# IP Addresses The **IP Address list** feature allows you to declare which IP addresses your app uses to make API requests to Zoom accounts. This enables Zoom account administrators to enforce IP-based access controls for enhanced security. When you provide IP addresses in the build flow, account administrators who install your app can: - Review the IP addresses your app uses. - Approve or reject specific IP addresses. - Enable IP allowlist enforcement to restrict API access to approved addresses only. > **Best practice: include address in the IP Address list** > > We recommend you not leave the address list empty. If an account administrator enables **IP Allowlist** on the Zoom admin portal, and your app has **no approved IP addresses**, Zoom blocks all API requests from your app to that account. For information about the experience from the administrator's perspective, see [Managing the IP and domain allowlist for Marketplace apps](https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0089123). ## Adding IP addresses to the address list 1. Go to the **Created Apps** screen on the Zoom Marketplace. 2. Open your app's configuration, and go to **Basic Information** > **IP Addresses**. 3. Select **Add IP Address/CIDR**, and add the addresses your app uses. 4. Save your changes. ## IP Address format You can provide IP addresses in two formats: - Single IP address: A specific IPv4 address (e.g., `192.168.1.100`) - IP range using CIDR notation: A range of addresses (e.g., `192.168.1.0/24`) ## What Gets Blocked When an account administrator enables IP allowlisting, API requests from non-approved IP addresses are blocked at the following endpoints: - OAuth token exchange (`/oauth/token`). - Token revocation (`/oauth/revoke`). - MCP server discovery endpoint. - OpenID Connect discovery endpoint. - All other Zoom API endpoints. ## Best Practices - **Provide IP addresses early** - Configure your IP list before publishing your app to the Marketplace. - **Use IP ranges when appropriate** - If your app runs on multiple servers in the same network, use CIDR notation to cover the entire range. - **Keep your list updated** - If your infrastructure changes, update your IP list in the build flow promptly. - **Plan for redundancy** - Include all production IP addresses, including backup or failover infrastructure. > **Server to Server App** > > S2S apps are intended for customer internal developers so they do not have IP list configuration in the build flow. If you are customer internal developer building Server-to-Server app, coordinate with your admin to declare IPs that govern S2S apps within the App IP allowlist configuration.