Skip to content

Payment Provider Security

To reduce the risk of API credential abuse, payment provider API access is restricted to known IP ranges wherever the provider supports it. This means that even if a payment token is leaked, it cannot be used from outside our whitelisted servers and network.

These tables record what is configured at the provider

Editing this page does not change any restriction — the allowlists live in the QuickPay and Adyen panels. When a server is migrated or rebuilt, update the provider first, then this page. Server IPs are listed per host in the Zero Trust resilience appendix.


QuickPay

IP whitelist

IP Location
87.116.13.2/32 Office
195.201.242.93/32 Hetzner — Dedicated Web Server
116.202.98.191 Hetzner — bknl-e01 (Barberklingen.nl)
188.34.159.227 Hetzner — bkse-e01 (Barberklingen.se)
157.90.240.83 Hetzner — bkdk-e01 (Barberklingen.dk)
46.225.54.181 Hetzner — kddk-e01 (Kaffedrengen.dk)
188.245.227.30 Hetzner — el-e01 (Elome.com)

Adjusting the whitelist

  1. Log in to manage.quickpay.net.
  2. Go to Users and select the API User.
  3. Edit the IP restrictions from there.

Adyen

IP whitelist

IP Location
87.116.13.2/32 Office
195.201.242.93/32 Hetzner — Dedicated Web Server
116.202.98.191 Hetzner — bknl-e01 (Barberklingen.nl)

Adjusting the whitelist

  1. Log in to Adyen.
  2. Navigate to DevelopersAPI Keys.
  3. Select the user named ws (Web Service) and edit the IP restrictions.

MobilePay

IP restrictions are not currently supported by MobilePay. This feature has been requested and may become available as part of the upcoming unified Vipps/MobilePay API.

Note

Until IP restrictions are available, MobilePay API credentials carry higher risk than QuickPay or Adyen credentials. Treat them accordingly — rotate immediately if a leak is suspected.