ssid.aiAPI

ssid.ai API

Identify the manufacturer behind any MAC address, and know when it's a randomized (private) address instead of a real prefix. No signup for the free tier.

Try it

curl "https://ssid.ai/api/v1/lookup?mac=F4:F5:E8:11:22:33"
{
  "mac": "F4:F5:E8:11:22:33",
  "oui": "F4F5E8",
  "kind": "universal",
  "randomized": false,
  "vendor": { "organization": "Google, Inc.", "address": "..." },
  "blockType": "MA-L",
  "block": null,
  "cidRegistrant": null,
  "deviceType": null,
  "confidence": 1,
  "source": { "name": "IEEE MA-L registry", "url": "https://standards-oui.ieee.org/oui/oui.csv" }
}

The lookup matches the longest IEEE prefix, not just the 24-bit OUI. Where the IEEE kept an MA-L block and assigned longer prefixes out of it, vendor.organization is the company holding the sub-block and blockType says which registry answered: MA-L (24-bit), MA-M (28-bit), or MA-S / IAB (36-bit). Sub-block answers also carry block.start and block.end.

curl "https://ssid.ai/api/v1/lookup?mac=70:B3:D5:12:34:56"

{
  "vendor": { "organization": "Amfitech ApS", "address": "..." },
  "blockType": "MA-S",
  "block": { "start": "70B3D5123000", "end": "70B3D5123FFF" },
  "source": { "name": "IEEE MA-S registry", "url": "https://standards-oui.ieee.org/oui36/oui36.csv" }
}

A randomized address keeps vendor: null and confidence: 0, because the device generated the address itself and no manufacturer assigned it. When its 24-bit prefix is a registered Company ID, cidRegistrant names the registrant alongside that null: DA:A1:19 is Google's, and Android generates from it.

Router default logins

The manufacturer-cited factory login for a router model, by ssid.ai slug or by exact brand + model. Null credential fields are real answers: credType says why there is no factory password, and source.url is the manufacturer page it was read from. Metered on every tier (this is the paid data); brand + model returns 409 with up to five candidate slugs when the model is ambiguous, never a list.

curl "https://ssid.ai/api/v1/device/tp-link-archer-ax55"
curl "https://ssid.ai/api/v1/device?brand=TP-Link&model=Archer%20AX55"
{
  "slug": "tp-link-archer-ax55",
  "brand": "TP-Link", "modelName": "Archer AX55", "category": "router",
  "defaultGatewayIp": "192.168.0.1", "loginHost": "tplinkwifi.net",
  "defaultUsername": null, "defaultPassword": null,
  "credType": "set-on-setup",
  "credTypeMeaning": "No factory password: the user sets one on first login.",
  "resetSteps": "...", "confidence": "high",
  "source": { "url": "https://www.tp-link.com/us/support/faq/87/", "name": "TP-Link official support (FAQ 87)" },
  "url": "https://ssid.ai/routers/tp-link-archer-ax55"
}

Get a key

MAC/OUI lookup is free with no daily limit and needs no key at all. A free key raises router and compliance calls from 100 to 1,000 a day — no email, shown once. ssid Pro ($15/mo) issues its own key on the checkout confirmation page.

No email required. Free tier: 1,000 lookups/day. Higher tiers upgrade with the same key.

Auth

Pass an API key to raise limits: Authorization: Bearer ssid_… (or x-api-key). Every response carries X-RateLimit-* headers.

Tiers

TierPriceRateBurst
Anonymous$0Unlimited60 / min
Free$0Unlimited60 / min
Pro$15 / mo10,000 / day120 / min

The burst ceiling scales with the tier so the daily figure stays reachable; your ceiling comes back on every response in X-RateLimit-Burst. Full terms, and when a cheaper option is the right call, on pricing.

ssid Pro — $15/mo

ssid Pro · $15/mo · one seat

submit_correction · 10,000 router calls/day · 120/min

Checkout and card handling run on Stripe — your card never touches ssid.ai. A new key is shown once on the confirmation page; an upgraded key keeps its value and gets Pro within a minute. Cancel any time from Manage billing; the key drops back to the free tier at period end.

Stuck, or something went wrong during checkout? Email support@ssid.ai and a person will answer. Router-data volume beyond Pro or data licensing: hello@ssid.ai. Refunds per the terms.

For agents

MCP server — get_router_defaults, check_router_compliance, lookup_mac and submit_correction over stdio. The three read tools need no key; submit_correction needs a Pro key in SSID_API_KEY. The router tools call the endpoints above, so their limits are the tiers above. Full docs on the MCP page. Add ssid.ai to any MCP-capable agent host:

{
  "mcpServers": {
    "ssid": { "command": "npx", "args": ["-y", "ssid-mcp"] }
  }
}