---
description: Restrict access to your Capawesome Cloud organization by IP address or country. Set up an IP allowlist or country allowlist for your mobile team.
title: Network Restrictions for Organizations - Capawesome
image: https://capawesome.io/docs/assets/images/social/cloud/organizations/network-restrictions.png
---

<!doctype html> 

[Skip to content ](#network-restrictions) 

[📲 Introducing **Build Sharing** — get your builds onto testers' devices with a link & QR code. No account required. ](/blog/share-mobile-app-builds-with-testers/) 

* [ SDKs ](/docs/sdks/)
* [ Formbricks ](/docs/sdks/capacitor/formbricks/)
* [ Geocoder ](/docs/sdks/capacitor/geocoder/)
* [ Google Sign-In ](/docs/sdks/capacitor/google-sign-in/)
* [ Grafana Faro ](/docs/sdks/capacitor/grafana-faro/)
* [ Gyroscope ](/docs/sdks/capacitor/gyroscope/)
* [ Haptics ](/docs/sdks/capacitor/haptics/)
* [ Home Indicator ](/docs/sdks/capacitor/home-indicator/)
* [ In-App Browser ](/docs/sdks/capacitor/in-app-browser/)
* [ Install Referrer ](/docs/sdks/capacitor/install-referrer/)
* [ Intercom ](/docs/sdks/capacitor/intercom/)
* [ Intune ](/docs/sdks/capacitor/intune/)
* [ Keep Awake ](/docs/sdks/capacitor/keep-awake/)
* [ libSQL ](/docs/sdks/capacitor/libsql/)
* [ Light Sensor ](/docs/sdks/capacitor/light-sensor/)
* [ Live Update ](/docs/sdks/capacitor/live-update/)
* [ Localization ](/docs/sdks/capacitor/localization/)
* [ Mail Composer ](/docs/sdks/capacitor/mail-composer/)
* [ Managed Configurations ](/docs/sdks/capacitor/managed-configurations/)
* [ Maps Launcher ](/docs/sdks/capacitor/maps-launcher/)
* [ Media Session ](/docs/sdks/capacitor/media-session/)
* [ ML Kit ](/docs/sdks/capacitor/mlkit/)
* [ Navigation Bar ](/docs/sdks/capacitor/navigation-bar/)
* [ Network ](/docs/sdks/capacitor/network/)
* [ NFC ](/docs/sdks/capacitor/nfc/)
* [ Node.js ](/docs/sdks/capacitor/nodejs/)
* [ OAuth ](/docs/sdks/capacitor/oauth/)
* [ Passkeys ](/docs/sdks/capacitor/passkeys/)
* [ Password Autofill ](/docs/sdks/capacitor/password-autofill/)
* [ PDF Generator ](/docs/sdks/capacitor/pdf-generator/)
* [ PDF Viewer ](/docs/sdks/capacitor/pdf-viewer/)
* [ Pedometer ](/docs/sdks/capacitor/pedometer/)
* [ Permissions ](/docs/sdks/capacitor/permissions/)
* [ Phone Dialer ](/docs/sdks/capacitor/phone-dialer/)
* [ Photo Editor ](/docs/sdks/capacitor/photo-editor/)
* [ Photo Manipulator ](/docs/sdks/capacitor/photo-manipulator/)
* [ PixLive ](/docs/sdks/capacitor/pixlive/)
* [ PostHog ](/docs/sdks/capacitor/posthog/)
* [ Printer ](/docs/sdks/capacitor/printer/)
* [ Privacy Screen ](/docs/sdks/capacitor/privacy-screen/)
* [ Proximity Sensor ](/docs/sdks/capacitor/proximity-sensor/)
* [ Purchases ](/docs/sdks/capacitor/purchases/)
* [ RealtimeKit ](/docs/sdks/capacitor/realtimekit/)
* [ Root Detection ](/docs/sdks/capacitor/root-detection/)
* [ Screen Brightness ](/docs/sdks/capacitor/screen-brightness/)
* [ Screen Orientation ](/docs/sdks/capacitor/screen-orientation/)
* [ Screen Reader ](/docs/sdks/capacitor/screen-reader/)
* [ Screenshot ](/docs/sdks/capacitor/screenshot/)
* [ Secure Preferences ](/docs/sdks/capacitor/secure-preferences/)
* [ Settings Launcher ](/docs/sdks/capacitor/settings-launcher/)
* [ Shake ](/docs/sdks/capacitor/shake/)
* [ Silent Mode ](/docs/sdks/capacitor/silent-mode/)
* [ SIM ](/docs/sdks/capacitor/sim/)
* [ SMS Composer ](/docs/sdks/capacitor/sms-composer/)
* [ Speech Recognition ](/docs/sdks/capacitor/speech-recognition/)
* [ Speech Synthesis ](/docs/sdks/capacitor/speech-synthesis/)
* [ Share Target ](/docs/sdks/capacitor/share-target/)
* [ Square Mobile Payments ](/docs/sdks/capacitor/square-mobile-payments/)
* [ SQLite ](/docs/sdks/capacitor/sqlite/)
* [ Superwall ](/docs/sdks/capacitor/superwall/)
* [ System WebView ](/docs/sdks/capacitor/system-webview/)
* [ Tauri ](/docs/sdks/capacitor/tauri/)
