Credits & limits
pWhois Maps is operated by VOSTROM. It stands on public routing data, public registry data and open-source software. This page says what we use, under which terms, and how much of the service you can use for free each day.
Attributions & licenses
Third-party software and data are used under the following terms. The inventory of every bundled component and its license is in /maps/licenses/THIRD_PARTY.md; each full license text is linked below.
Routing data
All routing data shown on Maps comes from the Prefix WhoIs service (whois.pwhois.org), which builds its table from VOSTROM's own live BGP sessions and route-views digests. Maps does not query any other routing-data source.
Attribution on captions and exports reads Data: Prefix WhoIs (pwhois.org).
Registry data
Organisation and network names come from the public registries of ARIN, RIPE NCC, APNIC, LACNIC and AFRINIC, as compiled by pWhois under its agreements with each registry. Copyright and database rights remain with the registries. This data is provided for network operations and research and may not be used for advertising, direct marketing or marketing research.
Geolocation
The city, region, country and coordinates shown for a prefix are community-sourced. VOSTROM makes no guarantee as to their accuracy, and they must not be relied on for any purpose requiring precision.
Software
Graphviz (https://graphviz.org), version 16.1.0, is included in object-code (WebAssembly) form via Viz.js. Graphviz is licensed under the Eclipse Public License, Version 2.0 (/maps/licenses/EPL-2.0.txt).
Viz.js: Copyright (c) Michael Daines, MIT License (text). Expat: Copyright (c) 1998-2000 Thai Open Source Software Center Ltd and Clark Cooper; Copyright (c) 2001-2025 Expat maintainers, MIT License (text).
mermaid: Copyright (c) 2014-2022 Knut Sveidqvist, MIT License (text), including bundled components: d3 (Copyright 2010-2023 Mike Bostock, ISC); dagre-d3-es (MIT); cytoscape.js (Copyright (c) 2016-2024 The Cytoscape Consortium, MIT); cytoscape-fcose (Copyright (c) 2018-present iVis-at-Bilkent, MIT); cytoscape-cose-bilkent (MIT); DOMPurify (Copyright (c) Cure53 and other contributors, used under the Apache License 2.0); KaTeX (Copyright (c) 2013-2020 Khan Academy and other contributors, MIT); khroma (MIT); roughjs (Copyright (c) 2019 Preet Shihn, MIT); Langium and Chevrotain (MIT and Apache License 2.0); d3-sankey (BSD-3-Clause, text); lodash-es (Copyright OpenJS Foundation and other contributors, MIT); and marked, stylis, dayjs, uuid, @braintree/sanitize-url, @iconify/utils, @upsetjs/venn.js, es-toolkit, fastdom and ts-dedent (all MIT). Mermaid's optional ELK layout engine is not included.
d3: Copyright 2010-2023 Mike Bostock, ISC License (text); d3-ease includes work by Robert Penner, BSD-3-Clause (text).
| Component | Version | License | Text |
|---|---|---|---|
| d3 | 7.9.0 | ISC | ISC-d3.txt |
| mermaid | 11.17.2 | MIT | MIT-mermaid.txt |
| Viz.js (@viz-js/viz) | 3.31.0 | MIT | MIT-viz.txt |
| Graphviz (in Viz.js) | 16.1.0 | EPL-2.0 | EPL-2.0.txt · source statement |
| Expat (in Viz.js) | 2.8.5 | MIT | MIT-expat.txt |
| DOMPurify (in mermaid) | 3.4.12 | Apache-2.0 (elected) | Apache-2.0.txt |
| Fonts | — | OFL-1.1 | OFL-1.1.txt |
Exact file versions, SHA-256 digests and sizes are recorded in THIRD_PARTY.md. Every vendored file is served from this site; pWhois Maps loads no scripts, styles, fonts or images from third-party hosts. License comments inside the vendored files are kept intact.
Fonts
JetBrains Mono (Copyright 2020 The JetBrains Mono Project Authors) and Nunito Sans (Copyright 2016 The Nunito Sans Project Authors) are licensed under the SIL Open Font License, Version 1.1 (/maps/licenses/OFL-1.1.txt). Both are self-hosted.
Maps terms
- Personal and operational use. Use pWhois Maps to understand, document and troubleshoot networks. Commercial redistribution of the data or of bulk extracts needs a conversation first — get in touch.
- No bulk harvesting. Do not script the maps to crawl the routing table or the registries, and do not use the service to build competing datasets. For programmatic access use the public whois service on port 43 (see queries) or run your own pWhois server.
- Exports carry attribution. SVG and PNG exports include an attribution line by default. You may switch it off for a single export, but then crediting the data source (Prefix WhoIs) when you republish is your responsibility. Do not use registry-derived fields such as organisation names for advertising, direct marketing or marketing research.
- No warranty. Maps are derived from the pWhois route cache and public registries, which can lag or be wrong. The service is provided as-is; see the general terms of use.
