Restrict an API key to your server IPs or website

Updated 3 October 2026

Open Settings next to any key in your dashboard. You can set:

  • Allowed server IPs: the key only works from these IP addresses or ranges, such as 203.0.113.0/24. This is the strongest protection for server-to-server use.
  • Allowed website domains: the key works from browser JavaScript only on these sites, such as example.com or *.example.com.
  • Expiry date: the key stops working automatically after this day.

Requests that break these rules are refused with HTTP 403 and an error such as ip_not_allowed or origin_not_allowed.

Was this article helpful?

Still need help?

Our team usually replies within one business day.

Open a support ticketContact us