By default, Kolleno's Open API accepts a valid API key from anywhere. If your security policy needs more than that, we can restrict your Open API to a list of IP addresses you nominate. A request that carries a valid key but comes from any other address is then rejected before it reaches your data.
This is off unless you ask for it, and we set it up for you.
What it covers
The whole Open API for your company: every endpoint, and every API key your team owns.
Your company instance only. Other companies are unaffected, including ones your users also have access to.
It does not affect the Kolleno app, the customer portal, or your ERP integrations. Only the Open API.
Ask us to turn it on
Email support@kolleno.com with the addresses your integration calls Kolleno from. We accept any number of:
a single address, for example 203.0.113.9
a range in CIDR notation, for example 203.0.113.0/24
đ Send the public address your traffic leaves from, which is usually your NAT gateway or egress IP, not an internal one such as 10.0.0.5. If you are not certain, your network team or cloud provider can confirm it.
We add your addresses first and switch the restriction on afterwards, so there is no window where your integration is locked out.
What changes once it is on
From an allowed address: nothing changes. Same keys, same permissions, same responses.
From any other address: the call is refused with a 403 response and the message "Requests to this API are not permitted from this IP address."
The company list endpoint returns your company only when you call from an allowed address.
Keep the list current
If the address your integration calls from changes, calls start failing straight away. That usually happens when you:
move the integration to a different server, region or cloud account
add a NAT gateway, or change an existing one
start routing traffic through a new VPN or proxy
Tell us before you make the change. We add the new address alongside the old one, then remove the old one once your cutover is finished, so nothing breaks in between.
Troubleshooting
What you see | What it usually means |
Every call suddenly refused | The address you call from has changed. Check it and send us the new one. |
Only some calls refused | You call from more than one address and only some are listed. Send us the full set, or a range that covers them. |
A refusal saying "Authentication credentials were not provided" | A key problem rather than an address problem. See Create an API key for Open API access. |
