Authentication, and IP Whitelisting

LedgerBlock API requests require authentication and, where enabled for your merchant account, requests must originate from an approved IP address.

Authentication

Authentication is required to access protected LedgerBlock API endpoints.

Your authentication credentials identify your merchant account and authorize your application to interact with LedgerBlock services.

Authentication Headers

LedgerBlock requests use authentication information in the request headers.

Depending on the endpoint, the required headers may include:

HeaderRequiredDescription
AuthorizationYes*Authentication credential used to authorize the request
x-merchant-refYes*Identifies the merchant making the request
Content-TypeWhere applicableSpecifies the format of the request body
  • Required headers may vary by endpoint. Always check the authentication requirements shown on the specific API endpoint.

Example Request

GET https://block.fuspay.finance/api/v1/utility/operators
Authorization: Bearer YOUR_API_KEY
x-merchant-ref: YOUR_MERCHANT_REF
Content-Type: application/json

Replace the placeholder values with the credentials associated with your LedgerBlock merchant account.

Never include real API credentials in documentation, source code, frontend applications, screenshots, or publicly accessible repositories.

Merchant Reference

The x-merchant-ref header identifies the merchant associated with the API request.

Example:

x-merchant-ref: YOUR_MERCHANT_REF

The merchant reference should be included exactly as provided when the endpoint documentation specifies it as required.

Authorization

The Authorization header is used to authenticate requests to protected LedgerBlock endpoints.

Example:

Authorization: Bearer YOUR_API_KEY

Keep your API credentials on your server and never expose them in client-side applications.

Recommended Credential Handling

Store your credentials securely using environment variables or a secrets-management solution.

For example:

LEDGERBLOCK_API_KEY=your_api_key
LEDGERBLOCK_MERCHANT_REF=your_merchant_reference

Your application should read these values at runtime rather than hard-coding them into the application source code.


IP Whitelisting

IP whitelisting provides an additional layer of security by restricting API access to requests originating from approved IP addresses.

When IP whitelisting is enabled for your merchant account, LedgerBlock only accepts API requests originating from the IP addresses registered for your account.

How IP Whitelisting Works

The process is:

  1. Your server sends a request to LedgerBlock.
  2. LedgerBlock identifies the originating IP address.
  3. The IP address is checked against the IP addresses registered for your merchant account.
  4. If the IP address is authorized, the request proceeds to authentication and processing.
  5. If the IP address is not authorized, the request is rejected.

Which IP Address Should Be Whitelisted?

Whitelist the public outbound IP address used by your backend server when communicating with LedgerBlock.

Do not whitelist:

  • Your personal computer's local IP address
  • localhost
  • Private network addresses such as 192.168.x.x
  • Private network addresses such as 10.x.x.x
  • An IP address that is not used by your production server to make outbound API requests

For cloud deployments, confirm the outbound or egress IP address configured for the service.

Multiple Servers

If your application sends LedgerBlock API requests from multiple servers with different public IP addresses, each IP address that needs API access should be registered for whitelisting.

For example:

203.0.113.10
203.0.113.11
203.0.113.12

Only add IP addresses that are actually required by your integration.

Changing Your Server IP

If your production server's public IP address changes, API requests may be rejected if the new IP has not been added to your approved whitelist.

Before migrating servers or changing your infrastructure:

  1. Identify the new outbound public IP.
  2. Request that the new IP be added to your merchant whitelist.
  3. Confirm that the new IP is active.
  4. Update your application infrastructure.
  5. Verify API connectivity.

Security Best Practices

For a secure LedgerBlock integration:

  • Keep API credentials private.
  • Store credentials in environment variables or a secrets manager.
  • Make API requests from your backend rather than directly from the browser.
  • Restrict API access to known production server IP addresses where IP whitelisting is enabled.
  • Do not commit credentials to Git repositories.
  • Do not expose credentials in logs or error messages.
  • Rotate credentials if they are accidentally exposed.
  • Remove old or unused IP addresses from your whitelist.

Important: Production credentials provide access to live LedgerBlock services. Treat them as sensitive credentials and restrict access to authorized systems and personnel only.