IP Access Control
Query API endpoints respect API key-level IP whitelisting. Similar to the SQL Console, Query API endpoints proxy requests from within ClickHouse’s infrastructure, so service-level IP whitelist settings don’t apply. To restrict which clients can call your Query API endpoints:1
Open API key settings
- Go to ClickHouse Cloud Console → Organization → API Keys
- Click Edit next to the API key used for Query API endpoints
2
Add allowed IP addresses
- In the Allow access to this API Key section, select Specific locations
- Enter IP addresses or CIDR ranges (e.g.,
203.0.113.1or203.0.113.0/24) - Add multiple entries as needed