IP allowlist
Use an IP allowlist to limit access to your Metabase instance to approved IP addresses. The allowlist applies to all access to your instance, so people outside the allowlist can’t reach the API, embedded dashboards and questions, or public links.
IP allowlists are only available on Metabase Cloud Pro or Enterprise plans. To restrict access to a self-hosted Metabase, use your own firewall or load balancer, or consider air-gapping.
The allowlist accepts IPv4 addresses and CIDR ranges. Metabase treats a bare IPv4 address as a /32 range.
By default, restricting access by IP address is turned off.
To allow Metabase to reach your databases, see IP addresses to whitelist.
Set up an IP allowlist
When you save an allowlist, your instance restarts. Metabase blocks requests from addresses outside the allowlist, so include the address or range you’re connecting from before you save.
The allowlist doesn’t apply to the Metabase Store. If you leave out your own address, you can still log in to the Store and update the allowlist.
- Log in to your Metabase Store account.
- Navigate to Instances.
- In the instance you want to restrict access to, click Settings.
- Scroll to IP allowlist.
- Enable the Restrict access by IP address toggle.
- In the IP/CIDR ranges field, enter an IPv4 address or a CIDR range.
- To add more addresses, enter them in the empty field. To add several at once, paste a list with one address or range per line.
- Click Save.
- Review the warning, then confirm. Your instance restarts.
Metabase validates each entry as you type. To save the allowlist, you must first correct or remove invalid entries.
To remove an address, click the trash icon next to the address or range, then click Save.
Turn off the IP allowlist
When you turn off the IP allowlist and save, Metabase clears the saved addresses. To restrict access again, you must re-enter the addresses.
Turning off the allowlist doesn’t remove authentication. People still need to sign in to your Metabase.
In your instance’s IP allowlist settings:
- Disable the Restrict access by IP address toggle.
- Click Save.