Help Center/ API Gateway/ User Guide/ Configuring a Credential Policy/ Credential Access Control Policy
Updated on 2025-01-10 GMT+08:00

Credential Access Control Policy

Credential access control protects backend services by controlling the IP addresses of credentials that access APIs. You can configure an access control policy to allow or forbid a credential with a specified IP address to access an API.

Configuring a Credential Access Control Policy

  1. Go to the APIG console.
  2. Select a gateway at the top of the navigation pane.
  1. In the navigation pane, choose API Management > Credentials.
  2. Click the name of the target credential.
  3. In the Access Control Policy area, click Bind.
  4. Set the parameters according to the following table.

    Table 1 Access control policy configuration

    Parameter

    Description

    Effect

    Access control type. Options:

    • Allow: Only clients with specified IP addresses are allowed to call APIs to which the credential is bound.
    • Deny: Clients with specified IP addresses are not allowed to call APIs to which the credential is bound.

    IP Addresses

    Click Add IP Address to add IP addresses.

  5. After the configuring is complete, click OK.