* [ Text Interaction ](/docs/sdks/capacitor/text-interaction/)
* [ Text Zoom ](/docs/sdks/capacitor/text-zoom/)
* [ Thermal State ](/docs/sdks/capacitor/thermal-state/)
* [ Toast ](/docs/sdks/capacitor/toast/)
* [ Torch ](/docs/sdks/capacitor/torch/)
* [ Vault ](/docs/sdks/capacitor/vault/)
* [ Volume ](/docs/sdks/capacitor/volume/)
* [ Wallet ](/docs/sdks/capacitor/wallet/)
* [ Wifi ](/docs/sdks/capacitor/wifi/)
* [ YouTube Player ](/docs/sdks/capacitor/youtube-player/)
* [ Zip ](/docs/sdks/capacitor/zip/)
* [ Cordova ](/docs/sdks/cordova/)
* [ Cloud ](/docs/cloud/)
* [ Integrations ](/docs/cloud/live-updates/integrations/)
* Concepts
* Reference
* [ Troubleshooting ](/docs/cloud/live-updates/troubleshooting/)
* [ FAQ ](/docs/cloud/live-updates/faq/)
* [ Native Builds ](/docs/cloud/native-builds/)
* [ Set Up Environments ](/docs/cloud/native-builds/environments/)
* [ Set Up Native Configurations ](/docs/cloud/native-builds/native-configurations/)
* [ Auto-Increment Build Numbers ](/docs/cloud/native-builds/auto-incrementing-build-numbers/)
* [ Configure the Web Build Script ](/docs/cloud/native-builds/web-build-script/)
* [ Build from a Monorepo ](/docs/cloud/native-builds/monorepo/)
* [ Use pnpm, Yarn, or bun ](/docs/cloud/native-builds/package-managers/)
* [ Install Private npm Packages ](/docs/cloud/native-builds/npm-private-registry/)
* [ Override the Java Version ](/docs/cloud/native-builds/override-java-version/)
* [ Custom iOS Provisioning Profiles ](/docs/cloud/native-builds/custom-ios-provisioning-profiles/)
* [ Build without Git ](/docs/cloud/native-builds/build-without-git/)
* [ Access Git Behind a Firewall ](/docs/cloud/native-builds/firewall-access/)
* [ Integrations ](/docs/cloud/native-builds/integrations/)
* Reference
* [ Troubleshooting ](/docs/cloud/native-builds/troubleshooting/)
* [ FAQ ](/docs/cloud/native-builds/faq/)
* [ App Store Publishing ](/docs/cloud/app-store-publishing/)
* [ Submit a Build ](/docs/cloud/app-store-publishing/submit-a-build/)
* [ Submit Automatically After a Build ](/docs/cloud/app-store-publishing/submit-automatically/)
* [ Troubleshooting ](/docs/cloud/app-store-publishing/troubleshooting/)
* [ FAQ ](/docs/cloud/app-store-publishing/faq/)
* [ Automations ](/docs/cloud/automations/)
* [ Reference ](/docs/cloud/automations/reference/)
* [ Troubleshooting ](/docs/cloud/automations/troubleshooting/)
* [ FAQ ](/docs/cloud/automations/faq/)
* [ Assist ](/docs/cloud/assist/)
* [ CLI ](/docs/cloud/cli/)
* APIs and SDKs
* [ Webhooks ](/docs/cloud/webhooks/)
* [ Integrations ](/docs/cloud/integrations/)
* Notifications
* Account
* [ Organization ](/docs/cloud/organizations/)
* [ Two-Factor Enforcement ](/docs/cloud/organizations/two-factor-authentication/)
* Network Restrictions [ Network Restrictions ](/docs/cloud/organizations/network-restrictions/)
* [ Audit Logs ](/docs/cloud/organizations/audit-logs/)
* [ Billing ](/docs/cloud/organizations/billing/)
* [ License Keys ](/docs/cloud/license-keys/)
* [ AI ](/docs/ai/)
* [ Insiders ](/docs/insiders/)
* [ Billing & Plans ](/docs/insiders/billing-and-plans/)
* [ FAQ ](/docs/insiders/faq/)
* [ License ](https://capawesome.io/legal/eula/)
* [ Support ](/docs/support/)
* [ Contributing ](/docs/contributing/)
* Contributing code
* [ Code of Conduct ](/docs/contributing/code-of-conduct/)
* [ Questions ](https://docs.github.com/en/discussions/collaborating-with-your-community-using-discussions/participating-in-a-discussion#creating-a-discussion)
* [ Blog ](/blog/)
* Categories

# Network Restrictions[¶](#network-restrictions "Permanent link")

Network restrictions limit which networks may reach your [organization](/docs/cloud/organizations/). You can allow access from specific IP addresses and CIDR ranges, from specific countries, or both. Both restrictions are disabled by default.

