September 28, 2026
SaaSKit

IP allowlisting for client credentials: only your network can request tokens

You can now restrict which IP ranges can request and use tokens with an application's client credentials, so a leaked client secret cannot be used from outside your network.

Client credentials are what your backend uses to get tokens from Scalekit. Until now, anyone holding a client ID and secret could request tokens with them from anywhere until the secret was rotated. Security reviews regularly ask whether that access can be limited to known networks.

You can now add an IP allowlist to an application's client credentials. Scalekit issues and accepts tokens for that client only when the request comes from an IP range you have approved, such as your VPC's egress addresses or your CI runners. Requests from anywhere else are refused, so a leaked secret cannot be used from outside your network.

How it works

  • Open the application in the Scalekit dashboard and add approved IP ranges in CIDR notation.
  • Token requests using that client's credentials from addresses outside the allowlist are rejected.
  • The allowlist applies to environment and web application clients.
  • IP allowlisting is enabled per account.

Talk to us to turn on IP allowlisting for your environment.

Share on

IP allowlisting for client credentials: only your network can request tokens

—

Client credentials are what your backend uses to get tokens from Scalekit. Until now, anyone holding a client ID and secret could request tokens with them from anywhere until the secret was rotated. Security reviews regularly ask whether that access can be limited to known networks.

You can now add an IP allowlist to an application's client credentials. Scalekit issues and accepts tokens for that client only when the request comes from an IP range you have approved, such as your VPC's egress addresses or your CI runners. Requests from anywhere else are refused, so a leaked secret cannot be used from outside your network.

How it works

  • Open the application in the Scalekit dashboard and add approved IP ranges in CIDR notation.
  • Token requests using that client's credentials from addresses outside the allowlist are rejected.
  • The allowlist applies to environment and web application clients.
  • IP allowlisting is enabled per account.

Talk to us to turn on IP allowlisting for your environment.

Schedule a demo with Scalekit today.