Payment Provider Security¶
To reduce the risk of API credential abuse, payment provider API access is restricted to known IP ranges wherever the provider supports it. This means that even if a payment token is leaked, it cannot be used from outside our whitelisted servers and network.
These tables record what is configured at the provider
Editing this page does not change any restriction — the allowlists live in the QuickPay and Adyen panels. When a server is migrated or rebuilt, update the provider first, then this page. Server IPs are listed per host in the Zero Trust resilience appendix.
QuickPay¶
IP whitelist¶
| IP | Location |
|---|---|
87.116.13.2/32 | Office |
195.201.242.93/32 | Hetzner — Dedicated Web Server |
116.202.98.191 | Hetzner — bknl-e01 (Barberklingen.nl) |
188.34.159.227 | Hetzner — bkse-e01 (Barberklingen.se) |
157.90.240.83 | Hetzner — bkdk-e01 (Barberklingen.dk) |
46.225.54.181 | Hetzner — kddk-e01 (Kaffedrengen.dk) |
188.245.227.30 | Hetzner — el-e01 (Elome.com) |
Adjusting the whitelist¶
- Log in to manage.quickpay.net.
- Go to Users and select the API User.
- Edit the IP restrictions from there.
Adyen¶
IP whitelist¶
| IP | Location |
|---|---|
87.116.13.2/32 | Office |
195.201.242.93/32 | Hetzner — Dedicated Web Server |
116.202.98.191 | Hetzner — bknl-e01 (Barberklingen.nl) |
Adjusting the whitelist¶
- Log in to Adyen.
- Navigate to Developers → API Keys.
- Select the user named ws (Web Service) and edit the IP restrictions.
MobilePay¶
IP restrictions are not currently supported by MobilePay. This feature has been requested and may become available as part of the upcoming unified Vipps/MobilePay API.
Note
Until IP restrictions are available, MobilePay API credentials carry higher risk than QuickPay or Adyen credentials. Treat them accordingly — rotate immediately if a leak is suspected.