Security Settings
Find risky API keys, clean up unused ones, and restrict API keys to a list of trusted IP addresses.
Security settings
The Security page in the dashboard (anyrouter.dev/dashboard/security) helps you keep API keys safe. It has three tabs: Overview, Key safety, and IP allowlist.
Overview
Four cards count the active API keys in your workspace that need attention. Click a card to open Key safety with that filter applied.
| Card | What it counts |
|---|---|
| No spend limit | Keys without a spend limit. A leaked key can spend your whole balance. |
| Never expires | Keys without an expiry date. |
| Never used or idle | Keys that were never used, or not used for 90 days or more. |
| Safe to remove | Keys idle for 90+ days that spent less than $1 in their lifetime. |
Below the cards is a short list of recommended next steps. Workspace owners and organization admins can Copy CSV of every active key with its owner, to share with key holders.
Key safety
Key safety lists active sk-ar-v1 keys (disabled, expired and archived keys are not shown). Turn on Management keys to include your management API keys too.
Filter by:
- Search — key name; owners and admins can also search by owner
- Risk — No limit, or No expiry
- Inactivity — idle 30, 60, 90 or 180+ days, never used, or either (never used or idle 90+ days)
- Owner — owners and admins only
- Safe to remove
The Risk column flags missing safeguards: no spend limit, a spend limit of $1,000 or more, no expiry, or an expiry more than 365 days away. A key with more than one flag is marked in red.
The Status column tells you what to do with a key:
| Status | Meaning |
|---|---|
| Safe to remove | Idle 90+ days and spent less than $1. |
| Review | Idle 90+ days, but it carried real traffic. Check before removing. |
| In use | Used in the last 90 days, or created recently. |
Actions
Owners and admins can act on each key:
- Set limit — add or change the key's spend limit.
- Disable — stops the key, usually within seconds and always within about a minute. You can enable it again later from API keys.
- Archive — permanently removes the key. Type
archiveto confirm. This cannot be undone.
To retire a key that never expires, rotate it rather than extending its life:
- Create a new key with an expiry date (and a spend limit).
- Move every app that uses the old key to the new one.
- Disable the old key, then archive it once nothing breaks.
A fresh key also limits the damage if the old one was ever copied somewhere you don't know about.
IP allowlist
The IP allowlist limits which IP addresses can use your workspace's API keys. It is available on Pro and above.
- Add IPv4 addresses (
203.0.113.7), IPv6 addresses (2001:db8::1), or CIDR ranges (203.0.113.0/24,2001:db8::/32), each with an optional label. - An empty list allows every IP.
- Once the list has at least one entry, every request made with an
sk-ar-v1key in the workspace must come from a listed IP. Requests from any other IP are rejected. - Changes apply to all keys in the workspace, usually within seconds and always within about a minute.
- The dashboard itself is not affected — you can always sign in and edit the list.
- Workspace owners and organization admins can edit the list. Organization members can view it.
- You can remove entries on any plan, so the list never locks you out after a plan change.
A blocked request returns 403:
{
"error": {
"message": "Requests from IP 198.51.100.4 are not allowed for this workspace. Add it to the IP allowlist in Security settings.",
"type": "permission_error",
"code": "ip_not_allowed"
}
}Add every address your apps call from — servers, CI runners, office networks — before you rely on the list. Use Add my IP to add the address you are browsing from.
Manage the allowlist with the API
With a management key that has the read:security or write:security scope:
# List entries
curl https://anyrouter.dev/api/v1/security/ip-allowlist \
-H "Authorization: Bearer $ANYROUTER_MANAGEMENT_KEY"
# Add an entry
curl -X POST https://anyrouter.dev/api/v1/security/ip-allowlist \
-H "Authorization: Bearer $ANYROUTER_MANAGEMENT_KEY" \
-H "Content-Type: application/json" \
-d '{"cidr": "203.0.113.0/24", "label": "Office"}'
# Remove an entry
curl -X DELETE https://anyrouter.dev/api/v1/security/ip-allowlist/<id> \
-H "Authorization: Bearer $ANYROUTER_MANAGEMENT_KEY"GET /api/v1/security/keys returns the active keys shown on the Key safety tab.
Provider Routing
Route requests across upstream providers. Customize ordering, sorting, fallbacks, performance thresholds, data policies, and pricing budgets per request.
Sign in with AnyRouter
Let users sign in to your app with their AnyRouter account and run AI requests billed to them — no API keys to collect or store.