Skip to main content
Tazapay now supports IP allowlisting, so you can control which IP addresses can use your API secret key. Requests from non-allowlisted IPs are blocked, even when the key is valid, reducing risk if your secret key is ever leaked.

What’s New

1) Manage your IP allowlist from the dashboard

Add or remove IP addresses and CIDR ranges directly from the API Keys & Developer Docs page under Manage IP Allowlist. Changes take effect immediately after saving.

2) Configure allowlists for each secret key

Allowlists are configured per secret key, so your test and live keys each have their own allowlist.

3) Support for IPv4, IPv6 and CIDR ranges

Add up to 5 entries per secret key. Each entry can be an individual IPv4 or IPv6 address, or a CIDR range. Only public IP addresses can be allowlisted.

Action Required

No action required. The allowlist is empty by default, so your existing integrations continue to work without any changes. If you want to restrict access to your API secret key, add your trusted IP addresses or CIDR ranges to the IP allowlist.

Questions

See the IP Allowlisting guide for setup instructions and more details, or reach out to support@tazapay.com or your account manager.