# Security Settings

> Find risky API keys, clean up unused ones, and restrict API keys to a list of trusted IP addresses.


# Security settings

The **Security** page in the dashboard ([dash.anyrouter.dev/security](https://dash.anyrouter.dev/security)) helps you keep API keys safe. It has three tabs: **Overview**, **Key safety**, and **IP allowlist**.

## Overview

Four cards count the active API keys in your workspace that need attention. Click a card to open **Key safety** with that filter applied.

| Card | What it counts |
|---|---|
| **No spend limit** | Keys without a spend limit. A leaked key can spend your whole balance. |
| **Never expires** | Keys without an expiry date. |
| **Never used or idle** | Keys that were never used, or not used for 90 days or more. |
| **Safe to remove** | Keys idle for 90+ days that spent less than $1 in their lifetime. |

Below the cards is a short list of recommended next steps. Workspace owners and organization admins can **Copy CSV** of every active key with its owner, to share with key holders.

## Key safety

Key safety lists active `sk-ar-v1` keys (disabled, expired and archived keys are not shown). Turn on **Management keys** to include your management API keys too.

Filter by:

- **Search** — key name; owners and admins can also search by owner
- **Risk** — No limit, or No expiry
- **Inactivity** — idle 30, 60, 90 or 180+ days, never used, or either (never used or idle 90+ days)
- **Owner** — owners and admins only
- **Safe to remove**

The **Risk** column flags missing safeguards: no spend limit, a spend limit of $1,000 or more, no expiry, or an expiry more than 365 days away. A key with more than one flag is marked in red.

The **Status** column tells you what to do with a key:

| Status | Meaning |
|---|---|
| **Safe to remove** | Idle 90+ days and spent less than $1. |
| **Review** | Idle 90+ days, but it carried real traffic. Check before removing. |
| **In use** | Used in the last 90 days, or created recently. |

### Actions

Owners and admins can act on each key:

- **Set limit** — add or change the key's spend limit.
- **Disable** — stops the key, usually within seconds and always within about a minute. You can enable it again later from **API keys**.
- **Archive** — permanently removes the key. Type `archive` to confirm. This cannot be undone.

To retire a key that never expires, rotate it rather than extending its life:

1. Create a new key with an expiry date (and a spend limit).
2. Move every app that uses the old key to the new one.
3. Disable the old key, then archive it once nothing breaks.

A fresh key also limits the damage if the old one was ever copied somewhere you don't know about.

## IP allowlist

The IP allowlist limits which IP addresses can use your workspace's API keys. It is available on **Pro and above**.

- Add IPv4 addresses (`203.0.113.7`), IPv6 addresses (`2001:db8::1`), or CIDR ranges (`203.0.113.0/24`, `2001:db8::/32`), each with an optional label.
- **An empty list allows every IP.**
- Once the list has at least one entry, every request made with an `sk-ar-v1` key in the workspace must come from a listed IP. Requests from any other IP are rejected.
- Changes apply to all keys in the workspace, usually within seconds and always within about a minute.
- The dashboard itself is not affected — you can always sign in and edit the list.
- Workspace owners and organization admins can edit the list. Organization members can view it.
- You can remove entries on any plan, so the list never locks you out after a plan change.

A blocked request returns `403`:

```json
{
  "error": {
    "message": "Requests from IP 198.51.100.4 are not allowed for this workspace. Add it to the IP allowlist in Security settings.",
    "type": "permission_error",
    "code": "ip_not_allowed"
  }
}
```

Add every address your apps call from — servers, CI runners, office networks — before you rely on the list. Use **Add my IP** to add the address you are browsing from.

### Manage the allowlist with the API

With a [management key](/api-reference/management-keys) that has the `read:security` or `write:security` scope:

```bash
# List entries
curl https://anyrouter.dev/api/v1/security/ip-allowlist \
  -H "Authorization: Bearer $ANYROUTER_MANAGEMENT_KEY"

# Add an entry
curl -X POST https://anyrouter.dev/api/v1/security/ip-allowlist \
  -H "Authorization: Bearer $ANYROUTER_MANAGEMENT_KEY" \
  -H "Content-Type: application/json" \
  -d '{"cidr": "203.0.113.0/24", "label": "Office"}'

# Remove an entry
curl -X DELETE https://anyrouter.dev/api/v1/security/ip-allowlist/<id> \
  -H "Authorization: Bearer $ANYROUTER_MANAGEMENT_KEY"
```

`GET /api/v1/security/keys` returns the active keys shown on the Key safety tab.


## Related

- [Managing API Keys](/docs/features/api-keys.md)
- [Errors](/docs/guides/errors.md)
