> ## Documentation Index
> Fetch the complete documentation index at: https://developer.tazapay.com/llms.txt
> Use this file to discover all available pages before exploring further.

# IP Allowlisting

> Restrict which IP addresses can use your API secret key

IP allowlisting restricts which IP addresses can use your API secret key. The allowlist can contain individual IP addresses and CIDR ranges. Only requests originating from an allowlisted IP address are permitted. Requests made with a valid key from any other IP address are blocked.

Use this to reduce risk if your secret key is ever leaked — even with valid credentials, requests from outside your allowlisted IPs will be rejected.

<Info>
  IP allowlisting is managed from the Tazapay dashboard, on the **API Keys &
  Developer Docs** page, under **Manage IP Allowlist**. Allowlists are
  configured per secret key, so your test and live keys each have their own
  allowlist.
</Info>

<Warning>
  The allowlist is **empty by default**, which allows requests from any IP
  address. Your secret key is not IP-restricted until you add at least one
  entry.
</Warning>

***

## How It Works

**Prerequisite:** Your `API_Key` and `API_Secret` are authenticated as described in [Authentication](/api-reference/api-overview/authentication). Invalid credentials are rejected here, before any IP check.

Once authenticated:

1. If the allowlist is empty, the request is allowed through — no IP check is performed.
2. If the allowlist is not empty, Tazapay determines the originating IP address of the request and checks it against the allowlisted IP addresses and CIDR ranges.
3. Requests from an allowlisted IP address are permitted. Requests from all other IP addresses are blocked.

Changes to the allowlist take effect immediately after saving.

***

## Supported Formats

You can allowlist individual IP addresses and CIDR ranges, in IPv4 or IPv6, up to a total of **5 entries** per secret key. Each IP address or CIDR range counts as one entry, regardless of range size.

| Format | Example | Permits |
| - | - | - |
| IPv4 address | `198.51.100.42` | That address only |
| IPv6 address | `2001:db8:a05:42::7` | That address only |
| IPv4 CIDR range | `198.51.100.0/24` | All 256 addresses from `198.51.100.0` to `198.51.100.255` |
| IPv6 CIDR range | `2001:db8:a05:42::/64` | All addresses from `2001:db8:a05:42::` to `2001:db8:a05:42:ffff:ffff:ffff:ffff` |

***

## Invalid IP Addresses

The following are not permitted on an IP allowlist:

* **Non-public addresses** — private, loopback, link-local and other reserved addresses. Only public IP addresses can be allowlisted.
* **Invalid formats** — anything that is not a valid IPv4 or IPv6 address or CIDR range.

***

## Configuring the Allowlist

### Add or update entries

1. Navigate to the **API Keys & Developer Docs** page in the [sandbox dashboard](https://dashboard-sandbox.tazapay.com/) or [live dashboard](https://dashboard.tazapay.com).
2. Click **Manage IP Allowlist**.
3. Enter any combination of IP addresses and CIDR ranges, up to a total of 5, in the **IP Addresses** field, separated by commas or spaces, and click **Add**.
4. Click **Save**.

### Remove entries

1. Navigate to the **API Keys & Developer Docs** page in the [sandbox dashboard](https://dashboard-sandbox.tazapay.com/) or [live dashboard](https://dashboard.tazapay.com).
2. Click **Manage IP Allowlist**.
3. Click the delete icon next to the entry you want to remove.
4. Click **Remove IP** to confirm.
5. Click **Save**.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.