Before you start
Sign in as an Admin and open Platform → IP restrictions. The status banner shows whether restrictions are active and the address Lexful sees for your current connection.
With no active addresses, access is allowed from any IP address. Normal sign-in and account permissions still apply; this does not make your data public. Adding the first active entry turns restrictions on. Plan the addresses your team and integrations need before enabling them.
For an office, VPN or integration, use the public outbound IPv4 address that Lexful sees. A device's private LAN address usually is not the address to allow. The screenshot shows a local demonstration environment; use the address shown in your own account.
Add your current address first
Check the address in the status banner. If you intend to allow a VPN connection, connect to that VPN before checking.
Select Add my address. Lexful adds that address with the description “My current IP”.
Confirm the entry appears and the status shows that restrictions are active.
Add IP remains unavailable until your current address is covered by an active entry. The page checks your current connection again before saving changes to help prevent you from locking yourself out.
Add another address or range
Select Add IP.
Enter one IPv4 address or CIDR range in IP address. For example,
203.0.113.10represents one address, while203.0.113.0/24represents a range. These are documentation examples; replace them with your own network details.Optionally add a Description, such as “Main office” or “Production sync”.
Select Add address and confirm the entry appears.
Add each address or range separately; do not enter a comma-separated list. IPv6 is not supported. Allow only the ranges your team needs—0.0.0.0/0 covers all IPv4 addresses.
Include the outbound addresses used by integrations as well as staff connections. A person or integration connecting from outside the allowed addresses may lose access even if its credentials are correct.
Find and edit an entry
Use Search addresses to filter by address or description. Select the entry's edit action, update IP address or Description, then select Save changes.
Before replacing a range, add any replacement addresses your team needs. The page blocks changes that would remove coverage for your current connection while restrictions remain active, but that check does not prove other users or integrations are covered.
Remove an entry or turn restrictions off
Select an entry's remove action and review the confirmation. For a normal removal, choose Remove IP. Connections no longer covered by another entry lose access.
Removing the last active entry turns restrictions off. The confirmation changes to Allow access from any IP? and requires Allow any IP. An empty allowlist means unrestricted IP access, not “block everyone”.
Troubleshoot access
Add IP is disabled: add your current address first. If the IP check failed, retry it before making changes.
A change is blocked: your connection may have changed, or another admin may have edited the list. Review the refreshed address and entries.
Access stopped after changing networks: connect through an already allowed office or VPN, or ask an admin on an allowed connection to update the list.
An integration stopped connecting: check its public outbound address and whether the provider changed it. Do not assume it uses the same address as your browser.
If no administrator can connect from an allowed address, contact Lexful Support for help recovering access.
