Skip to main content
IP allowlisting restricts which IP addresses can use your API secret key. The allowlist can contain individual IP addresses and CIDR ranges. Only requests originating from an allowlisted IP address are permitted. Requests made with a valid key from any other IP address are blocked. Use this to reduce risk if your secret key is ever leaked — even with valid credentials, requests from outside your allowlisted IPs will be rejected.
IP allowlisting is managed from the Tazapay dashboard, on the API Keys & Developer Docs page, under Manage IP Allowlist. Allowlists are configured per secret key, so your test and live keys each have their own allowlist.
The allowlist is empty by default, which allows requests from any IP address. Your secret key is not IP-restricted until you add at least one entry.

How It Works

Prerequisite: Your API_Key and API_Secret are authenticated as described in Authentication. Invalid credentials are rejected here, before any IP check. Once authenticated:
  1. If the allowlist is empty, the request is allowed through — no IP check is performed.
  2. If the allowlist is not empty, Tazapay determines the originating IP address of the request and checks it against the allowlisted IP addresses and CIDR ranges.
  3. Requests from an allowlisted IP address are permitted. Requests from all other IP addresses are blocked.
Changes to the allowlist take effect immediately after saving.

Supported Formats

You can allowlist individual IP addresses and CIDR ranges, in IPv4 or IPv6, up to a total of 5 entries per secret key. Each IP address or CIDR range counts as one entry, regardless of range size.

Invalid IP Addresses

The following are not permitted on an IP allowlist:
  • Non-public addresses — private, loopback, link-local and other reserved addresses. Only public IP addresses can be allowlisted.
  • Invalid formats — anything that is not a valid IPv4 or IPv6 address or CIDR range.

Configuring the Allowlist

Add or update entries

  1. Navigate to the API Keys & Developer Docs page in the sandbox dashboard or live dashboard.
  2. Click Manage IP Allowlist.
  3. Enter any combination of IP addresses and CIDR ranges, up to a total of 5, in the IP Addresses field, separated by commas or spaces, and click Add.
  4. Click Save.

Remove entries

  1. Navigate to the API Keys & Developer Docs page in the sandbox dashboard or live dashboard.
  2. Click Manage IP Allowlist.
  3. Click the delete icon next to the entry you want to remove.
  4. Click Remove IP to confirm.
  5. Click Save.