Déclarer une adresse IP autorisée
curl --request POST \
--url https://guichet.apidjonanko.tech/v1/merchants/me/allowed-ips \
--header 'Content-Type: application/json' \
--header 'x-api-key: <api-key>' \
--header 'x-api-secret: <api-key>' \
--data '
{
"cidr": "41.207.12.34"
}
'const options = {
method: 'POST',
headers: {
'x-api-key': '<api-key>',
'x-api-secret': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({cidr: '41.207.12.34'})
};
fetch('https://guichet.apidjonanko.tech/v1/merchants/me/allowed-ips', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://guichet.apidjonanko.tech/v1/merchants/me/allowed-ips"
payload = { "cidr": "41.207.12.34" }
headers = {
"x-api-key": "<api-key>",
"x-api-secret": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://guichet.apidjonanko.tech/v1/merchants/me/allowed-ips",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'cidr' => '41.207.12.34'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-api-key: <api-key>",
"x-api-secret: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"allowedIp": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"cidr": "<string>",
"label": "<string>"
}
}{
"success": false,
"error": {
"code": "VALIDATION_ERROR",
"message": "La requête est invalide.",
"details": {
"fields": [
"amount must be an integer number"
]
}
},
"requestId": "9f1c2b7e-4a5d-4c8f-b0a1-e2d3c4b5a697",
"timestamp": "2026-10-01T10:12:04.000Z"
}{
"success": false,
"error": {
"code": "INVALID_CREDENTIALS",
"message": "Identifiants API invalides."
},
"requestId": "9f1c2b7e-4a5d-4c8f-b0a1-e2d3c4b5a697",
"timestamp": "2026-10-01T10:12:04.000Z"
}Sécurité — IPs autorisées
Déclarer une adresse IP autorisée
Déclarez les adresses depuis lesquelles vos serveurs appellent. C’est un second facteur de fait : une clé volée ne sert à rien si elle doit être présentée depuis votre infrastructure.
POST
/
merchants
/
me
/
allowed-ips
Déclarer une adresse IP autorisée
curl --request POST \
--url https://guichet.apidjonanko.tech/v1/merchants/me/allowed-ips \
--header 'Content-Type: application/json' \
--header 'x-api-key: <api-key>' \
--header 'x-api-secret: <api-key>' \
--data '
{
"cidr": "41.207.12.34"
}
'const options = {
method: 'POST',
headers: {
'x-api-key': '<api-key>',
'x-api-secret': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({cidr: '41.207.12.34'})
};
fetch('https://guichet.apidjonanko.tech/v1/merchants/me/allowed-ips', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://guichet.apidjonanko.tech/v1/merchants/me/allowed-ips"
payload = { "cidr": "41.207.12.34" }
headers = {
"x-api-key": "<api-key>",
"x-api-secret": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://guichet.apidjonanko.tech/v1/merchants/me/allowed-ips",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'cidr' => '41.207.12.34'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-api-key: <api-key>",
"x-api-secret: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"allowedIp": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"cidr": "<string>",
"label": "<string>"
}
}{
"success": false,
"error": {
"code": "VALIDATION_ERROR",
"message": "La requête est invalide.",
"details": {
"fields": [
"amount must be an integer number"
]
}
},
"requestId": "9f1c2b7e-4a5d-4c8f-b0a1-e2d3c4b5a697",
"timestamp": "2026-10-01T10:12:04.000Z"
}{
"success": false,
"error": {
"code": "INVALID_CREDENTIALS",
"message": "Identifiants API invalides."
},
"requestId": "9f1c2b7e-4a5d-4c8f-b0a1-e2d3c4b5a697",
"timestamp": "2026-10-01T10:12:04.000Z"
}Si vous ne savez pas quelle adresse déclarer, demandez-la d’abord à
GET /merchants/me/ip-check : derrière un NAT ou un proxy sortant, ce n’est pas toujours celle que vous croyez.Adresse IPv4 seule ou plage CIDR. Pensez aux régions de secours et aux tâches de fond.Authorizations
Votre clé publique, préfixée gk_live_ (ou gk_test_).
Votre secret, préfixé gs_live_ (ou gs_test_). Affiché une seule fois, à l'émission de la clé. Il ne doit jamais quitter vos serveurs.
Body
application/json
Response
Adresse déclarée.
Show child attributes
Show child attributes
