs such as ipify.
Do third parties see my IP?
Yes when fallbacks run. Public echo operators necessarily observe the request. Prefer DeviceHub /api/client-ip on a Cloudflare deployment to keep observation on DeviceHub infrastructure.
Why are colo or country fields missing?
Those Cloudflare metadata fields require /api/client-ip. Local Astro preview without Pages Functions often lacks them even when ipify still returns an IPv4 address.
Is this my LAN (192.168.x.x) address?
No. This tool shows public egress as seen by HTTP lookups, not your private RFC1918 LAN address.
Do I need a permission?
No. IP lookups use permissions none, no microphone, camera, or clipboard prompts.
Should I also run IPv6 Test?
Yes when dual-stack reachability matters. IP Address is often IPv4-first; IPv6 Test compares IPv4 and dual-stack echo endpoints.

Newsletter

Updates coming soon

A lightweight email digest for new tools and release notes is planned. No signup form is live yet — check Release Notes for product updates.

Release notes

Need another diagnostic after IP Address?

Explore related DeviceHub tools that pair well with this test.