Limits
Each source IP address gets 100 chart inputs per UTC day. Building or expanding a chart costs one input, including when the result comes from our 24-hour cache; opening the galaxy overview, reading a node's registry details and exporting are free. The counter resets at 00:00 UTC, and the live readout on the Maps page shows what you have left. Short-term burst limits (20 chart builds and 30 detail lookups per minute) and a site-wide budget protect the pWhois servers.
Shared looks: up to 30 per source IP per UTC day (10 a minute); creating or opening one costs no chart inputs, but whoever opens it rebuilds the map with their own. A shared look is kept until a year after its last visit (and at least a year after it was made), then removed. Plain permalinks such as /maps/15169/4 are unlimited; see Permalinks & sharing.
Need more? Education, research and operations teams can request a higher limit and tell us the address, what you are building and roughly how many charts you need.
Privacy
To count chart inputs and to prevent abuse we record your source IP address and browser user agent with each chart request (and with each shared look you create, which keeps its source address for as long as the share exists). This log is retained for 90 days and is visible to VOSTROM staff for abuse control. We do not use accounts and do not set advertising or tracking cookies for Maps. An anti-abuse check run by VOSTROM (Vouch) executes before a chart is built. See the site privacy policy for everything else.
Data freshness
Routing data comes from the pWhois route cache, which is built from VOSTROM's live BGP sessions and route-views digests. The cache refreshes on its own schedule and reports each refresh as Cache-Date; every chart shows the cache date of its sources, and the status rail at the top of the site shows live cache information. The galaxy overview of the largest origin ASes is refreshed from the same cache every 12 hours, and the page serves a copy that is at most an hour old; charts you build are cached for up to 24 hours. Routing changes minute by minute, so treat any chart as a snapshot, not a live view.
How a map is drawn
A map shows what pWhois’s route collectors observe, selected by a fixed set of rules. This section states those rules.
Which paths are read
An AS map is built only from the paths to the prefixes that network originates. For a network with 250 or fewer prefixes in an address family, every path reported by every collector peer is read; for a larger network, the server’s best path for each prefix is used, which keeps the cost of a map bounded. An address or prefix map reads every collector’s path to that route.
Direct upstreams and collector peers
- Direct upstream. The AS immediately before the focus on a path. Direct upstreams are always drawn: up to 48, ranked by the number of paths they carry. MCP charts draw fewer to keep labels legible and say in the caption how many were left out.
- Collector peer. The first AS of each path is the network whose BGP session feeds one of pWhois’s collectors. It shows where a route was observed from, not who the network buys transit from. Collector peers are counted in every map and chart caption, and drawn only when “Show collector vantage points” is on (in the MCP tool,
collectors: true).
Farther hops
Above each direct upstream, the networks farther up the paths are ranked: networks on the best path first, then by the number of paths they carry. Up to 8 per upstream are drawn at two hops and up to 4 at three hops. The rest fold into a “+K more” ghost node, which lists them in the side panel.
Where upstreams stop
Nothing is drawn above a Tier-1 network. VOSTROM maintains a short list of settlement-free networks for this purpose:
| AS | Network |
|---|---|
| AS174 | Cogent |
| AS209 | Lumen (CenturyLink) |
| AS286 | KPN |
| AS701 | Verizon |
| AS1239 | Sprint |
| AS1299 | Arelion |
| AS2914 | NTT |
| AS3257 | GTT |
| AS3320 | Deutsche Telekom |
| AS3356 | Lumen (Level 3) |
| AS3491 | PCCW Global |
| AS5511 | Orange |
| AS6453 | Tata Communications |
| AS6461 | Zayo |
| AS6762 | Telecom Italia Sparkle |
| AS6830 | Liberty Global |
| AS6939 | Hurricane Electric |
| AS7018 | AT&T |
| AS12956 | Telefónica |
For any other direct upstream, pWhois checks whether it ever sees a provider above that network on the network’s own routes. If it sees none, the network is marked observed transit-free and nothing is drawn above it either. At most 6 upstreams per map are checked; a definite answer is kept for 24 hours, and an unknown one (no answer, or an answer too large to check) is retried after 15 minutes. An upstream that is not checked, or whose answer is unknown, is treated as not transit-free.
Where a chain of upstreams reaches a collector’s own session, the last network drawn carries an “observed from here” mark: that is where pWhois’s collectors receive the route.
Address families
An AS map combines IPv4 and IPv6. In the IPv4 view an edge tagged v6 was seen on IPv6 only, and in the IPv6 view an edge tagged v4 was seen on IPv4 only; an untagged edge was seen on the view’s own family.
Downstream networks
Downstream views, the networks behind an AS, use pWhois’s transit data: every route whose path passes through that AS. The automatic fetch is bounded at 20,000 usable routes, 12 MB or 12 seconds per address family, and a view cut by any of these limits is marked sampled. The full cone can be loaded on request, within 250,000 routes, 64 MB or 60 seconds per family.
Caches
Maps are cached for 24 hours and the galaxy overview for 12 hours, as described under Data freshness.
Contact
Questions about attribution, a license notice or a data source: contact us. If you represent a data source or a registry and want something changed or removed, tell us and we will act promptly.