# API keys and IP whitelist

> StatesideIP API: API keys with scopes and the IP whitelist for password-free proxy access. Parameters, example responses, curl, Python and Node.js code.

- URL: https://statesideip.com/docs/api/api-keys/
- Last updated: 2026-10-06
- Publisher: StatesideIP (https://statesideip.com)

Create and revoke API keys with limited scopes, and whitelist the source IPs allowed to use the proxies without a username and password.

**Endpoints on this page**

- `GET /v1/api-keys`: List API keys
- `POST /v1/api-keys`: Create an API key
- `DELETE /v1/api-keys/{keyId}`: Revoke an API key
- `GET /v1/ip-whitelist`: List whitelisted IPs
- `POST /v1/ip-whitelist`: Whitelist an IP or range
- `DELETE /v1/ip-whitelist/{entryId}`: Remove a whitelisted IP

Base URL `https://statesideip.com/api/v1`. Authentication, errors and limits: see the [API overview](https://statesideip.com/docs/api/).

## List API keys

`GET /v1/api-keys`

Authentication: API key in the `Authorization: Bearer API_KEY` header.

**Response** `200 OK`

```json
{
  "data": [
    {
      "id": "key_5n2v8q",
      "name": "Rotation script",
      "prefix": "pk_4f9a2c",
      "scopes": [
        "read",
        "proxies"
      ],
      "createdAt": "2026-10-05T14:03:11Z",
      "lastUsedAt": null
    }
  ],
  "limit": 20
}
```

*curl*

```bash
curl -s "https://statesideip.com/api/v1/api-keys" \
  -H "Authorization: Bearer $API_KEY"
```

*Python*

```python
import os
import requests

API = "https://statesideip.com/api/v1"
HEADERS = {"Authorization": f"Bearer {os.environ['API_KEY']}"}

r = requests.get(f"{API}/api-keys", headers=HEADERS, timeout=30)
r.raise_for_status()
print(r.json())
```

*Node.js*

```javascript
// Node.js 18+ (built-in fetch), ES module
const API = 'https://statesideip.com/api/v1';

const res = await fetch(`${API}/api-keys`, {
  headers: { Authorization: `Bearer ${process.env.API_KEY}` },
});
if (!res.ok) throw new Error((await res.json()).error?.message ?? `HTTP ${res.status}`);
console.log(await res.json());
```

## Create an API key

`POST /v1/api-keys`

The full `secret` is returned once.

Authentication: API key in the `Authorization: Bearer API_KEY` header.

**Request body**

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| `name` | string | Yes | max. 60 characters |
| `scopes` | array of `read` · `proxies` · `billing` | Yes | — |

*Example*

```json
{
  "name": "Rotation script",
  "scopes": [
    "read",
    "proxies"
  ]
}
```

**Response** `201 Created`

```json
{
  "id": "key_5n2v8q",
  "name": "Rotation script",
  "prefix": "pk_4f9a2c",
  "scopes": [
    "read",
    "proxies"
  ],
  "createdAt": "2026-10-05T14:03:11Z",
  "lastUsedAt": null,
  "secret": "pk_4f9a2c8e1b7d3f6a9c2e5b8d1f4a7c0e"
}
```

*curl*

```bash
curl -s -X POST "https://statesideip.com/api/v1/api-keys" \
  -H "Authorization: Bearer $API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"name":"Rotation script","scopes":["read","proxies"]}'
```

*Python*

```python
import os
import requests

API = "https://statesideip.com/api/v1"
HEADERS = {"Authorization": f"Bearer {os.environ['API_KEY']}"}

r = requests.post(f"{API}/api-keys", headers=HEADERS, json={"name": "Rotation script", "scopes": ["read", "proxies"]}, timeout=30)
r.raise_for_status()
print(r.json())
```

*Node.js*

```javascript
// Node.js 18+ (built-in fetch), ES module
const API = 'https://statesideip.com/api/v1';

const res = await fetch(`${API}/api-keys`, {
  method: 'POST',
  headers: { Authorization: `Bearer ${process.env.API_KEY}`, 'Content-Type': 'application/json' },
  body: JSON.stringify({ name: 'Rotation script', scopes: ['read', 'proxies'] }),
});
if (!res.ok) throw new Error((await res.json()).error?.message ?? `HTTP ${res.status}`);
console.log(await res.json());
```

## Revoke an API key

`DELETE /v1/api-keys/{keyId}`

Authentication: API key in the `Authorization: Bearer API_KEY` header.

**Parameters**

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `keyId` | path | string | Yes | — |

**Response** `204 No Content`

No body: the status code is the answer.

*curl*

```bash
curl -s -X DELETE "https://statesideip.com/api/v1/api-keys/key_5n2v8q" \
  -H "Authorization: Bearer $API_KEY"
```

*Python*

```python
import os
import requests

API = "https://statesideip.com/api/v1"
HEADERS = {"Authorization": f"Bearer {os.environ['API_KEY']}"}

r = requests.delete(f"{API}/api-keys/key_5n2v8q", headers=HEADERS, timeout=30)
r.raise_for_status()
print(r.status_code)  # 204: done
```

*Node.js*

```javascript
// Node.js 18+ (built-in fetch), ES module
const API = 'https://statesideip.com/api/v1';

const res = await fetch(`${API}/api-keys/key_5n2v8q`, {
  method: 'DELETE',
  headers: { Authorization: `Bearer ${process.env.API_KEY}` },
});
if (!res.ok) throw new Error(`HTTP ${res.status}`);
console.log(res.status); // 204: done
```

## List whitelisted IPs

`GET /v1/ip-whitelist`

Authentication: API key in the `Authorization: Bearer API_KEY` header.

