Set database allowlist
Set the source CIDRs allowed to connect to an externally accessible database.
Request & response examples
curl --fail-with-body --request POST \ 'https://app.helicarrier.xyz/api/services/YOUR_ID/db/allowlist' \ -H "Authorization: Bearer $HELI_API_KEY" \ -H 'Content-Type: application/json' \ --data '{ "allowIps": [ "203.0.113.4/32" ]}'const response = await fetch( "https://app.helicarrier.xyz/api/services/YOUR_ID/db/allowlist", { method: "POST", headers: { Authorization: `Bearer ${process.env.HELI_API_KEY}`, "Content-Type": "application/json" }, body: JSON.stringify({ "allowIps": [ "203.0.113.4/32" ] }) });const data = await response.json();if (!response.ok) { throw new Error(`HTTP ${response.status}: ${data.error}`);}// Inspect data; avoid logging secret responses.import osimport requests
response = requests.request( "POST", "https://app.helicarrier.xyz/api/services/YOUR_ID/db/allowlist", headers={ "Authorization": f"Bearer {os.environ['HELI_API_KEY']}" }, json={ "allowIps": [ "203.0.113.4/32" ] }, timeout=30,)response.raise_for_status()data = response.json()# Inspect data; avoid logging secret responses.{ "allowIps": [ "203.0.113.4/32" ], "enforced": true}Illustrative values · selected fields
Path parameters
id string required Database or bucket service id.
Request body
allowIps string[] required IPv4 addresses or CIDRs allowed to connect. Empty list = allow all.
Response 200
Returns the saved CIDRs and whether the firewall is enforcing them. An empty list allows any source; check enforced before relying on the restriction.
Examples show selected response fields with illustrative values. Your response can contain additional fields.
allowIps array Allowed external source CIDRs. An empty list permits any source.
enforced boolean Whether the source-IP firewall is currently enforcing the saved rules.
Errors
400 Invalid parameters. Check the required fields, types, and resource configuration.
401 The API key is missing, invalid, or revoked.
403 The caller or key scope does not permit this operation.
500 The operation could not be completed. Check resource state before retrying a write.
set_db_allowlist
Required MCP arguments: id, allowIps. Send path, query,
and body fields together as tool arguments.