> ## Documentation Index
> Fetch the complete documentation index at: https://docs.omni.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Restricting Omni access with an IP allowlist

> Limit access to your Omni organization to a list of approved public IP addresses and CIDR ranges.

export const XCircleIcon = ({label}) => {
  return <span>
      <Icon icon="circle-xmark" iconType="solid" color="#ff2465" />
      {label && ` ${label}`}
    </span>;
};

export const CheckIcon = ({label}) => {
  return <span>
      <Icon icon="circle-check" iconType="solid" color="#26bd6c" />
      {label && ` ${label}`}
    </span>;
};

<Note>
  **This guide is about limiting who can access Omni**. To let Omni connect to your database or other systems, refer to [Omni IP addresses](/administration/security/omni-ip-addresses).
</Note>

Use an IP allowlist to let people and systems access your Omni organization only from public IP addresses that you approve. This guide tells you how to set up, change, and disable the allowlist, and how to let Omni support and SCIM provisioning bypass it.

## How the IP allowlist works

An IP allowlist limits access to your Omni organization to specific networks, such as a company VPN or office network. When the allowlist is enabled, requests from an address that isn't on the list are blocked.

### When to use an allowlist

<Columns cols={2}>
  <Card title="An allowlist is a good fit when..." type="tip" icon={<CheckIcon />}>
    * Everyone who uses Omni connects through networks your organization controls, such as a company VPN or office network.
    * Your IT team knows the public IP addresses of those networks, and those addresses rarely change.
  </Card>

  <Card title="An allowlist isn't a good fit when..." type="danger" icon={<XCircleIcon />}>
    * People sign in from home, mobile, or other networks that don't route through your VPN.
    * Your VPN provider changes its public IP addresses without notice. A change can lock everyone out, including admins.
    * You embed Omni content for people outside your organization. Embedded viewers must also connect from a listed address.
  </Card>
</Columns>

### What the allowlist applies to

When enabled, the allowlist applies to all requests to your organization, including:

* **Users in the Omni app**, including the login page. Blocked users see an **Access restricted** page that shows their IP address.
* **Embedded content**, including content on a [vanity domain](/embed/customization/vanity-domains).
* **Embed SSO requests** from your backend servers.
* **API requests**, including [SCIM](/administration/authentication/okta/scim) provisioning requests from your identity provider. To allow SCIM requests from any address, refer to [SCIM provisioning](#scim-provisioning).
* **MCP requests** from AI clients.

Blocked requests that don't come from a browser receive a `403` response.

<h3 id="address-rules">
  Allowlist address rules
</h3>

Omni applies these rules to the entries:

* An address without a CIDR suffix allows only that address.
* Only public addresses are accepted. Private ranges, such as `10.0.0.0/8` or `192.168.0.0/16`, are rejected.
* Ranges that include all addresses, such as `0.0.0.0/0`, are rejected.
* Each address or range can be listed only once.
* Omni stores a CIDR range as its network address. For example, `203.0.113.77/24` is saved as `203.0.113.0/24`.

## Requirements

**Organization Admin** permissions are required to access and change IP allowlist settings.

<h2 id="setup">
  Setting up the IP allowlist
</h2>

<Steps titleSize="h3">
  <Step title="Enable the allowlist">
    1. Navigate to **Settings > General** and click the **IP allowlist** tab.
    2. Turn on **Enable IP allowlist**.
  </Step>

  <Step title="Add addresses to the allowlist">
    First, add the address in the **Your current IP address** banner to the list. **This address must be in the list before you can save.**

    After you add your own IP address:

    1. Click **Add address** or press `Enter` to add more addresses.
    2. In **Allowed addresses**, enter a public IPv4 or IPv6 address or CIDR range in **Address or range**. For example, `203.0.113.0/24`, `198.51.100.14`, or `2001:db8::/32`.

       See [Allowlist address rules](#address-rules) for the rules Omni applies to addresses.

           <Tip>
             You can also paste a list of addresses, one per line, and Omni will add a row for each address. If you copy two columns from a spreadsheet, Omni puts the first column in **Address or range** and the second in **Note**.
           </Tip>
    3. Use the **Note** field to describe what the address is for, such as `Office VPN`. Notes can be up to 200 characters and must have a valid address in the same row.
    4. Add additional addresses to the list as needed.

