Before you begin
Make sure that:- Your role can access Developers > IP whitelist in the YCloud dashboard.
- You know the public outbound IP address used by each system that calls YCloud APIs.
- Your infrastructure uses static egress IP addresses, or you have a process for updating the whitelist when an address changes.
- You have included backup gateways, NAT gateways, proxies, and failover environments that may send requests.
10.0.0.0/8, 172.16.0.0/12, or 192.168.0.0/16 ranges.
Add approved IP addresses
- Sign in to the YCloud dashboard.
- Go to Developers > IP whitelist.
- Click Add Whitelist IP.
- Enter the public outbound IP address of a system that calls YCloud APIs.
- Save the address.
- Repeat these steps for every production, staging, backup, and failover source.
Enter one approved public IP address or range per line. This form has not been submitted.
Enable the IP whitelist
After you have added all required addresses:- Review the whitelist with your infrastructure or networking team.
- Turn on Enable IP whitelists feature.
- Send a test request from each expected environment.
- Confirm that scheduled jobs, webhook-related services, and failover systems can still call YCloud APIs.
The whitelist applies to the source IP address of the outbound API request. If requests pass through a NAT gateway or proxy, add that gateway or proxy’s public egress IP rather than the application’s internal IP.
Update the whitelist safely
Infrastructure changes can alter your public egress IP. Use this order to avoid service interruption:- Add the new public IP address to the whitelist.
- Send a successful test request through the new address.
- Move production traffic to the new route.
- Confirm that no traffic uses the previous address.
- Delete the previous IP address from the whitelist.
Security recommendations
- Enable the IP whitelist even when your API key is stored in a secret manager.
- Grant access to whitelist settings only to trusted account members.
- Review the list regularly and remove addresses that are no longer in use.
- Monitor failed authentication attempts after network or infrastructure changes.
- Rotate the account API key immediately if you suspect exposure. See Manage API keys.

