Skip to main content
Use avraapi.security() for the two released Security operations. Both are async ApiResponse calls. A false signal means the configured provider did not classify that signal; it is not an allow or block decision by itself.
Every Security operation supports the shared one-request privacy control: avraapi.security().withPrivacyMode().checkVpn({ ip: 'IP_ADDRESS' }). It sends X-Privacy-Mode: 1 for that request only, then clears.

Check VPN, proxy, and IP risk

checkVpn({ ip }): Promise<ApiResponse> evaluates one permitted IPv4 or IPv6 address for VPN, proxy, Tor, relay, and hosting signals. SDK function
Copy the SDK call
Read IP-risk signals

Response

Some network fields can be null. Combine the signals with your own risk policy and process only IP addresses you are permitted to use. Read the Security REST API Reference for field and error details.

Check a disposable email address

checkBurnerEmail({ email }): Promise<ApiResponse> evaluates one email address for syntax and configured disposable-domain signals. SDK function
Copy the SDK call
Use a disposable-email signal

Response

is_disposable: false means configured lists did not contain a matching domain. It does not verify ownership, inbox reachability, or user trust.

Handle Security errors

Security calls reject with typed SDK errors. Keep error.requestId in backend support records, never expose provider diagnostics to a browser, and follow the common pattern in Node.js Overview and setup.
Last modified on October 1, 2026