**Response** `200 OK`

```json
{
  "data": [
    {
      "id": "ipw_8c1k2m",
      "cidr": "203.0.113.24",
      "label": "Office server",
      "createdAt": "2026-10-05T14:03:11Z"
    }
  ],
  "limit": 50
}
```

*curl*

```bash
curl -s "https://statesideip.com/api/v1/ip-whitelist" \
  -H "Authorization: Bearer $API_KEY"
```

*Python*

```python
import os
import requests

API = "https://statesideip.com/api/v1"
HEADERS = {"Authorization": f"Bearer {os.environ['API_KEY']}"}

r = requests.get(f"{API}/ip-whitelist", headers=HEADERS, timeout=30)
r.raise_for_status()
print(r.json())
```

*Node.js*

```javascript
// Node.js 18+ (built-in fetch), ES module
const API = 'https://statesideip.com/api/v1';

const res = await fetch(`${API}/ip-whitelist`, {
  headers: { Authorization: `Bearer ${process.env.API_KEY}` },
});
if (!res.ok) throw new Error((await res.json()).error?.message ?? `HTTP ${res.status}`);
console.log(await res.json());
```

## Whitelist an IP or range

`POST /v1/ip-whitelist`

Accepts an IPv4 address, an IPv4 CIDR from /24 to /32, an IPv6 address or an IPv6 CIDR from /48 to /128. Private, loopback and reserved ranges are rejected (`422`). Active at the gateway within 60 s.

Authentication: API key in the `Authorization: Bearer API_KEY` header.

**Request body**

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| `cidr` | string | Yes | — |
| `label` | string | No | max. 60 characters |

*Example*

```json
{
  "cidr": "203.0.113.24",
  "label": "Office server"
}
```

**Response** `201 Created`

```json
{
  "id": "ipw_8c1k2m",
  "cidr": "203.0.113.24",
  "label": "Office server",
  "createdAt": "2026-10-05T14:03:11Z"
}
```

*curl*

```bash
curl -s -X POST "https://statesideip.com/api/v1/ip-whitelist" \
  -H "Authorization: Bearer $API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"cidr":"203.0.113.24","label":"Office server"}'
```

*Python*

```python
import os
import requests

API = "https://statesideip.com/api/v1"
HEADERS = {"Authorization": f"Bearer {os.environ['API_KEY']}"}

r = requests.post(f"{API}/ip-whitelist", headers=HEADERS, json={"cidr": "203.0.113.24", "label": "Office server"}, timeout=30)
r.raise_for_status()
print(r.json())
```

*Node.js*

```javascript
// Node.js 18+ (built-in fetch), ES module
const API = 'https://statesideip.com/api/v1';

const res = await fetch(`${API}/ip-whitelist`, {
  method: 'POST',
  headers: { Authorization: `Bearer ${process.env.API_KEY}`, 'Content-Type': 'application/json' },
  body: JSON.stringify({ cidr: '203.0.113.24', label: 'Office server' }),
});
if (!res.ok) throw new Error((await res.json()).error?.message ?? `HTTP ${res.status}`);
console.log(await res.json());
```

## Remove a whitelisted IP

`DELETE /v1/ip-whitelist/{entryId}`

Authentication: API key in the `Authorization: Bearer API_KEY` header.

**Parameters**

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `entryId` | path | string | Yes | — |

**Response** `204 No Content`

No body: the status code is the answer.

*curl*

```bash
curl -s -X DELETE "https://statesideip.com/api/v1/ip-whitelist/ipw_8c1k2m" \
  -H "Authorization: Bearer $API_KEY"
```

*Python*

```python
import os
import requests

API = "https://statesideip.com/api/v1"
HEADERS = {"Authorization": f"Bearer {os.environ['API_KEY']}"}

r = requests.delete(f"{API}/ip-whitelist/ipw_8c1k2m", headers=HEADERS, timeout=30)
r.raise_for_status()
print(r.status_code)  # 204: done
```

*Node.js*

```javascript
// Node.js 18+ (built-in fetch), ES module
const API = 'https://statesideip.com/api/v1';

const res = await fetch(`${API}/ip-whitelist/ipw_8c1k2m`, {
  method: 'DELETE',
  headers: { Authorization: `Bearer ${process.env.API_KEY}` },
});
if (!res.ok) throw new Error(`HTTP ${res.status}`);
console.log(res.status); // 204: done
```

---

StatesideIP: StatesideIP is a US and Canada proxy provider: residential IPs with state, city, ZIP and ASN targeting, plus dedicated T-Mobile, AT&T and Verizon 4G/5G mobile ports. No KYC — no ID, no selfie, no documents. Pay in crypto.
