An IP allowlist restricts who can reach your Veriff integration by IP address. You can set up two independent allowlists in the Veriff Customer Portal: one for access to Customer Portal itself (referred to as “Station access” in the UI), and one for access to the Veriff Public API. When a list is active, only requests from the IP addresses and ranges on that list are allowed.
This article is about restricting inbound access to your Veriff account from your own IP addresses. If you need the list of Veriff's URLs and IP addresses to allow in your own firewall, see Allowlisted URLs and IP addresses.
Prerequisites
An Enterprise plan with Veriff.
The "Manage IP access allowlist" permission in Customer Portal. By default:
Under Advanced permissions, the Owner team has it.
Under Basic permissions, the Administrator group has it.
If you do not have this permission, ask a user who can manage roles to grant it. See Changing user roles in Veriff Station in Knowledge base (you need to log in to Veriff Customer Portal to access the article).
The public (egress) IP addresses or ranges that your team and your servers use to connect to Veriff.
How IP allowlists work
The Station access (aka access to the Veriff Customer Portal) list and the Public API access list behave as two separate lists. Each list can hold different IP addresses and ranges, and each one is enforced on its own.
The Public API access list applies to API requests from your own systems. It does not apply to requests made from your end-users' devices, such as the web flow or mobile SDKs, so restricting the Public API to your server IPs does not block your end-users.
An empty list allows all requests, meaning that the list is enforced only when it has at least one entry. While a list is empty, requests from any IP address are allowed for that scope.
If you have an existing allowlists (meaning if Veriff set up an IP allowlist for your account in the past) it appears in Customer Portal and you can now manage it yourself.
Every change you make to either list is recorded in the Activity log in Customer Portal. If Veriff Support restores your access, those changes will not appear in your Activity log.
Supported entries
Single IPv4 addresses, for example
203.0.113.10IPv4 ranges in CIDR notation, for example
203.0.113.0/24Several entries at once: paste multiple entries, then click Save once
Ranges need to be /16 or smaller
Rejected entries
IPv6 addresses and ranges. IPv6 is not supported.
0.0.0.0/0, because they would allow all addresses.Exact duplicates of an existing entry. Customer Portal shows message "Already in the list, adding it again would create a duplicate entry".
Overlapping ranges that are not exact duplicates are allowed, for example 203.0.113.0/24 and 203.0.113.0/28. Overlapping ranges are not automatically merged, meaning they will stay as separate entries, in the format you added them.
You can add up to 500 entries per list. You can upload up to 30 entries in one batch.
Set up an IP allowlist
In Customer Portal, select IP allowlist in the left-hand panel.
Select the tab for the list to edit: Station access or Public API access.
Enter one or more IP addresses or CIDR ranges. You can copy-paste up to 30 values at a time.
Click Save.
Review the warning and confirm. See Warnings and confirmations.

When a list has at least one entry, Customer Portal shows the status Allowlist enabled for it.

If no entries in a list, the status is Open to all IP addresses.

To stop enforcing a list, delete all its entries. See Delete entries.
Warnings and confirmations
Customer Portal asks you to confirm the changes that can block access.
First entry in the Station access list
Saving the first entry turns on the block for Customer Portal. To help you avoid locking yourself out, the UI shows your current detected IP address and does not let you turn on the block unless that address is covered by an entry on the list.

First entry in the Public API access list
Saving the first entry turns on the block for the Public API. After you save, API requests from IP addresses that are not on the list are denied. You need to type a confirmation before the change is saved.

To help you avoid locking yourself out, the UI shows your current detected IP address and does not let you turn on the block unless that address is covered by an entry on the list. Note that this is just a warning, it will not prevent you from blocking your IP address.

Anyone who has been denied access due to restricted IP will see the following response:
{
"status": "fail",
"code": "1820",
"message": "IP <IP> is not allowed to access the integration."
}
Batch upload limit reached
If you try to add more than 30 entries at the same time, the UI notifies you of reaching the batch upload limit.

Delete entries
When you delete an entry, the UI asks you to confirm, because the deleted IP addresses are denied access from then on.
Deleting the last entry allows all IP addresses
When you delete the last entry on a list, the list becomes empty and Veriff stops enforcing it: requests from any IP address are allowed again for that scope. This is the opposite of having one IP address on the list. the UI asks for a stronger confirmation: you need to type Remove before it deletes the last entry.
Remove a single range from the list

Remove your own IP address from the list

Remove the last IP address from the list, opening the access to everyone

Lockout and recovery
You can lock yourself out of Customer Portal
The UI checks only your current IP address. It cannot know whether that address will stay the same. If your IP address changes after you turn on the Station access list, you may no longer be able to log in, and you cannot fix this yourself.
Common reasons your IP address can change:
Your internet provider assigns dynamic IP addresses.
Your internet provider's equipment restarts, for example overnight, and you get a new IP address.
You connect through a VPN or a proxy, or you switch between them.
If you are locked out of the Customer Portal, contact Veriff Technical Support to restore access. To contact support, use the Support chat bubble inside the Veriff Customer Portal, or send an email to support@veriff.com.
If only the Public API access list blocks you, for example because your server's IP address changed, you can still log in to the Customer Portal and update the Public API access list, as long as the Station access list allows your current IP address.
Best practices
Check your egress IP addresses before you turn on a list. Confirm with your network or IT team which public IP addresses your offices, VPN, and servers use.
Prefer CIDR ranges over single dynamic IP addresses. A range assigned to your organisation survives address changes better than one address.
Keep at least one reliable static IP address or range on each list, so that a change to a dynamic address does not lock you out.
Before you delete the last entry on a list, remember that the list then allows all IP addresses.
Review the Activity Log regularly to see who changed the lists and when.
Changelog
Date | Description |
|---|---|
Oct 7, 2026 | Documentation published |