Programa de referidos →
InicioGlosarioWhitelist de IP
Glosario

Whitelist de IP

Una regla por la que un servicio acepta conexiones solo desde direcciones registradas de antemano. En un proxy sustituye al usuario y la contraseña.

La whitelist de IP es una forma de autenticarte en un servicio de proxy usando tu dirección IP de origen en lugar de un usuario y contraseña. Registras las direcciones IP de las máquinas que usarán el proxy, y el proveedor permite conexiones solo desde esas direcciones. Cualquier solicitud desde una IP en la whitelist se confía automáticamente.

Es la principal alternativa a la autenticación por usuario/contraseña. Las credenciales viajan con cada solicitud y funcionan desde cualquier sitio; la whitelist vincula el acceso a máquinas concretas y no requiere credenciales en el código. Muchos proveedores admiten ambas, y eliges según el caso de uso.

La whitelist brilla para la infraestructura fija. Si tus scrapers corren en servidores con IPs públicas estables, poner esas IPs en la whitelist es limpio y seguro - no hay credenciales que puedan filtrarse en el código o los logs. Es incómodo cuando tu IP de origen cambia a menudo (conexiones domésticas dinámicas, autoescalado en la nube), ya que debes mantener la whitelist actualizada.

Un requisito práctico: debes conocer y controlar tu IP pública saliente para ponerla en la whitelist, y debe ser lo bastante estática como para seguir siendo válida. Para equipos que ejecutan proxies desde servidores en la nube o desde una IP de oficina fija, la whitelist suele ser más simple y segura que distribuir credenciales de usuario/contraseña.

Authenticating by where you are rather than what you know

A proxy has to decide whether a connection belongs to a paying customer. The usual answer is a username and password sent with each connection. The alternative is a whitelist: the provider records the addresses your traffic will come from, and any connection from those addresses is accepted without credentials.

The appeal is practical. Tools that cannot handle proxy authentication, and there are more of them than you would expect, work fine against a whitelisted proxy because there is nothing to authenticate. Selenium without extra packages is the classic example.

The cost is flexibility. Your server address becomes the key, so a change of server, a new office connection or a laptop on hotel wifi all break access until you update the list. On a home connection with a dynamic address, whitelisting stops working roughly whenever the router reboots.

There is also a security tradeoff that runs both ways. Credentials can leak in a log file or a screenshot, and a whitelist cannot. But anyone who can send traffic from a whitelisted address, including another tenant on the same shared server, inherits your access.

Where whitelisting fits in our setup

Residential lists accept a whitelist, so a server can use them without credentials in the connection string:

Two ways to authorise the same traffic

# By credentials, works from anywhere
curl -x login_c_US:password@proxy.sotaproxy.com:10000 https://api.ipify.org

# By whitelist: register your server address, then connect without a password
# from that address only.
#
# Manage the list in the dashboard or through the API:
#   GET  /user/residential/whitelist
#   POST /user/residential/whitelist
  • Whitelist your servers, not your laptop. A residential connection at home changes address often enough to make this a source of confusion rather than convenience.
  • Keep credentials working as a fallback. If the whitelist is your only path and your server address changes, you lose access exactly when you are least able to debug calmly.
  • On a shared or cloud host, remember that the address may not be exclusively yours. Prefer credentials on anything multi-tenant.
  • Static addresses use credentials. The whitelist applies to residential lists, so a mixed setup will have both forms of authentication in it.

What whitelisting does not do

It does not hide anything from the destination

Whitelisting governs who may use the proxy. The site you visit sees the exit address either way and knows nothing about how you authenticated.

It is not more secure by default

It replaces a secret with a location. Which is safer depends entirely on whether your address is exclusively yours.

It does not survive dynamic addresses

Home and mobile connections rotate. A whitelist entry that worked yesterday will fail silently after a reconnect, and the error looks like a proxy fault.

It is not a substitute for a firewall

Whitelisting tells us which addresses may use your proxy. It does nothing about what reaches your own server.

Where you meet an IP whitelist

The term is not proxy vocabulary. The same rule appears across the stack, and the differences that matter are what gets allowed and how it breaks.

WhereWhat it allowsHow it usually breaks
Firewall or security groupInbound traffic to a host or port from listed sourcesA colleague works from a new network and is locked out with no message that explains it
Cloud provider consoleAccess to a database or management APIThe list is per region or per resource, and one resource gets forgotten
SaaS or payment dashboardSign-in or API calls from your office and serversA provider changes its egress addresses and your integration stops without warning
Managed databaseConnections from application servers onlyAn autoscaled instance comes up on an address nobody registered
Proxy providerUse of the proxy without sending a username and passwordThe home router renews its lease overnight and every request starts returning 407

Every row fails the same way: the address changed and the list did not. That is the single thing to plan for, whichever of these you are configuring.

Questions people actually type

What is IP whitelisting?

A rule that tells a service to accept connections only from addresses you registered in advance, and to refuse everything else. The address becomes the credential: being at the right place is what grants access, instead of knowing the right password.

What is a whitelisted IP address?

An address that appears on that list. Nothing about the address itself changes. It behaves exactly as before everywhere else, and it is privileged only on the service where it was registered.

Is IP whitelisting secure?

It is a useful layer and a poor foundation. It answers where a request came from, never who sent it, so anyone on the same office network or the same machine inherits the access. Source addresses can also be spoofed in some setups. Treat it as a filter in front of authentication rather than instead of it.

What happens when my IP address changes?

Access stops, usually without a helpful message. Home connections get a new address whenever the lease renews or the router reboots, mobile networks change it constantly. This is the most common reason a whitelist that worked yesterday fails today, and it is why a static address or credentials suit anything that has to keep running.

How do I find the IP address to whitelist?

Ask the machine that will actually connect, not the one you are sitting at. On a server, curl an address echo service from that server. A laptop behind a company network usually leaves through a different address than the one it sees locally, and it is the leaving address that must go on the list.

Whitelisting or a username and password on a proxy?

Whitelisting when the connection comes from a fixed address you control, such as a server, because there is then nothing to leak in a config file. Credentials when the address moves, when several people share the setup, or when you need the same credentials to work from anywhere. We support both, and the choice is not permanent.

¿Listo para usar whitelist de ip?

SotaProxy te da acceso a proxies residenciales rotativos, móviles, de centro de datos e ISP. Sin compromiso mínimo.

Empezar