Finer controls for IP Address Allowlist

There were recent changes to the IP Address Allowlist configuration that caused API integrations to fail.

Currently, there is a single switch in the Admin settings for configuring the allowlist. If it's set to ON then the IP Address Allowlist applies to Mobile, Workbench, and API Clients.

While this security feature is nice, it would beneficial to have each form of access controllable so that we could customize the IP Address Allowlist settings for API Clients. As an example, if an API integration involves spinning up resources with dynamic external IP addresses, then there would be no way to know which IP Address Allowlist to use. For example, see Salesforce's Hyperforce External IP Address policy: https://compliance.salesforce.com/en/documents/a006e0000121zduAAA

It would be nice to be able to choose if we want to enable/disable the IP Address Allowlist specifically for API Clients. Even better would be able to specify which API Clients are allowed to access the data from which IP Addresses. For example, perhaps an integration with Salesforce does not have restricted access but an integration with an external customer has an IP Address allowed that is different from an internal VPN IP address.

Tagged:
1
1 votes