IP allowlisting is managed from the Tazapay dashboard, on the API Keys &
Developer Docs page, under Manage IP Allowlist. Allowlists are
configured per secret key, so your test and live keys each have their own
allowlist.
How It Works
Prerequisite: YourAPI_Key and API_Secret are authenticated as described in Authentication. Invalid credentials are rejected here, before any IP check.
Once authenticated:
- If the allowlist is empty, the request is allowed through — no IP check is performed.
- If the allowlist is not empty, Tazapay determines the originating IP address of the request and checks it against the allowlisted IP addresses and CIDR ranges.
- Requests from an allowlisted IP address are permitted. Requests from all other IP addresses are blocked.
Supported Formats
You can allowlist individual IP addresses and CIDR ranges, in IPv4 or IPv6, up to a total of 5 entries per secret key. Each IP address or CIDR range counts as one entry, regardless of range size.Invalid IP Addresses
The following are not permitted on an IP allowlist:- Non-public addresses — private, loopback, link-local and other reserved addresses. Only public IP addresses can be allowlisted.
- Invalid formats — anything that is not a valid IPv4 or IPv6 address or CIDR range.
Configuring the Allowlist
Add or update entries
- Navigate to the API Keys & Developer Docs page in the sandbox dashboard or live dashboard.
- Click Manage IP Allowlist.
- Enter any combination of IP addresses and CIDR ranges, up to a total of 5, in the IP Addresses field, separated by commas or spaces, and click Add.
- Click Save.
Remove entries
- Navigate to the API Keys & Developer Docs page in the sandbox dashboard or live dashboard.
- Click Manage IP Allowlist.
- Click the delete icon next to the entry you want to remove.
- Click Remove IP to confirm.
- Click Save.