1. Overview
Sipay API Documentation
EN
  • EN
  • TR
  • Overview
    • Getting Started
    • Test Cards
    • IP Restriction
  • Authentication
    • Token Generation
      POST
  • Installments & Commission
    • Installment Details
      POST
    • Merchant Installments
      POST
    • Commission
      POST
  • HASH
    • Hash Creation
    • Hash Validation
  • Non-Secure Payment
    • Non-Secure Payment Flow
    • Non-Secure Card Payment
      POST
    • Non-Secure Recurring Payment
      POST
    • Non-Secure Insurance Payment
      POST
    • Non-Secure Pre-Authorization Payment
      POST
    • Confirm Payment
      POST
  • 3D Secure Payment
    • 3D Secure Payment Flow
    • 3D Secure Card Payment
      POST
    • 3D Secure Recurring Payment
      POST
    • 3D Secure Pre-Authorization Payment
      POST
    • Complete Payment
      POST
    • Confirm Payment
      POST
    • 3D Secure Agriculture Payment
      POST
  • Non-Secure and 3D Payment with Sipay
    • Purchase Link Example
    • Non-Secure and 3D Secure Payment with Sipay
      POST
  • Check Status
    • Check Status
  • Payment with Saved Card
    • Card Registration
    • 3D Secure Pay by Card Token
    • Non-Secure Pay by Card Token
    • Retrieving Saved Card
    • Edit Saved Card
    • Delete Saved Card
  • Recurring
    • Recurring Query Search
    • Recurring Plan Process
    • Recurring Plan Update
  • Refund
    • Refund
  • Cashout
    • Cashout to Bank
  • Webhook
    • Webhook
  • Status Codes
    • Status Codes
  1. Overview

IP Restriction

Merchant-based IP restrictions are applied to improve the security of payment requests. Once the restriction is enabled, payment requests must be sent only from pre-registered static IP addresses or supported IP ranges.

Supported IP Formats#

The following IP formats can be registered:
A single static IP address
An IP range in CIDR /24 format
Note: IP ranges in /29, /30, and /31 formats are not supported.

IP Registration Limit#

A maximum of 5 unique IP addresses or IP ranges can be registered for each merchant.
If more than five IP addresses or IP ranges are required, the following information must be provided:
A written justification for the additional IP addresses
The IP addresses or IP ranges to be registered
The transaction type or transaction types for which the IP addresses will be used
Requests for more than five IP addresses require a written justification and approval from the Sipay Risk team.

Dynamic IP Addresses#

Dynamic IP addresses are not supported. Payment requests must be sent from registered static IP addresses.
If a shared NAT infrastructure is used, the outbound public IP addresses from which the requests will be sent must be provided.

IP Registration Process#

IP registrations are performed exclusively by the Sipay Operations team through the Backoffice Admin Panel.
The following information must be included in the registration request:
The static IP address or supported /24 IP range
The transaction type or transaction types for which the IP address will be used
A written justification if more than five IP addresses are requested
Previous
Test Cards
Next
Token Generation
Built with