IP allowlist for Customer Portal and Public API

Prev Next

An IP allowlist restricts who can reach your Veriff integration by IP address. You can set up two independent allowlists in the Veriff Customer Portal: one for access to Customer Portal itself (referred to as “Station access” in the UI), and one for access to the Veriff Public API. When a list is active, only requests from the IP addresses and ranges on that list are allowed.

This article is about restricting inbound access to your Veriff account from your own IP addresses. If you need the list of Veriff's URLs and IP addresses to allow in your own firewall, see Allowlisted URLs and IP addresses.

Prerequisites

  • An Enterprise plan with Veriff.

  • The "Manage IP access allowlist" permission in Customer Portal. By default:

    • Under Advanced permissions, the Owner team has it.

    • Under Basic permissions, the Administrator group has it.

    • If you do not have this permission, ask a user who can manage roles to grant it. See Changing user roles in Veriff Station in Knowledge base (you need to log in to Veriff Customer Portal to access the article).

  • The public (egress) IP addresses or ranges that your team and your servers use to connect to Veriff.


How IP allowlists work

The Station access (aka access to the Veriff Customer Portal) list and the Public API access list behave as two separate lists. Each list can hold different IP addresses and ranges, and each one is enforced on its own.

The Public API access list applies to API requests from your own systems. It does not apply to requests made from your end-users' devices, such as the web flow or mobile SDKs, so restricting the Public API to your server IPs does not block your end-users.

An empty list allows all requests, meaning that the list is enforced only when it has at least one entry. While a list is empty, requests from any IP address are allowed for that scope.

If you have an existing allowlists (meaning if Veriff set up an IP allowlist for your account in the past) it appears in Customer Portal and you can now manage it yourself.

Every change you make to either list is recorded in the Activity log in Customer Portal. If Veriff Support restores your access, those changes will not appear in your Activity log.

Supported entries

  • Single IPv4 addresses, for example 203.0.113.10

  • IPv4 ranges in CIDR notation, for example 203.0.113.0/24

  • Several entries at once: paste multiple entries, then click Save once

  • Ranges need to be /16 or smaller

Rejected entries

  • IPv6 addresses and ranges. IPv6 is not supported.

  • 0.0.0.0/0,  because they would allow all addresses.

  • Exact duplicates of an existing entry. Customer Portal shows message "Already in the list, adding it again would create a duplicate entry".

Overlapping ranges that are not exact duplicates are allowed, for example 203.0.113.0/24 and 203.0.113.0/28. Overlapping ranges are not automatically merged, meaning they will stay as separate entries, in the format you added them.

You can add up to 500 entries per list. You can upload up to 30 entries in one batch.


Set up an IP allowlist

  1. In Customer Portal, select IP allowlist in the left-hand panel.

  2. Select the tab for the list to edit: Station access or Public API access.

  3. Enter one or more IP addresses or CIDR ranges. You can copy-paste up to 30 values at a time.

  4. Click Save.

  5. Review the warning and confirm. See Warnings and confirmations.

Interface for adding IP addresses with instructions and confirmation checkbox displayed.

When a list has at least one entry, Customer Portal shows the status Allowlist enabled for it.

IP allowlist management interface showing allowed IP addresses and their addition dates.

If no entries in a list, the status is Open to all IP addresses.

Manage IP addresses for Veriff Station access and Public API settings.

To stop enforcing a list, delete all its entries. See Delete entries.


Warnings and confirmations

Customer Portal asks you to confirm the changes that can block access.

First entry in the Station access list

Saving the first entry turns on the block for Customer Portal. To help you avoid locking yourself out, the UI shows your current detected IP address and does not let you turn on the block unless that address is covered by an entry on the list.

Instructions for adding IP addresses and understanding access restrictions for Station access.

First entry in the Public API access list

Saving the first entry turns on the block for the Public API. After you save, API requests from IP addresses that are not on the list are denied. You need to type a confirmation before the change is saved.

Input fields for adding IP addresses for Public API access with warning message.

To help you avoid locking yourself out, the UI shows your current detected IP address and does not let you turn on the block unless that address is covered by an entry on the list. Note that this is just a warning, it will not prevent you from blocking your IP address.

Input field for adding IP addresses with a warning about current IP access.

Anyone who has been denied access due to restricted IP will see the following response:

{
    "status": "fail",
    "code": "1820",
    "message": "IP <IP> is not allowed to access the integration."
}

Batch upload limit reached

If you try to add more than 30 entries at the same time, the UI notifies you of reaching the batch upload limit.

Input field for adding multiple IP addresses with a limit warning message displayed.

Delete entries

When you delete an entry, the UI asks you to confirm, because the deleted IP addresses are denied access from then on.

Deleting the last entry allows all IP addresses

When you delete the last entry on a list, the list becomes empty and Veriff stops enforcing it: requests from any IP address are allowed again for that scope. This is the opposite of having one IP address on the list. the UI asks for a stronger confirmation: you need to type Remove before it deletes the last entry.

Remove a single range from the list

Warning message about removing an IP address and potential access loss.

Remove your own IP address from the list

Warning about potential IP address blocking when removing a specific IP from the list.

Remove the last IP address from the list, opening the access to everyone

Confirmation prompt to remove an IP address from the access list.


Lockout and recovery

You can lock yourself out of Customer Portal

The UI checks only your current IP address. It cannot know whether that address will stay the same. If your IP address changes after you turn on the Station access list, you may no longer be able to log in, and you cannot fix this yourself.

Common reasons your IP address can change:

  • Your internet provider assigns dynamic IP addresses.

  • Your internet provider's equipment restarts, for example overnight, and you get a new IP address.

  • You connect through a VPN or a proxy, or you switch between them.

If you are locked out of the Customer Portal, contact Veriff Technical Support to restore access. To contact support, use the Support chat bubble inside the Veriff Customer Portal, or send an email to support@veriff.com.

If only the Public API access list blocks you, for example because your server's IP address changed, you can still log in to the Customer Portal and update the Public API access list, as long as the Station access list allows your current IP address.


Best practices

  • Check your egress IP addresses before you turn on a list. Confirm with your network or IT team which public IP addresses your offices, VPN, and servers use.

  • Prefer CIDR ranges over single dynamic IP addresses. A range assigned to your organisation survives address changes better than one address.

  • Keep at least one reliable static IP address or range on each list, so that a change to a dynamic address does not lock you out.

  • Before you delete the last entry on a list, remember that the list then allows all IP addresses.

  • Review the Activity Log regularly to see who changed the lists and when.


Changelog

Date

Description

Oct 7, 2026

Documentation published