    <Warning>
      **If you use embed SSO or the Omni API**, add the public IP addresses of the servers that send those requests to the list. Otherwise, their requests will be blocked.

      **For SCIM**, add your identity provider's public IP addresses or turn on [**Let SCIM provisioning bypass the allowlist**](#scim-provisioning).
    </Warning>
  </Step>

  <Step title="Optional: Enable allowlist bypass settings">
    Enable bypass settings to let [Omni support](#omni-support-access) or [SCIM provisioning](#scim-provisioning) requests access your organization from addresses that aren't on the list. See [Enabling bypass settings](#bypass) for more information.
  </Step>

  <Step title="Save the allowlist">
    When finished, click **Save changes**.

    If the list is empty, has an invalid row, or doesn't include your current IP address, Omni displays an error. You'll need to fix the issue before you can save the list.
  </Step>
</Steps>

<h2 id="modify">
  Modifying the allowlist
</h2>

1. Navigate to **Settings > General** and click the **IP allowlist** tab.
2. In **Allowed addresses**, add, edit, or remove rows. To remove a row, click the <Icon icon="trash" className="icons" /> icon in the row.
3. Click **Save changes**.

## Disabling the allowlist

1. Navigate to **Settings > General** and click the **IP allowlist** tab.
2. Turn off **Enable IP allowlist**.
3. Click **Save changes**.

Omni keeps the addresses, the notes, and the bypass settings, so you can enable the allowlist again later without entering them again.

<h2 id="bypass">
  Enabling bypass settings
</h2>

Bypass settings let specific types of requests access your organization from addresses that aren't on the allowlist. These settings are off by default and display only when **Enable IP allowlist** is on.

### Omni support access

When **Let Omni support bypass the allowlist** is enabled, Omni support staff can access your organization from addresses that aren't on the list. They must sign in through Omni's support login.

This setting is off by default. When it's off, Omni support can't sign in to your organization to help you unless they connect from an address on the list. The setting displays only when **Enable IP allowlist** is on.

For other controls on support access, refer to [Support settings](/administration/settings#support-settings).

### SCIM provisioning

Your identity provider sends [SCIM](/administration/authentication/okta/scim) requests from its own IP addresses. You can add these addresses to the list, but some identity providers use many addresses or change them without notice.

When **Let SCIM provisioning bypass the allowlist** is enabled, requests to Omni's SCIM endpoints work from any address, including the SCIM endpoints for embed users. These requests must still use an [Organization API key](/api/authentication#token-types). This setting is off by default.

This setting doesn't change other access:

* Users that SCIM creates must still sign in from an address on the list.
* Other API requests are still blocked if they come from an address that isn't on the list.

## Troubleshooting

<AccordionGroup>
  <Accordion title="Everyone is locked out of Omni">
    This can occur if the public IP addresses of your VPN or office network change. Contact Omni support to get access again.
  </Accordion>

  <Accordion title="SCIM provisioning stopped working">
    Your identity provider's requests come from its own IP addresses. Do one of these:

    * Add your identity provider's public IP addresses to the list. Refer to your identity provider's documentation for these addresses.
    * Turn on [**Let SCIM provisioning bypass the allowlist**](#scim-provisioning).
  </Accordion>

  <Accordion title="API or embed SSO requests return a 403 error">
    Add the public IP addresses of the servers that send the requests to the list.
  </Accordion>

  <Accordion title="Omni doesn't save my changes because the settings changed">
    This can occur if another admin saved changes to the IP allowlist after you opened the page. Reload the page, make your changes again, and click **Save changes**.
  </Accordion>

  <Accordion title="A user sees the Access restricted page">
    The page shows the user's IP address. Ask the user to connect through an approved network, or add their address to the list. After you save the change, the user can refresh the page to get access.
  </Accordion>
</AccordionGroup>

## Next steps

* [Omni IP addresses](/administration/security/omni-ip-addresses) - The addresses Omni uses to connect to your systems
* [Organization settings](/administration/settings)
* [Audit log event types](/administration/audit-logs/event-types#ip-allowlist-updated) - The events Omni logs when IP allowlist settings change


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.