403 Forbidden.
Enabling IP Allowlisting
IP allowlisting is managed via Guard policies or directly in Guard → Settings → IP Allowlist in the dashboard.Via API
Listing Allowlist Rules
Updating a Rule
Removing a Rule
Scope
IP allowlisting applies to all API requests workspace-wide, including requests from integrations and SDK clients. It does not apply to the SSO login flow — IdP redirects are always permitted.Temporary Bypass
You can temporarily exempt a specific API key from IP allowlisting (e.g. for emergency access from an unlisted IP):guard.ip_allowlist.bypassed action.
All allowlist changes and bypass events are recorded in the Guard audit log and can trigger alert rules if configured.