Skip to content
Developer guide

IP allowlist

Lock your production secret key to your servers' IP addresses.

Context and key considerations

Each shop can have a list of allowed IP addresses or CIDR ranges. When enforced, the production secret key (and any access token minted with it) only authenticates from those IPs: a leaked key stops working outside your servers.

1 / 4

What it applies to

Only server-to-server calls with the production secret key. Never the publishable key, the hosted checkout, or anything your buyers use — they call from any network. Sandbox is not restricted, so your team can integrate from anywhere.

The IP evaluated is your server's egress IP. If your infrastructure has no fixed IP (serverless functions, cloud without static NAT), ask support for a range or an exemption.
Key2Pay Developer documentationAPI v1
Documentation
Dashboard