> ## Documentation Index
> Fetch the complete documentation index at: https://docs-api.kravata.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Update IP Allowlist

> Registers the IP ranges (CIDR notation) allowed to call the API with your credentials. The client is taken from the access token, so you can only change your own allowlist.

The list you send **replaces** the current one completely. To add an IP, send the full list including the existing ranges.

#### Request

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| Authorization | Header | Yes | `Bearer <access_token>` obtained from **POST /api/v1/client/token**. |

#### Request Body

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| allowedIpRanges | array of strings | Yes | IP ranges in CIDR notation, e.g. `203.0.113.10/32` for a single IP or `198.51.100.0/24` for a range. IPv4 and IPv6 are supported. |

```bash
curl -X PUT https://partners-api.kravata.co/api/v1/client/security/ips \
  --cert client.crt --key client.key \
  -H "Authorization: Bearer <accessToken>" \
  -H "Content-Type: application/json" \
  -d '{"allowedIpRanges": ["203.0.113.10/32", "198.51.100.0/24"]}'
```

#### Response

| Field | Description |
| --- | --- |
| id | Identifier of your security policy. |
| partnerClientId | Your client identifier. |
| allowedIpRanges | The IP ranges now in effect. |
| subjectCn / certSerial | Common name and serial number of your registered mTLS certificate. |
| issuedAt / expiresAt / revokedAt | Validity of your mTLS certificate. |
| createdAt / updatedAt | Timestamps of the policy. |

#### Important

- **Include the IP you are calling from.** If the new list does not contain it, your next requests are rejected, including calls to this endpoint.
- **An empty list (`[]`) blocks all IPs.**
- Entries that are not valid CIDR ranges are ignored when the allowlist is checked; verify each range before sending it.
- If you lock yourself out, contact Kravata to restore access.

#### Errors

| Status | When |
| --- | --- |
| 400 | Invalid request body. |
| 401 | Missing, invalid or expired access token. |
| 403 | The token is not a client (partner) token. |



## OpenAPI

````yaml /stack/openapi.json put /api/v1/client/security/ips
openapi: 3.1.0
info:
  title: Kravata Stack API
  version: '2.0'
  description: >-
    Kravata Stack API: users, accounts, custody wallets, liquidity ramps and
    fiat payments.
servers:
  - url: https://test-api-kore.kravata.co
    description: Test
  - url: https://partners-api.kravata.co
    description: Production (mTLS + IP allowlist)
security:
  - bearerAuth: []
tags:
  - name: Authentication
  - name: Users
  - name: Accounts
  - name: Earn
  - name: Custody
  - name: Liquidity Ramps
  - name: Payments
  - name: Webhooks
paths:
  /api/v1/client/security/ips:
    put:
      tags:
        - Authentication
      summary: Update IP Allowlist
      description: >-
        Registers the IP ranges (CIDR notation) allowed to call the API with
        your credentials. The client is taken from the access token, so you can
        only change your own allowlist.


        The list you send **replaces** the current one completely. To add an IP,
        send the full list including the existing ranges.


        #### Request


        | Field | Type | Required | Description |

        | --- | --- | --- | --- |

        | Authorization | Header | Yes | `Bearer <access_token>` obtained from
        **POST /api/v1/client/token**. |


        #### Request Body


        | Field | Type | Required | Description |

        | --- | --- | --- | --- |

        | allowedIpRanges | array of strings | Yes | IP ranges in CIDR notation,
        e.g. `203.0.113.10/32` for a single IP or `198.51.100.0/24` for a range.
        IPv4 and IPv6 are supported. |


        ```bash

        curl -X PUT https://partners-api.kravata.co/api/v1/client/security/ips \
          --cert client.crt --key client.key \
          -H "Authorization: Bearer <accessToken>" \
          -H "Content-Type: application/json" \
          -d '{"allowedIpRanges": ["203.0.113.10/32", "198.51.100.0/24"]}'
        ```


        #### Response


        | Field | Description |

        | --- | --- |

        | id | Identifier of your security policy. |

        | partnerClientId | Your client identifier. |

        | allowedIpRanges | The IP ranges now in effect. |

        | subjectCn / certSerial | Common name and serial number of your
        registered mTLS certificate. |

        | issuedAt / expiresAt / revokedAt | Validity of your mTLS certificate.
        |

        | createdAt / updatedAt | Timestamps of the policy. |


        #### Important


        - **Include the IP you are calling from.** If the new list does not
        contain it, your next requests are rejected, including calls to this
        endpoint.

        - **An empty list (`[]`) blocks all IPs.**

        - Entries that are not valid CIDR ranges are ignored when the allowlist
        is checked; verify each range before sending it.

        - If you lock yourself out, contact Kravata to restore access.


        #### Errors


        | Status | When |

        | --- | --- |

        | 400 | Invalid request body. |

        | 401 | Missing, invalid or expired access token. |

        | 403 | The token is not a client (partner) token. |
      operationId: update-ip-allowlist
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                allowedIpRanges:
                  type: array
                  items:
                    type: string
            example:
              allowedIpRanges:
                - 203.0.113.10/32
                - 198.51.100.0/24
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    type: string
                  partnerClientId:
                    type: string
                  realmName:
                    type: string
                  allowedIpRanges:
                    type: array
                    items:
                      type: string
                  certSerial:
                    type: string
                  subjectCn:
                    type: string
                  issuedAt:
                    type: string
                  expiresAt:
                    type: string
                  revokedAt: {}
                  createdAt:
                    type: string
                  updatedAt:
                    type: string
              examples:
                ip-allowlist-updated:
                  summary: IP allowlist updated
                  value:
                    id: 5b0d3c1e-8f2a-4c6d-9e1b-7a3f2c4d5e6f
                    partnerClientId: <your-client-id>
                    realmName: <your-realm>
                    allowedIpRanges:
                      - 203.0.113.10/32
                      - 198.51.100.0/24
                    certSerial: <certificate-serial>
                    subjectCn: <certificate-common-name>
                    issuedAt: '2026-09-01T00:00:00Z'
                    expiresAt: '2027-09-01T00:00:00Z'
                    revokedAt: null
                    createdAt: '2026-09-01T00:00:00Z'
                    updatedAt: '2026-09-30T12:00:00Z'
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: Access token from POST /api/v1/client/token.

````