Get a credential's IP allowlist
Returns the IP allowlist enforced for this credential and the pending change, if any, still inside its grace window.
Authentication
AuthorizationBearer
Bearer authentication of the form Bearer <token>, where token is your auth token.
Path parameters
tenantId
Tenant identifier (same value as X-Tenant-Id).
clientId
Credential (client_id) the subresource belongs to.
Headers
X-Tenant-Id
Tenant context used for authorization and routing.
X-Request-Timestamp
Unix seconds. Required on the signed host; tolerance is 300s either way (403 request_timestamp_skew).
X-Content-SHA256
Lowercase hex SHA-256 of the body. An empty body hashes the empty string, so the header is always present. Mismatch returns 400 body_hash_mismatch.
X-Request-Signature
Detached JWS (<protected>..<signature>, ES256 or PS256) over METHOD\nPATH?QUERY\nTIMESTAMP\nIDEMPOTENCY_KEY_OR_EMPTY\nX_CONTENT_SHA256.
Response
Effective and pending allowlists.
clientId
ips
The set in force right now.
pendingIps
Complete set that takes over at pendingUntil (additions wait 18h).
pendingUntil
Errors
403
Forbidden Error
404
Not Found Error