> Source: https://ashareapi.com/en/docs/endpoints/ip-whitelist/  ·  Markdown version for LLMs / AI agents

Pro endpoint · Pro

# IP allow-list (lock a key to fixed IPs) API
 Lock an API key to a fixed set of IPs, so a leaked key cannot be used from anywhere else. GET returns the current list · POST replaces it (`ips=1.2.3.4,5.6.7.8`, up to 50) · DELETE clears it (the key is then usable from any IP again). When the list is non-empty, requests from other IPs get `403`. Authenticate with the same key you are locking. ⚠️ Calls from your own current IP always pass, so you cannot lock yourself out; use DELETE to recover. Paid tier — Unlimited (¥199) and above.
 Pro `GET /v1/ip-whitelist`
 Signature
```
GET /v1/ip-whitelist
```
 One-liner

```
curl "https://api.ashareapi.com/v1/ip-whitelist?key=YOUR_KEY"
```
 Parameters: `none` * = required

## Quick start
 Replace the key below with yours (free endpoints need no key):
 curl

```
# 推荐：Authorization 头（密钥不进日志）
curl -H "Authorization: Bearer YOUR_KEY" \
 "https://api.ashareapi.com/v1/ip-whitelist"

# 快速测试：直接浏览器打开（?key= 会留在日志/历史里，别用于生产）
curl "https://api.ashareapi.com/v1/ip-whitelist?key=YOUR_KEY"
```
 Python

```
import requests

r = requests.get(
 "https://api.ashareapi.com/v1/ip-whitelist",
 headers={"Authorization": "Bearer YOUR_KEY"},
 params={},
 timeout=30,
)
print(r.json())
```
 JavaScript

```
const r = await fetch("https://api.ashareapi.com/v1/ip-whitelist", {
 headers: { Authorization: "Bearer YOUR_KEY" },
});
console.log(await r.json());
```

## Methods
 GET `/v1/ip-whitelist` Read the IP allow-list (Unlimited)
 Read the current IP allow-list for this key (empty = not enabled).

 POST `/v1/ip-whitelist` Set the IP allow-list (replaces the old one)
 Replace the allow-list. Pass `ips` (comma-separated, up to 50, exact IPv4/IPv6 only — no CIDR). ⚠️ Include both old and new IPs when switching networks, or the old one stops working immediately. After setting, this endpoint can only be called from an IP on the list.

- `ips` (string) — Comma-separated IPs to allow, up to 50 (e.g. 1.2.3.4,5.6.7.8)

 DELETE `/v1/ip-whitelist` Clear the IP allow-list
 Clear the allow-list so the key works from any IP again. ⚠️ Like GET/POST, this must be called from an IP already on the list — if you get locked out, contact support.

- `target_key` (string) — 仅客服使用：要清除的目标 Key

 Response
 Unified envelope: `{ ok, endpoint, tier, elapsed_ms, source, data }`
 Rows live in `data`; when upstream returns nothing you get `ok:false` and **the call is not counted**.

 Rate limits & quota
 Free endpoints need no key (anonymous 5/min — 250 bars per request, 100k rows per day; solve one PoW challenge for 15/min). Paid tiers: Trial 30 · Standard 120 · Pro 300 · Unlimited 600 per minute; buyout packs are capped by total calls and never expire.
[See the error code table →](/en/docs/errors)

## FAQ

### General (applies to every endpoint)
 Do these endpoints need an API key?
 **Free endpoints do not**: health, challenge, quote, kline, hot, market-overview and changedist work anonymously. **Paid endpoints do**: send `Authorization: Bearer `. ⚠️ The anonymous allowance is **tiered by caller type**: browsers (humans) get **5/min**; scripts, SDKs and AI Agents (curl, requests, axios, openai user-agent strings) get **2/min** — automated traffic is easier to abuse. Solving one PoW challenge (`GET /v1/challenge`, then send the `X-PoW` header) raises it to **15/min** regardless of type. ⚠️ Also, anonymous calls are capped at **250 bars per request and 100k rows per day** — use an API key for the full 1212 bars or unlimited daily volume.

 Am I charged when the upstream returns nothing or errors?
 **No.** When the upstream fails or returns nothing you get `ok:false` and the charge for that call is **refunded** (total_calls / usage_log / ep_log are rolled back together). Only calls that actually returned data count.

 How fresh is the data?
 Quotes (quote / kline / orderbook / changedist) are **real-time or current session**; financials, shareholders, dividends and events are **within T+1 of upstream disclosure**. The `source` field in every response tells you which data channel actually served it.

 Can I request several stocks in one call?
 **No.** `code` is a single-value parameter — one stock per call. For batches, issue concurrent calls and respect your tier per-minute limit.

 How do I use this from Claude / Cursor / ChatGPT?
 Set up MCP once, then just ask the AI — it calls the endpoint itself. MCP exposes 26 tools covering quotes, financials, screening, sectors and macro.

## Related endpoints
 [Full-history K-line (10y daily · raw + adjustment factors)](/en/docs/endpoints/kline-full)[Quant backtest (single-stock live / portfolio precomputed)](/en/docs/endpoints/backtest)[Quant strategy list (20 single-stock + 9 portfolio)](/en/docs/endpoints/strategies)[Batch backtest (many stocks × many strategies)](/en/docs/endpoints/backtest-batch)[Quant factor library (88 factors + 22 presets)](/en/docs/endpoints/factors)[Quant playbook library (how to judge the market · 13 playbooks)](/en/docs/endpoints/playbooks)[分时（当日 / 近 5 日盘中走势）](/en/docs/endpoints/minute)[Financial statements](/en/docs/endpoints/finance)

 Use it from an AI Agent?
 Set up MCP once, then just ask the AI — it calls the endpoint itself.

 [MCP setup](/en/mcp)[Pricing](/en/pricing)

 [← Back to the full endpoint reference](/en/endpoints)
