Skip to content
Helicarrier Developers

Set database allowlist

Set the source CIDRs allowed to connect to an externally accessible database.

POST /api/services/{id}/db/allowlist HTTPS
Request & response examples
Request example Server-side
curl --fail-with-body --request POST \
'https://app.helicarrier.xyz/api/services/YOUR_ID/db/allowlist' \
-H "Authorization: Bearer $HELI_API_KEY" \
-H 'Content-Type: application/json' \
--data '{
"allowIps": [
"203.0.113.4/32"
]
}'
Response example 200
{
"allowIps": [
"203.0.113.4/32"
],
"enforced": true
}

Illustrative values · selected fields

Authorization

An account key with access to the resource. Project and service keys do not authorize this operation.

Authorization: Bearer <key> Key setup ↗

Path parameters

id string required

Database or bucket service id.

Request body

allowIps string[] required

IPv4 addresses or CIDRs allowed to connect. Empty list = allow all.

Response 200

Returns the saved CIDRs and whether the firewall is enforcing them. An empty list allows any source; check enforced before relying on the restriction.

Examples show selected response fields with illustrative values. Your response can contain additional fields.

allowIps array

Allowed external source CIDRs. An empty list permits any source.

enforced boolean

Whether the source-IP firewall is currently enforcing the saved rules.

Errors

400

Invalid parameters. Check the required fields, types, and resource configuration.

401

The API key is missing, invalid, or revoked.

403

The caller or key scope does not permit this operation.

500

The operation could not be completed. Check resource state before retrying a write.

Error handling and safe retries
ALSO AVAILABLE VIA MCP

set_db_allowlist

Required MCP arguments: id, allowIps. Send path, query, and body fields together as tool arguments.

Connect your agent ↗