What’s new
- IP allowlisting for UI logins, including multi-org SSO
- IP allowlisting for API keys and service tokens, so a compromised key can’t be used to reach env zero from an untrusted network
- IP allowlisting for the Agent API, adding defense in depth on top of token-based authentication for self-hosted and SaaS agents
How it works
- The allowlist is configured per organization, supporting both IPv4 and IPv6 addresses and subnets.
- If no allowlist is configured, all IPs are allowed. There’s no change in behavior for organizations that don’t opt in.
- Once configured, logins and API/Agent requests are only permitted from an approved IP or subnet. Allowlist updates take effect immediately.
IP allowlisting is configured at the organization level. Contact your env zero account team or support to enable and configure it for your organization.