Live: Tor + abuse feeds refreshed every 6 hours
Pricing

Simple, credit-based pricing

One credit = one lookup. Every plan includes every endpoint — identity signals for IP, email, phone, domain and device, the unified signup score, AI agent authorization, custom rules and the reporting network. No setup fees, cancel anytime.

A lookup is one signal checked. Single-signal endpoints cost one credit; the unified /v1/score/user checks up to five and costs one per signal, so a full signup is five credits — 200 of them on the free tier. Cached signals are free, and every response returns billable_lookups so you never have to guess.

Free
$0forever
1,000 lookups / mo
  • Five identifier types in one call — ip, email, phone, domain and device
  • All 15 endpoints — scoring, verification and fraud reporting
  • Device fingerprinting + bot detection
  • No daily cap, and cached calls are never billed
Start free
Starter
$49/ mo
20,000 lookups / mo
  • Everything in Free
  • Works out at $0.0024 per lookup
  • No monthly cap — then $0.004 per lookup
  • Custom allow / block rules
  • Email support · 2 business days
Get started
Scale
$749/ mo
500,000 lookups / mo
  • Everything in Growth
  • Works out at $0.0015 per lookup
  • Then $0.0022 per lookup beyond that
  • Webhooks + SLA on request
  • Onboarding support
  • Slack or Teams · same-day
Get started
Need more than 500k/mo? Talk to us about Enterprise — volume discounts, dedicated support, and SLA. Every plan is billed monthly; cancel anytime.

Not sure which plan fits?

Set your monthly volume and see what each plan costs, overage included. The cheapest is marked, and it is sometimes the free one.

Free1,000 includedcapped — upgrade needed
Starter20,000 included · $0.004/extracheapest$169 /mo
Growth100,000 included · $0.003/extra$199 /mo
Scale500,000 included · $0.0022/extra$749 /mo

Cached repeat lookups and every test-mode call are free and are not counted here, so real bills usually come in under these figures. Above 1M lookups a month, Enterprise pricing is lower per lookup than any tier shown — that needs a conversation rather than a slider.

Start free — 1,000 lookups →No card required · cancel anytime

Before you integrate

The things worth knowing before you put this in front of real users.

How fast is the LayerCall API?

Repeat lookups are served from cache in 0.02–0.09 seconds — measured across all four endpoints, not a best case — and first-time lookups take 1-4 seconds, because a value we have not seen before means live MX, SPF, DMARC and RDAP queries against other people's servers. The check runs server-to-server and is invisible to your end users. Cached and test-mode lookups never count toward your quota or bill.

What happens if LayerCall is down or unreachable?

Fail open. If the API is unreachable or times out, let the signup proceed rather than losing a legitimate customer — a fraud check that blocks real users when it breaks costs more than the fraud it was stopping. Every SDK ships with a timeout and every response carries its own processing_time_sec, so you can set a budget and move on when it is exceeded. Treat the score as one input to your decision, never as the gate itself.

Is LayerCall GDPR compliant, and do you store personal data?

LayerCall is designed to minimize personal data. Its reputation network stores only a one-way SHA-256 hash of observed values — never raw IP addresses, emails, or phone numbers — so there is no personal data in it to expose. See our Privacy Policy for how account and usage data are handled and how to exercise your data rights.

What data sources power the risk scores?

Most signals come from authoritative, first-party sources rather than resold aggregates: registration data straight from the registries over RDAP, exit-node lists published by the VPN operators themselves, the Tor Project's official exit list, IP ranges published by AWS, Google Cloud, Oracle, Cloudflare and other hosts, ASN records verified against RIPE, DB-IP geolocation, libphonenumber numbering plans, and maintained disposable-email domain lists. LayerCall also runs its own first-seen reputation network, which records how often a hashed value has been seen and any confirmed-fraud reports; it starts empty for a new deployment and strengthens as traffic grows, so it adds little on day one and more over time.

How often does it wrongly block a real customer? Measured, and published with the sample size rather than as a percentage: see the accuracy figures, the method and the corpus.

More in the full FAQ.