{"uid":"cap_yf40FLSY3l-6MWwb1nIje","slug":"rpki-route-origin-validation-b84e4d6e","name":"RPKI Route-Origin Validation","description":"RPKI Route-Origin Validation for an IPv4 prefix and origin AS, computed per RFC 6811 from the bulk Validated ROA Payload set. Returns the ROA status, the covering ROA count and the matching ROAs with their origin, max length and trust anchor.","url":"https://api.agentstools.dev/netintel/rpki","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"type":"object","required":["prefix"],"properties":{"origin":{"type":"string","description":"Optional origin AS number; if omitted it is resolved from the IP-to-ASN table"},"prefix":{"type":"string","description":"Public IPv4 prefix in CIDR form or a bare address"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.008","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.008/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.008","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.008","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_XsN9wQNyGdxc3vh1GbJpy","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.008","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Validates an IPv4 prefix and origin AS against the RPKI Validated ROA Payload set per RFC 6811, returning ROA status, covering ROA count, and matching ROA details.","exampleAgentPrompt":"What is the RPKI ROA validation status for the prefix 198.51.100.0/24 — is it valid, invalid, or not found, and which trust anchors cover it?","exampleUseCases":[{"title":"Detect BGP route origin hijacking","prompt":"I just saw an unexpected BGP announcement for 203.0.113.0/24 originating from AS64501 — can you check the RPKI status and tell me whether that AS is actually authorized to originate that prefix, or if this looks like a potential route hijack?"},{"title":"Audit prefix ROA trust anchors","prompt":"We're reviewing the RPKI coverage for our network block 192.0.2.0/24 announced from AS65000 — please validate it against the ROA payload and list all the matching ROAs along with their trust anchors and maximum prefix lengths."},{"title":"Verify BGP route before peering","prompt":"Before we accept a BGP route for 10.20.30.0/24 from AS12345 at our new peering point, can you run an RFC 6811 RPKI validation on that prefix and origin AS so I know if it comes back valid, invalid, or not found?"}],"resultDescription":"Returns the RPKI validation status (valid/invalid/not-found) for the given IPv4 prefix and origin AS, the number of covering ROAs, and an array of matching ROA records each containing the authorized origin AS, maximum prefix length, and trust anchor name.","failureModes":["Missing required 'prefix' query parameter returns a 400 error","Private or reserved IP prefixes may return not-found status rather than an error","Invalid CIDR notation returns a validation error","Origin AS not matching any ROA returns invalid status","Payment not provided or invalid returns 402 Payment Required"],"whenToPreferThis":"Use this endpoint when you need RFC 6811-compliant RPKI route-origin validation for a specific IPv4 prefix, especially when you need the full breakdown of matching ROAs including trust anchors and max lengths. Prefer this over generic BGP tools when you specifically need ROA-level detail per the RPKI Validated ROA Payload standard.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T12:45:46.548Z","isFirstParty":false}