IP allowlist
The IP allowlist restricts your JupiterOne account to a set of source IP addresses that you define. Once enabled, requests coming from any other address are rejected.
The allowlist applies to the whole account, not to individual users or groups. It is configured by account admins in Settings > Admin > Security & Access.
The allowlist is an access control, not a network boundary. It does not make JupiterOne unreachable from other addresses — it means requests from those addresses are refused.
What the allowlist blocks
When the allowlist is enabled, JupiterOne checks the source IP of every authenticated request against your entries and rejects anything that does not match. This covers:
- Web app usage. Every action a user takes in the JupiterOne app.
- API and SDK traffic. Anything authenticated with a JupiterOne API token, including the CLI, the SDK, custom scripts, and CI jobs.
- Integrations you run yourself. Any collector or job that authenticates to JupiterOne with an account or user API token from your own infrastructure.
Blocked requests fail with a permission error. They are not treated as authentication failures, so a blocked user is not prompted to log in again.
What the allowlist does not block
Signing in. A user connecting from a non-allowed address can still authenticate, but no action they take afterward will succeed. Expect this to look like a working login followed by an app that cannot load anything.
The allowlist governs requests made against your account with your users' sessions and your API tokens. It is a restriction on where your account can be used from, not a replacement for the rest of your access controls — keep managing token lifetimes, user offboarding, and group permissions as you would without it.
If you are assessing the allowlist as part of a security review and need its exact coverage boundary, contact your JupiterOne account team or support rather than relying on this page.
JupiterOne staff are subject to your allowlist too. Support engineers cannot access your account from outside your allowed addresses. See If you get locked out for what this means for support requests.
Configure the allowlist
- Click Settings (the gear icon) and select Admin.
- Open Security & Access and find the IP allowlist section.
- Enable the allowlist and add your entries. You can add them one at a time, or paste many at once with Bulk add (see Add entries in bulk). For each entry, provide:
- Address or range — a single IPv4 or IPv6 address, or a CIDR block of either family. For example
203.0.113.42,203.0.113.0/24,2001:db8::1, or2001:db8::/48. - Label — a short description of what the entry covers, such as
HQ office egressorChicago VPN. Labels are up to 64 characters.
- Address or range — a single IPv4 or IPv6 address, or a CIDR block of either family. For example
- Save your changes.
An account can hold up to 500 entries, and malformed addresses are rejected as you type them. An enabled allowlist with no entries is not a valid configuration and will not save.
Add entries in bulk
To add many entries at once, click Bulk add next to Add CIDR. This opens the Bulk add CIDR ranges dialog with a box to paste into.
Paste one entry per line, as <cidr>, <label>. The label is optional — a line with no comma is a CIDR with no label. Only the first comma separates the two fields, so a label may itself contain commas: 10.0.0.0/24, Frankfurt, DE adds the range 10.0.0.0/24 with the label Frankfurt, DE. Blank lines are ignored, so a list pasted out of a spreadsheet or with a trailing newline causes no error.
Each line is checked as you type and marked with one of three outcomes:
- To add — a valid new range that will be added.
- Invalid — a malformed entry, shown with the same message the inline field gives.
- Duplicate — a range already in the list, or one that appears on an earlier line in the same paste.
A running summary above the list reads N to add · N invalid · N duplicate. Duplicates are matched on the normalized address, so 2001:DB8::/48 and 2001:db8::/48 are the same range, and a bare 10.0.0.1 is the same range as 10.0.0.1/32.
Only the addable lines are committed. The confirm button names the count — for example Add 3 ranges — and is disabled when nothing is addable. Invalid and duplicate lines are reported, never silently added.
A paste that would exceed the 500-entry limit is refused whole, not truncated. The dialog tells you how many slots remain and how many lines to remove, and nothing is added until you bring the paste within that limit.
Added ranges become ordinary rows — you can edit or remove each one individually, and they are saved by the same Save changes button and typed confirmation as the rest of the section.
Verify your own address first
The section displays the source IP JupiterOne sees for your current request. This is the value that will actually be compared against your entries, and it is not necessarily the address your machine reports for itself — traffic through a VPN, a corporate proxy, or NAT arrives from the egress address of that hop.
Use the displayed value as your reference when you build the list. If you are unsure what a location's egress range is, get it from whoever manages that network rather than guessing.
Confirming a save
Some saves ask you to type your account short name before they apply. The confirmation shows your proposed entries next to the source IP JupiterOne sees for you, so you can check your own access before committing. You are asked to confirm when:
- You turn the allowlist on. Enforcement affects everyone in the account, so this is confirmed even when your own address is covered.
- Your source IP falls outside the entries you are saving. The confirmation warns you explicitly that you are about to lose access.
Other saves apply without the extra step: turning the allowlist off, and editing an already-enabled list in a way that still covers your own address.
You cannot save an enabled allowlist while JupiterOne is unable to determine the address you are connecting from. Without that value there is no way to tell whether your entries cover you.
Avoid locking yourself out
Saving a list that does not include your own address locks out the person best placed to undo it. Before you save:
- Confirm your entries cover the source IP shown in the section.
- Add every egress range your users actually come from — each office, each VPN concentrator, each cloud NAT gateway — not just your own.
- Include the egress addresses of any automation that authenticates with a JupiterOne API token. A CI runner or a self-hosted collector that falls outside the list stops working as soon as enforcement begins.
- Remember that ranges change. Consumer ISPs, cellular networks, and CGNAT pools reassign addresses; a home address that works today may not tomorrow. Prefer stable egress points.
This check matters most right after a bulk paste. When you add a long list at once it is easy to stop reading each entry, but the save confirmation still shows your proposed entries against the source IP JupiterOne sees for you. Read that confirmation and make sure your own address is covered before you save, whether the list was pasted or built by hand.
Removing an entry or turning the allowlist off
Editing entries and disabling the allowlist are both done from the same section. Turning the allowlist off leaves your entries in place, so you can re-enable the same list later without re-entering it.
When changes take effect
Allowlist changes apply immediately in most cases, but some can take a few minutes to propagate.
Allow for that when you widen the list or re-enable enforcement: access you have just granted may take a few minutes to work. If you need a change to take effect immediately, contact support.
If you get locked out
Raise a request through your normal JupiterOne support channel, as an account administrator. Support can pause enforcement on your account, which restores access without touching your entries — your addresses and labels are preserved exactly as you saved them.
Two things to know about the recovery path:
- While enforcement is paused, your account is not IP-restricted. Correct your entries and re-enable enforcement promptly rather than leaving the pause in place.
- Only you can turn it back on. Support cannot re-enable enforcement or edit your entries. Once you have access again, fix the list in Security & Access and enable the allowlist yourself.
After you re-enable it, allow a few minutes for the change to propagate before concluding that something is wrong.
Limitations
- Not compatible with AWS PrivateLink. If your account reaches JupiterOne over PrivateLink, do not enable an IP allowlist — PrivateLink already restricts network access, and combining the two will break your connectivity. Contact your JupiterOne representative if you are unsure whether this applies to you.
- Up to 500 entries per account, with labels up to 64 characters.
- Account-wide only. The allowlist cannot be scoped to a user group, a role, or a specific API token.