AnyRouter
Guides

Security Settings

Find risky API keys, clean up unused ones, and restrict API keys to a list of trusted IP addresses.

Security settings

The Security page in the dashboard (anyrouter.dev/dashboard/security) helps you keep API keys safe. It has three tabs: Overview, Key safety, and IP allowlist.

Overview

Four cards count the active API keys in your workspace that need attention. Click a card to open Key safety with that filter applied.

CardWhat it counts
No spend limitKeys without a spend limit. A leaked key can spend your whole balance.
Never expiresKeys without an expiry date.
Never used or idleKeys that were never used, or not used for 90 days or more.
Safe to removeKeys idle for 90+ days that spent less than $1 in their lifetime.

Below the cards is a short list of recommended next steps. Workspace owners and organization admins can Copy CSV of every active key with its owner, to share with key holders.

Key safety

Key safety lists active sk-ar-v1 keys (disabled, expired and archived keys are not shown). Turn on Management keys to include your management API keys too.

Filter by:

  • Search — key name; owners and admins can also search by owner
  • Risk — No limit, or No expiry
  • Inactivity — idle 30, 60, 90 or 180+ days, never used, or either (never used or idle 90+ days)
  • Owner — owners and admins only
  • Safe to remove

The Risk column flags missing safeguards: no spend limit, a spend limit of $1,000 or more, no expiry, or an expiry more than 365 days away. A key with more than one flag is marked in red.

The Status column tells you what to do with a key:

StatusMeaning
Safe to removeIdle 90+ days and spent less than $1.
ReviewIdle 90+ days, but it carried real traffic. Check before removing.
In useUsed in the last 90 days, or created recently.

Actions

Owners and admins can act on each key:

  • Set limit — add or change the key's spend limit.
  • Disable — stops the key, usually within seconds and always within about a minute. You can enable it again later from API keys.
  • Archive — permanently removes the key. Type archive to confirm. This cannot be undone.

To retire a key that never expires, rotate it rather than extending its life:

  1. Create a new key with an expiry date (and a spend limit).
  2. Move every app that uses the old key to the new one.
  3. Disable the old key, then archive it once nothing breaks.

A fresh key also limits the damage if the old one was ever copied somewhere you don't know about.

IP allowlist

The IP allowlist limits which IP addresses can use your workspace's API keys. It is available on Pro and above.

  • Add IPv4 addresses (203.0.113.7), IPv6 addresses (2001:db8::1), or CIDR ranges (203.0.113.0/24, 2001:db8::/32), each with an optional label.
  • An empty list allows every IP.
  • Once the list has at least one entry, every request made with an sk-ar-v1 key in the workspace must come from a listed IP. Requests from any other IP are rejected.
  • Changes apply to all keys in the workspace, usually within seconds and always within about a minute.
  • The dashboard itself is not affected — you can always sign in and edit the list.
  • Workspace owners and organization admins can edit the list. Organization members can view it.
  • You can remove entries on any plan, so the list never locks you out after a plan change.

A blocked request returns 403:

{
  "error": {
    "message": "Requests from IP 198.51.100.4 are not allowed for this workspace. Add it to the IP allowlist in Security settings.",
    "type": "permission_error",
    "code": "ip_not_allowed"
  }
}

Add every address your apps call from — servers, CI runners, office networks — before you rely on the list. Use Add my IP to add the address you are browsing from.

Manage the allowlist with the API

With a management key that has the read:security or write:security scope:

# List entries
curl https://anyrouter.dev/api/v1/security/ip-allowlist \
  -H "Authorization: Bearer $ANYROUTER_MANAGEMENT_KEY"

# Add an entry
curl -X POST https://anyrouter.dev/api/v1/security/ip-allowlist \
  -H "Authorization: Bearer $ANYROUTER_MANAGEMENT_KEY" \
  -H "Content-Type: application/json" \
  -d '{"cidr": "203.0.113.0/24", "label": "Office"}'

# Remove an entry
curl -X DELETE https://anyrouter.dev/api/v1/security/ip-allowlist/<id> \
  -H "Authorization: Bearer $ANYROUTER_MANAGEMENT_KEY"

GET /api/v1/security/keys returns the active keys shown on the Key safety tab.

On this page