ssid.ai API
Identify the manufacturer behind any MAC address, and know when it's a randomized (private) address instead of a real prefix. No signup for the free tier.
Try it
curl "https://ssid.ai/api/v1/lookup?mac=F4:F5:E8:11:22:33"
{
"mac": "F4:F5:E8:11:22:33",
"oui": "F4F5E8",
"kind": "universal",
"randomized": false,
"vendor": { "organization": "Google, Inc.", "address": "..." },
"blockType": "MA-L",
"block": null,
"cidRegistrant": null,
"deviceType": null,
"confidence": 1,
"source": { "name": "IEEE MA-L registry", "url": "https://standards-oui.ieee.org/oui/oui.csv" }
}The lookup matches the longest IEEE prefix, not just the 24-bit OUI. Where the IEEE kept an MA-L block and assigned longer prefixes out of it, vendor.organization is the company holding the sub-block and blockType says which registry answered: MA-L (24-bit), MA-M (28-bit), or MA-S / IAB (36-bit). Sub-block answers also carry block.start and block.end.
curl "https://ssid.ai/api/v1/lookup?mac=70:B3:D5:12:34:56"
{
"vendor": { "organization": "Amfitech ApS", "address": "..." },
"blockType": "MA-S",
"block": { "start": "70B3D5123000", "end": "70B3D5123FFF" },
"source": { "name": "IEEE MA-S registry", "url": "https://standards-oui.ieee.org/oui36/oui36.csv" }
}A randomized address keeps vendor: null and confidence: 0, because the device generated the address itself and no manufacturer assigned it. When its 24-bit prefix is a registered Company ID, cidRegistrant names the registrant alongside that null: DA:A1:19 is Google's, and Android generates from it.
Router default logins
The manufacturer-cited factory login for a router model, by ssid.ai slug or by exact brand + model. Null credential fields are real answers: credType says why there is no factory password, and source.url is the manufacturer page it was read from. Metered on every tier (this is the paid data); brand + model returns 409 with up to five candidate slugs when the model is ambiguous, never a list.
curl "https://ssid.ai/api/v1/device/tp-link-archer-ax55" curl "https://ssid.ai/api/v1/device?brand=TP-Link&model=Archer%20AX55"
{
"slug": "tp-link-archer-ax55",
"brand": "TP-Link", "modelName": "Archer AX55", "category": "router",
"defaultGatewayIp": "192.168.0.1", "loginHost": "tplinkwifi.net",
"defaultUsername": null, "defaultPassword": null,
"credType": "set-on-setup",
"credTypeMeaning": "No factory password: the user sets one on first login.",
"resetSteps": "...", "confidence": "high",
"source": { "url": "https://www.tp-link.com/us/support/faq/87/", "name": "TP-Link official support (FAQ 87)" },
"url": "https://ssid.ai/routers/tp-link-archer-ax55"
}Get a key
MAC/OUI lookup is free with no daily limit and needs no key at all. A free key raises router and compliance calls from 100 to 1,000 a day — no email, shown once. ssid Pro ($15/mo) issues its own key on the checkout confirmation page.
No email required. Free tier: 1,000 lookups/day. Higher tiers upgrade with the same key.
Auth
Pass an API key to raise limits: Authorization: Bearer ssid_… (or x-api-key). Every response carries X-RateLimit-* headers.
Tiers
| Tier | Price | Rate | Burst |
|---|---|---|---|
| Anonymous | $0 | Unlimited | 60 / min |
| Free | $0 | Unlimited | 60 / min |
| Pro | $15 / mo | 10,000 / day | 120 / min |
The burst ceiling scales with the tier so the daily figure stays reachable; your ceiling comes back on every response in X-RateLimit-Burst. Full terms, and when a cheaper option is the right call, on pricing.
ssid Pro — $15/mo
ssid Pro · $15/mo · one seat
submit_correction · 10,000 router calls/day · 120/min
Checkout and card handling run on Stripe — your card never touches ssid.ai. A new key is shown once on the confirmation page; an upgraded key keeps its value and gets Pro within a minute. Cancel any time from Manage billing; the key drops back to the free tier at period end.
Stuck, or something went wrong during checkout? Email support@ssid.ai and a person will answer. Router-data volume beyond Pro or data licensing: hello@ssid.ai. Refunds per the terms.
For agents
MCP server — get_router_defaults, check_router_compliance, lookup_mac and submit_correction over stdio. The three read tools need no key; submit_correction needs a Pro key in SSID_API_KEY. The router tools call the endpoints above, so their limits are the tiers above. Full docs on the MCP page. Add ssid.ai to any MCP-capable agent host:
{
"mcpServers": {
"ssid": { "command": "npx", "args": ["-y", "ssid-mcp"] }
}
}- npm: npmjs.com/package/ssid-mcp
- x402: GET /api/x402/lookup — machine-payable (402 → pay → data).