Use IP allowlisting to restrict access to your Vibranium Labs organization to trusted networks only. When it is enabled, requests must come from one of the IP addresses or CIDR ranges listed in your security settings.

<aside>

IP allowlisting takes effect as soon as you save it while enabled. Before turning it on, make sure the network you are currently using is included in the allowlist.

</aside>

What IP Allowlisting Does

IP allowlisting adds an organization-wide network access control. If a request comes from an allowed IP address or range, Vibranium Labs continues handling it normally. If the request comes from another network, access is blocked.

Use this when your organization wants Vibranium Labs access to come only from known locations, such as an office network, company VPN, NAT gateway, or other trusted egress point.

What Is Restricted

When IP allowlisting is enabled, it applies to:

What Is Not Restricted

IP allowlisting does not apply to every inbound request. These routes remain available so external systems can continue sending events to Vibranium Labs:

Verified mobile app access is also exempt. From version 1.15.0, the Vibe OnCall mobile app proves that it is a genuine, unmodified build running on an uncompromised device, using Apple App Attest on iOS and Google Play Integrity on Android. Sessions from a verified app are exempt from IP allowlisting.

This is deliberate. On-call responders are paged at any hour and from any network — home Wi-Fi, mobile data, an airport — and requiring a VPN before someone can acknowledge a page delays incident response. The exemption is granted per session and only after the device passes verification, so it is not a general exemption for mobile traffic. It currently cannot be turned off for an individual organization.