Skip to main content
An IP whitelist limits where requests authenticated with your YCloud account API key can originate. When the feature is enabled, YCloud accepts API calls using the key only from IP addresses in the whitelist. YCloud recommends enabling the IP whitelist for every account that calls APIs from known server environments. It adds an important layer of protection: even if an API key is exposed, requests from unapproved IP addresses are blocked.
Add every production, staging, backup, and failover egress IP before enabling the whitelist. If an active system sends requests from an address that is not listed, its YCloud API calls will fail.

Before you begin

Make sure that:
  • Your role can access Developers > IP whitelist in the YCloud dashboard.
  • You know the public outbound IP address used by each system that calls YCloud APIs.
  • Your infrastructure uses static egress IP addresses, or you have a process for updating the whitelist when an address changes.
  • You have included backup gateways, NAT gateways, proxies, and failover environments that may send requests.
Add the public IP address that YCloud sees for outbound traffic. Do not add a private internal address such as an address in the 10.0.0.0/8, 172.16.0.0/12, or 192.168.0.0/16 ranges.

Add approved IP addresses

  1. Sign in to the YCloud dashboard.
  2. Go to Developers > IP whitelist.
  3. Click Add Whitelist IP.
  4. Enter the public outbound IP address of a system that calls YCloud APIs.
  5. Save the address.
  6. Repeat these steps for every production, staging, backup, and failover source.
Add Whitelist IP dialog showing one-address-per-line input.

Enter one approved public IP address or range per line. This form has not been submitted.

The table displays each approved IP address and the date it was added.

Enable the IP whitelist

After you have added all required addresses:
  1. Review the whitelist with your infrastructure or networking team.
  2. Turn on Enable IP whitelists feature.
  3. Send a test request from each expected environment.
  4. Confirm that scheduled jobs, webhook-related services, and failover systems can still call YCloud APIs.
The whitelist applies to the source IP address of the outbound API request. If requests pass through a NAT gateway or proxy, add that gateway or proxy’s public egress IP rather than the application’s internal IP.

Update the whitelist safely

Infrastructure changes can alter your public egress IP. Use this order to avoid service interruption:
  1. Add the new public IP address to the whitelist.
  2. Send a successful test request through the new address.
  3. Move production traffic to the new route.
  4. Confirm that no traffic uses the previous address.
  5. Delete the previous IP address from the whitelist.
Do not remove an address until every service that depends on it has migrated.

Security recommendations

  • Enable the IP whitelist even when your API key is stored in a secret manager.
  • Grant access to whitelist settings only to trusted account members.
  • Review the list regularly and remove addresses that are no longer in use.
  • Monitor failed authentication attempts after network or infrastructure changes.
  • Rotate the account API key immediately if you suspect exposure. See Manage API keys.
An IP whitelist complements secure API key handling; it does not replace key rotation, least-privilege access, or secret management.