> For the complete documentation index, see [llms.txt](https://dev.indodana.id/indodana-paylater/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://dev.indodana.id/indodana-paylater/go-live-preparation/whitelist-ip.md).

# Whitelist IP

{% hint style="danger" %}
⚠️ Important Security Notice: Do Not Implement SSL/TLS Pinning

Please do not perform SSL/TLS certificate or public key pinning on Indodana API endpoints (`*.indodana.id` / `*.indodana.com`).

**Why?** Indodana periodically rotates SSL/TLS certificates for security and infrastructure maintenance. If your system hardcodes or pins our SSL certificate/public key, your API integration will immediately break during a certificate rotation, leading to failed payment transactions.

**Required Setup:** Indodana periodically rotates SSL certificates for infrastructure maintenance and security updates. Hardcoding or pinning certificates will cause your API integration to break during routine rotations, resulting in failed payment transactions. Standard HTTPS/TLS validation using standard system Root CA trust stores is fully secure and sufficient
{% endhint %}

Please make sure to include our IPs below to your Whitelist IP list based on your corresponding integration environment:

| Sandbox        | Production     |
| -------------- | -------------- |
| 34.101.105.81  | 34.101.73.168  |
| 34.101.46.55   | 34.101.126.214 |
| 34.128.121.174 | 34.101.175.244 |
|                | 34.128.80.135  |
|                |                |
|                |                |