## How Network Restrictions Work[¶](#how-network-restrictions-work "Permanent link")

The two restrictions are independent, and you can enable either one or both:

* **IP allowlist** — exact IPv4 and IPv6 addresses and CIDR ranges.
* **Country allowlist** — ISO 3166-1 alpha-2 country codes, such as `DE` or `US`.

If you enable both, a request must satisfy both to be allowed. An empty allowlist means that restriction is switched off.

Both restrictions fail closed. If a restriction is enabled and the IP address or country of a request cannot be determined, the request is denied. Requests coming from the Tor network never match a country allowlist.

Warning

An IP allowlist and a country allowlist are not equally strong. An IP allowlist is a real perimeter. A country allowlist is a coarse filter that anyone can work around by renting a server in an allowed country. Don't rely on a country allowlist alone where you need a security boundary.

## What Is Restricted[¶](#what-is-restricted "Permanent link")

Network restrictions apply to requests made with a session (the Console) and with an [API token](/docs/cloud/accounts/tokens/) (the CLI and the Cloud API). They also apply to SSO sign-in, and to accepting an invitation to the organization.

Members who are not part of the organization see the usual authorization error and are never told that the organization restricts access by network.

## Restricting Access by IP Address[¶](#restricting-access-by-ip-address "Permanent link")

1. Go to the **Settings** page in the [Capawesome Cloud Console](https://console.cloud.capawesome.io/organizations/%5F/settings).
2. Scroll to the **Security** section.
3. Enable **Restrict access by IP address**.
4. Enter each IP address or CIDR range and press **Enter** after each one.
5. Click on the **Save** button.

![Security settings of an organization](/docs/assets/images/screenshots/cloud-organization-security-settings.png)

Both address families are supported, as single addresses or as CIDR ranges — for example `203.0.113.4`, `203.0.113.0/24`, `2001:db8::1`, or `2001:db8::/32`. You can add up to 250 entries.

To turn the restriction off again, disable **Restrict access by IP address** and save.

## Restricting Access by Country[¶](#restricting-access-by-country "Permanent link")

1. Go to the **Settings** page in the [Capawesome Cloud Console](https://console.cloud.capawesome.io/organizations/%5F/settings).
2. Scroll to the **Security** section.
3. Enable **Restrict access by country**.
4. Select each country you want to allow.
5. Click on the **Save** button.

You can add up to 250 countries. The country of a request is determined from its IP address, so a member connecting through a VPN or proxy in another country is treated as being in that country.

To turn the restriction off again, disable **Restrict access by country** and save.

## Avoiding Lockout[¶](#avoiding-lockout "Permanent link")

Because you are subject to your own allowlist, an allowlist that excludes you is rejected when you save it. Make sure your own IP address and country are covered before saving.

You can look them up on the [Sessions](https://console.cloud.capawesome.io/settings/sessions) page, which shows the IP address and country of your current session. The Console links to it from both fields.

Keep in mind that this protects only you. Other members, and any automation using an API token, can still be locked out by an allowlist that doesn't cover them. Before you save, consider:

* **Members working remotely or from other offices.** Home connections usually have dynamic IP addresses that change without notice.
* **CI/CD pipelines.** A pipeline running on GitHub Actions, GitLab CI, or a similar hosted runner authenticates with an [API token](/docs/cloud/accounts/tokens/) and is subject to the IP allowlist. Either allowlist your provider's egress ranges, or use Capawesome-hosted builds, which are not restricted.
* **Members travelling abroad**, if you use a country allowlist.

## Regaining Access[¶](#regaining-access "Permanent link")

If everyone with permission to change the settings ends up outside the allowlist, the restriction can no longer be lifted from the Console — the check runs before the request reaches the settings. In that case, [contact Capawesome support](/docs/support/) to have the restriction removed.

## Next Steps[¶](#next-steps "Permanent link")

* [Roles & permissions](/docs/cloud/organizations/roles-and-permissions/) — control what each member can do.
* [Two-factor enforcement](/docs/cloud/organizations/two-factor-authentication/) — require 2FA for members.
* [Single sign-on (SSO)](/docs/cloud/organizations/sso/) — enforce SSO for your members.
* [Audit logs](/docs/cloud/organizations/audit-logs/) — review actions across the organization.

August 7, 2026 

Back to top

```json
{"@context": "https://schema.org", "@graph": [{"@type": "TechArticle", "@id": "https://capawesome.io/docs/cloud/organizations/network-restrictions/#article", "headline": "Network Restrictions for Organizations", "name": "Network Restrictions for Organizations", "description": "Restrict access to your Capawesome Cloud organization by IP address or country. Set up an IP allowlist or country allowlist for your mobile team.", "inLanguage": "en", "url": "https://capawesome.io/docs/cloud/organizations/network-restrictions/", "mainEntityOfPage": "https://capawesome.io/docs/cloud/organizations/network-restrictions/", "author": {"@type": "Organization", "name": "Capawesome", "url": "https://capawesome.io", "logo": {"@type": "ImageObject", "url": "https://capawesome.io/assets/images/logo.svg"}}, "publisher": {"@type": "Organization", "name": "Capawesome", "url": "https://capawesome.io", "logo": {"@type": "ImageObject", "url": "https://capawesome.io/assets/images/logo.svg"}}}]}
```
