Skip to main content

IP Allowlisting

IP Allowlisting lets Admins restrict platform access to specific IP ranges. You can restrict interactive sign-in for all users, restrict external MCP client connections, and separately restrict individual API keys or Agents to their own IP ranges.

Restricting Sign-In​

You can require that users sign in and interact with the platform only from approved IP ranges. The IP Allowlist field is read-only until you select its edit icon, so an existing list can't be changed by accident.

  1. Navigate to Settings and select Security.
  2. Select the edit icon next to the IP Allowlist field.
  3. Enter one CIDR range per line (for example, 203.0.113.0/24 or 198.51.100.42/32).
  4. Turn on Enable IP allowlist.

When enabled, anyone signing in from outside the listed ranges is blocked, and any user already signed in is signed out the next time they interact with the platform.

IP Allowlist field, read-only with an edit icon

Updating an Existing List

To change the list without changing whether it's enforced, select the edit icon, make your changes, then select Save Changes.

Live Enforcement

IP restrictions are checked continuously, not just at sign-in. If you remove a range while a user is actively using the platform from that range, they are signed out on their very next action — you do not need to wait for their session to expire. The same applies to the ranges assigned to API keys and Agents, and to MCP client connections: changes take effect on the next request made with that credential or client.

Restricting MCP Access​

Separately from sign-in, you can restrict external MCP clients (such as Claude Desktop or Cursor) to specific IP ranges. This does not affect the Vera AI chat experience.

  1. Navigate to Settings and select MCP.
  2. Select the Access tab.
  3. Under Restrict MCP Access by IP, enter one CIDR range per line (for example, 203.0.113.0/24 or 198.51.100.42/32).
  4. Turn on Restrict MCP Access by IP.
  5. Select Save Changes.

Restrict MCP Access by IP card with a configured CIDR range

When enabled, external MCP client connections from outside the listed ranges are denied on their next request. The CIDR list can be edited at any time regardless of whether the restriction is currently on or off.

Named Ranges for API Keys and Agents​

Separately from the sign-in allowlist, you can maintain a catalog of named IP ranges and assign them to individual API Keys or Agents. This lets you restrict a specific machine credential to its own IP range without affecting interactive sign-in for your users. Adding or removing a range takes effect immediately — there's no separate save step for this catalog.

  1. Navigate to Settings and select Security.
  2. Under Machine Access Ranges, enter a Name and CIDR Range for the range.
  3. Select Add.

Machine Access Ranges catalog with a named range and Add fields

To remove a range, select its trash icon. A named range must be removed from every API key and Agent it's assigned to before you can delete it.

Restricting an API Key​

You can restrict an existing API key to specific IP ranges from its settings.

  1. Navigate to Settings and select API Keys.
  2. Select the API key you want to restrict.
  3. Turn on Restrict this key to specific IP ranges.
  4. Select one or more ranges from the list.
  5. Select Save Changes.

API Key drawer with Machine Access Ranges checkbox and assigned range

This option is unavailable until at least one named range exists under Machine Access Ranges. Once you turn it on, you must select at least one range — otherwise the key won't save.

Restricting an Agent​

You can restrict an Agent's key to specific IP ranges when you create the Agent, or at any time afterward.

When creating a new Agent:

  1. Navigate to Agents and select Add New Agent.
  2. Enter a name and select an Agent Type.
  3. Turn on Restrict to specific IP ranges.
  4. Select one or more ranges from the list.
  5. Select Add New Agent.

Add New Agent window with the Restrict to specific IP ranges checkbox

On an existing Agent:

  1. Navigate to Agents and select the Agent you want to restrict.
  2. In the Details panel, turn on Restrict to specific IP ranges.
  3. Select one or more ranges from the list.
  4. Select Save Changes.

As with API keys, this option is unavailable until at least one named range exists under Machine Access Ranges, and you must select at least one range before the Agent will save.

 

Need help?
If you have any questions, please reach out to your dedicated Account Manager or contact us at support@datagrail.io.

Disclaimer: The information contained in this message does not constitute as legal advice. We would advise seeking professional counsel before acting on or interpreting any material.