Restrict an API key to your server IPs or website
Updated 3 October 2026
Open Settings next to any key in your dashboard. You can set:
- Allowed server IPs: the key only works from these IP addresses or ranges, such as
203.0.113.0/24. This is the strongest protection for server-to-server use. - Allowed website domains: the key works from browser JavaScript only on these sites, such as
example.comor*.example.com. - Expiry date: the key stops working automatically after this day.
Requests that break these rules are refused with HTTP 403 and an error such as ip_not_allowed or origin_not_allowed.