Skip to content
Fixedmark
Use case · Payments

Static IP for Payout APIs: Razorpay, Cashfree, Stripe

RazorpayX and Cashfree Payouts reject live payout API calls from IPs you have not whitelisted, and Stripe lets you lock secret keys to IPs you choose. On Vercel, Railway, or AWS Lambda your outbound IP changes, so send payout calls through a static IP pair and add both addresses in the gateway dashboard.

Which payment APIs check your IP

Payout and disbursement APIs move money out of your account, so gateways add a network check on top of API keys. Rules differ by gateway:

  • RazorpayX: IP allowlisting is mandatory for Payouts, Contacts, Fund Accounts, Payout Links, and Fund Account Validation APIs in live mode. Requests from other IPs fail. You can add up to 20 IPs, and only the account Owner or an Admin can change them.
  • Cashfree Payouts: production calls must come from a whitelisted IPv4 address (up to 25), or carry an x-cf-signature header made with Cashfree's public key. The test environment has no IP check.
  • Stripe: optional. Access policies can restrict a secret or restricted key to IPv4 addresses or CIDR ranges, so a leaked key fails from anywhere else.
  • PayU: its payouts docs describe an IP check for payout requests. Confirm with PayU whether your account needs it.

Static IP or signature?

Cashfree offers a signature as an alternative to a whitelisted IP. If your stack can sign each request, you may not need a static IP for Cashfree at all. RazorpayX has no such alternative for payout APIs in live mode, so a serverless app needs a fixed egress IP there.

For Stripe, IP restriction is extra protection, not a requirement. It is worth it when your secret key lives in many environments, because a leaked key then fails from any IP but yours.

Webhooks go the other way

A static egress IP covers calls your app makes to the gateway. Webhooks are calls the gateway makes to you, so they are not affected. Verify webhook signatures as each gateway documents. If you also want to firewall your webhook endpoint, Razorpay publishes the IPs its webhooks come from.

What the proxy sees

HTTPS payout calls pass through Fixedmark as an encrypted CONNECT tunnel. Fixedmark logs the destination host, bytes, and result, never the request body, amounts, or account numbers. Add a destination allowlist such as api.razorpay.com:443 so the proxy token cannot be used to reach anything else.

Whitelist a static IP with your payment gateway

Route only the payout calls through the proxy. Checkout and other API calls can stay direct.

Fixedmark is in early access. Proxy URLs are issued at launch. Join early access to get yours when your region opens.

  1. 1
    Create a dedicated pair near the gatewayMumbai for Razorpay, Cashfree, and PayU. Virginia or Frankfurt for Stripe, depending on where your app runs.
  2. 2
    Add both IPs in the gateway dashboardIn RazorpayX, the IP allowlist is under Developer Controls in account settings and is confirmed with an OTP. In Cashfree Payouts, whitelist the IPs as its two-factor authentication docs describe. In Stripe, attach an access policy to the key.
  3. 3
    Store the proxy URLSet FIXEDMARK_PROXY_URL in your platform's environment variables, next to the gateway keys.
  4. 4
    Use a proxied client for payout callsCreate one HTTP client with the proxy and use it for payout, contact, and fund account calls only.
  5. 5
    Lock the token and test in live modeAdd the gateway's API host to the token's destination allowlist. IP checks apply only in live mode, so confirm with a small live payout and check the connection log.
// npm install undici  (undici 8 needs Node.js 22.19+)
import { fetch, ProxyAgent } from "undici";

// FIXEDMARK_PROXY_URL=https://APP_ID:TOKEN@mum.egress.fixedmark.com:443
const proxy = new ProxyAgent(process.env.FIXEDMARK_PROXY_URL);

const res = await fetch("https://api.partner.example/v1/orders", {
  dispatcher: proxy,
  headers: { authorization: `Bearer ${process.env.PARTNER_API_KEY}` },
});
console.log(res.status, await res.json());

Pro plan

Planned launch pricing

A dedicated IP pair for one production app and its bank or partner allowlists.

Price
$29/mo
IPs
Dedicated IP pair, 1 region
Included
500,000 requests, 200 GB

Planned launch pricing. Available at launch. Regions at launch: Mumbai, Singapore, Frankfurt, New York, and Virginia.

Frequently asked questions

Is IP whitelisting mandatory for RazorpayX payouts?

Yes, in live mode. RazorpayX requires allowlisted IPs for Payouts, Contacts, Fund Accounts, Payout Links, and Fund Account Validation API requests. Requests from other IPs fail. Test mode has no IP check.

How many IPs can I whitelist in RazorpayX and Cashfree?

RazorpayX accepts up to 20 IPs. Cashfree Payouts accepts up to 25 IPv4 addresses. A Fixedmark pair uses two slots.

Does Stripe require a static IP?

No. Stripe lets you restrict API keys to IP addresses as an optional safeguard. If you turn it on, every request with that key must come from an allowed IP.

Do I need a static IP to receive payment webhooks?

No. Webhooks are sent from the gateway to your server, so your outbound IP does not matter. Verify webhook signatures instead.

Make it fixed.

Fixedmark is in early access. Join the list to get dedicated static IPs when your region opens.