[Action Needed] API User Security Improvements - June 30, 2025

We are implementing IP allowlisting for API use and enforcing one-time email validation for API users. This change ensures that only API users from authorized IPs with validated email addresses can access the API, providing an additional layer of security and control.

Partners can configure subnet restrictions for API users on the administrating tenant. This allows API users to make calls on behalf of analytic tenants while enforcing subnet restrictions set by the administrating tenant.

After June 30, the API allowlist and the one-time email address validation will be required for the API users to access the application.

Actions

  1. Required - Configure IP allowlisting for your API users, please follow the steps outlined in our documentation: API IP Allowlisting Instructions.
  2. Required - Make sure API users have a valid email address. To validate the email address for your API user, login to the web application with that user. You will be prompted to validate the email address.

Thank you for your prompt attention to this matter. We appreciate your cooperation as we work to enhance the security and reliability of our services.

Please let your Partner Success Manager know if you have any questions or concerns.