# `KEY_IP_NOT_ALLOWED` (HTTP 403): the key is used from an address outside its allowlist

The secret key was created with an allowlist of source addresses or CIDR ranges, and this request came from elsewhere.

An allowlist pins a key to the servers that should hold it, so a leaked key is useless from anywhere else. The address checked is the client address as seen through the trusted proxy in front of the service.

Nothing is billed for a refused request.

**What to do.** Call from a listed address, or create a key whose allowlist includes the new range. Allowlists are set when a key is created; Rotate on the API keys page issues a replacement carrying the same one, so change the list by creating a new key rather than by rotating.

```json
{
    "success": false,
    "error": {
        "code": "KEY_IP_NOT_ALLOWED",
        "message": "This API key cannot be used from this address. Add the address to the key's allowlist or create a key without one.",
        "request_id": "req_01m1kgdm4xngzmbmff68g94w0c"
    }
}
```

Reference: https://spaw.co/docs/errors/KEY_IP_NOT_ALLOWED
