> ## Documentation Index
> Fetch the complete documentation index at: https://oximy.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Restrict provider access by source IP

> Allow model-provider traffic only from the IP addresses shown in Oximy.

Some model providers let you restrict an API key or resource so it accepts requests only from an approved list of source IP addresses.

When this option is available, traffic to the provider will originate from the IP addresses displayed in Oximy. Open **Models → Providers → Add provider**, choose the provider, then expand **Restrict access by IP** and copy the current list.

<Warning>
  Allow every displayed address. Verification and live model requests may otherwise have different results.
</Warning>

## Configure a provider allowlist

<Steps>
  <Step title="Copy the current addresses">
    In the provider setup guide, select **Copy all**. The copied value contains one address per line, formatted for the selected provider. Paste the addresses exactly as displayed.
  </Step>

  <Step title="Add every address to the provider">
    Follow the linked provider instructions and add the complete list to its source-IP allowlist or firewall rules.
  </Step>

  <Step title="Verify before enforcing default deny">
    Save the provider connection in Oximy and select **Check now**. Confirm it reaches **Working** before removing broader network access.
  </Step>
</Steps>

## Address rotation

During a planned rotation, Oximy may temporarily display additional addresses. Add the new addresses while retaining the old ones, verify the provider connection, and remove old addresses only after Oximy no longer displays them.

If verification reports **Network blocked**, keep the credential stored, compare the provider allowlist with the current Oximy list, add any missing addresses, and check again.
