ip_not_allowed
Address not allowed
HTTP 403
At launchSent from launch, once the origin lock and the partner security platform enforce.
The key holds an IP allowlist, and this request came from an address outside it: the address our edge saw, never one a header names. Send the request from an address the allowlist holds, or change the key's allowlist in the portal. A request refused this way isn't counted against the key's rate limit, and a signed request's nonce isn't spent.
The problem body
Sent as application/problem+json, with the request id in request_id and the X-Request-Id header. Branch on code: the error and detail sentences can change, and some operations add members of their own.
{
"error": "Address not allowed",
"code": "ip_not_allowed",
"type": "https://secondappraisal.com/developers/errors/ip_not_allowed",
"title": "Address not allowed",
"status": 403,
"detail": "Address not allowed",
"instance": "/api/gap/v1/referrals",
"request_id": "req_4f9a2c7e1b8d4a6f9c3e2b1a7d5f8e0c"
}Operations that can send it
- POST /api/gap/v1/referrals · HTTP 403 · Create a referral
- GET /api/gap/v1/referrals · HTTP 403 · List referrals
- GET /api/gap/v1/referrals/{id} · HTTP 403 · Retrieve a referral
- PATCH /api/gap/v1/referrals/{id} · HTTP 403 · Update or cancel a referral
- POST /api/gap/v1/referrals/bulk · HTTP 403 · Create referrals in bulk
- POST /api/gap/v1/referrals/{id}/simulate · HTTP 403 · Simulate a sandbox referral's next stepAt launchIt opens with the referral sandbox.
- POST /api/gap/v1/referrals/{id}/attest · HTTP 403 · Attest a warm handoffAt launchIt opens with the referral sandbox.
- GET /api/gap/v1/analytics · HTTP 403 · Savings and spend analytics
- POST /api/gap/v1/plans/enrollments · HTTP 403 · Enroll one vehicle
- GET /api/gap/v1/plans/enrollments · HTTP 403 · List your roster
- GET /api/gap/v1/plans/enrollments/{id} · HTTP 403 · Retrieve one enrollment
- PATCH /api/gap/v1/plans/enrollments/{id} · HTTP 403 · Cancel, swap the VIN, or edit contact details
- POST /api/gap/v1/plans/enrollments/bulk · HTTP 403 · Enroll up to 500 vehicles
- POST /api/gap/v1/plans/roster-sync · HTTP 403 · Reconcile your full roster
- POST /api/gap/v1/plans/loss-notices · HTTP 403 · Tell us a member vehicle was declared a total loss
- GET /api/gap/v1/plans/redemptions · HTTP 403 · Member consultations drawn against your roster
- GET /api/gap/v1/plans/statements · HTTP 403 · Your monthly membership statements
- GET /api/gap/v1/events · HTTP 403 · List your eventsAt launchIt opens with the partner security platform.
- GET /api/gap/v1/me · HTTP 403 · The key making this call
- POST /api/gap/v1/credentials/{id}/verify · HTTP 403 · Activate a signed credentialAt launchIt opens when signed credentials open.
- POST /api/gap/v1/signature-check · HTTP 403 · Check a signature (test credentials)Planned: not served yet.
- POST /api/gap/v1/review-status/lookup · HTTP 403 · Look up review status by VIN, claim number or referenceAt launchIt opens with review records.
- GET /api/gap/v1/referrals/{id}/review-record · HTTP 403 · Retrieve a referral's review recordAt launchIt opens with review records.