Skip to content

[ALNR-7032] Add API key IP allowlist support - #2077

Merged
Gabefire merged 1 commit into
developfrom
codex/api-key-ip-allowlist
Sep 17, 2026
Merged

Gabefire merged 1 commit into
developfrom
codex/api-key-ip-allowlist

Conversation

@Gabefire

@Gabefire Gabefire commented Sep 17, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • add allowed_ip_cidrs to the public API key creation route
  • validate, normalize, deduplicate, and enforce the 50-entry limit before making the GraphQL request
  • accept IPv4/IPv6 strings and standard ipaddress address/network objects
  • expose allowed_ip_cidrs on retrieved ApiKey objects
  • align the SDK with Labelbox/intelligence#31317

Testing

  • pytest -o addopts="" libs/labelbox/tests/unit/schema/test_api_key.py libs/labelbox/tests/unit/test_client.py (18 passed)
  • focused Ruff formatting and import/error checks
  • git diff --check

Note

Medium Risk
Touches API key creation and credential policy (IP restrictions); validation is client-side and creation remains alpha, but misconfigured allowlists could lock out legitimate API use.

Overview
Adds optional IP allowlisting for API keys in the Python SDK.

Client.create_api_key and ApiKey.create_api_key accept allowed_ip_cidrs (strings or ipaddress objects). Entries are validated, normalized, deduplicated, and capped at 50 before the create mutation sends allowedIpCidrs. Retrieved ApiKey objects expose allowed_ip_cidrs; list queries request the field and treat null as [].

Unit tests cover validation, GraphQL variable wiring, client forwarding, and fetch behavior.

Reviewed by Cursor Bugbot for commit a1d61c9. Bugbot is set up for automated code reviews on this repo. Configure here.

@Gabefire
Gabefire merged commit 9354fd8 into develop Sep 17, 2026
15 of 25 checks passed
@Gabefire
Gabefire deleted the codex/api-key-ip-allowlist branch September 17, 2026 18:06

This branch was successfully deployed

1 active deployment
Test-PyPI — a1d61c98 Deployed Sep 17, 2026 by Gabefire via test-pypi #2514
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants