> ## Documentation Index
> Fetch the complete documentation index at: https://docs-api.kravata.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Get IP Allowlist

> Returns the IP allowlist currently registered for your client. The client is taken from the access token.

#### Request

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| Authorization | Header | Yes | `Bearer <access_token>` obtained from **POST /api/v1/client/token**. |

#### Response

| Field | Description |
| --- | --- |
| partnerClientId | Your client identifier. |
| allowedIpRanges | Registered IP ranges. `null` means no allowlist has been registered yet (requests are not filtered by IP); `[]` means every IP is blocked. |
| updatedAt | Last update of the allowlist, or `null` when none is registered. |

#### Errors

| Status | When |
| --- | --- |
| 401 | Missing, invalid or expired access token. |
| 403 | The token is not a client (partner) token. |



## OpenAPI

````yaml /stack/openapi.json get /api/v1/client/security/ips
openapi: 3.1.0
info:
  title: Kravata Stack API
  version: '2.0'
  description: >-
    Kravata Stack API: users, accounts, custody wallets, liquidity ramps and
    fiat payments.
servers:
  - url: https://test-api-kore.kravata.co
    description: Test
  - url: https://partners-api.kravata.co
    description: Production (mTLS + IP allowlist)
security:
  - bearerAuth: []
tags:
  - name: Authentication
  - name: Users
  - name: Accounts
  - name: Earn
  - name: Custody
  - name: Liquidity Ramps
  - name: Payments
  - name: Webhooks
paths:
  /api/v1/client/security/ips:
    get:
      tags:
        - Authentication
      summary: Get IP Allowlist
      description: >-
        Returns the IP allowlist currently registered for your client. The
        client is taken from the access token.


        #### Request


        | Field | Type | Required | Description |

        | --- | --- | --- | --- |

        | Authorization | Header | Yes | `Bearer <access_token>` obtained from
        **POST /api/v1/client/token**. |


        #### Response


        | Field | Description |

        | --- | --- |

        | partnerClientId | Your client identifier. |

        | allowedIpRanges | Registered IP ranges. `null` means no allowlist has
        been registered yet (requests are not filtered by IP); `[]` means every
        IP is blocked. |

        | updatedAt | Last update of the allowlist, or `null` when none is
        registered. |


        #### Errors


        | Status | When |

        | --- | --- |

        | 401 | Missing, invalid or expired access token. |

        | 403 | The token is not a client (partner) token. |
      operationId: get-ip-allowlist
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  partnerClientId:
                    type: string
                  allowedIpRanges:
                    type: array
                    items:
                      type: string
                  updatedAt:
                    type: string
              examples:
                ip-allowlist:
                  summary: IP allowlist
                  value:
                    partnerClientId: 4e1f6c2a-9b3d-4f7e-8a21-6c5d0b9e3f12
                    allowedIpRanges:
                      - 0.0.0.0/0
                      - '::/0'
                    updatedAt: '2026-10-01T05:13:42.520183Z'
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: Access token from POST /api/v1/client/token.

````