Workspace IP allowlist
Restrict access to your bldrAgent workspace to specific IP addresses or ranges for enhanced security.
IP allowlist (Enterprise)
The IP allowlist restricts access to your bldrAgent workspace so only connections from approved IP addresses or CIDR ranges are permitted.
This is useful for organisations that require all SaaS access to occur over a corporate VPN or from a fixed office network.
How it works
When IP allowlist is enabled:
- Any login attempt from a non-allowlisted IP is blocked
- The blocked user sees an error page explaining the restriction
- Workspace owners always retain access to manage the allowlist
Configuring the allowlist
- Workspace Settings → Security → IP Allowlist
- Click Add IP range
- Enter an IPv4 address, IPv4 CIDR range, or IPv6 address:
- Single IP:
203.0.113.1 - CIDR range:
203.0.113.0/24 - VPN gateway: add your VPN's egress IP
- Single IP:
- Add a label (e.g. "Office — London", "Corporate VPN")
- Click Save
Repeat for all approved IP ranges.
Enabling and disabling
Toggle the allowlist on/off with the Enable IP Allowlist switch at the top of the page.
Warning: Enabling the allowlist with incorrect IPs will lock you and your team out. Always test from the target network before enabling.
Important considerations
- Only applies to workspace access (bldrAgent builder), not to end-user access to your published apps
- To restrict end-user access to your apps, configure access control in App Settings → Access
- Allowlist changes take effect immediately
- If you're using workspace SSO, the allowlist adds a network-level second factor on top of SSO
Common configurations
| Scenario | Configuration |
|---|---|
| Fixed office network | Add the office's static IP |
| Remote team on VPN | Add the VPN server's egress IP |
| Multiple offices | Add each office's IP range |
| Cloud CI/CD runners | Add your CI/CD provider's IP ranges |
