> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tracecat.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get Security Settings



## OpenAPI

````yaml https://platform.tracecat.com/api/openapi.json get /settings/security
openapi: 3.1.0
info:
  title: Tracecat API
  summary: Tracecat API
  description: The open source AI automation platform for security teams and agents.
  termsOfService: >-
    https://docs.google.com/document/d/e/2PACX-1vQvDe3SoVAPoQc51MgfGCP71IqFYX_rMVEde8zC4qmBCec5f8PLKQRdxa6tsUABT8gWAR9J-EVs2CrQ/pub
  contact:
    name: Tracecat Founders
    email: founders@tracecat.com
  license:
    name: AGPL-3.0
    url: https://www.gnu.org/licenses/agpl-3.0.html
  version: '1'
servers:
  - url: /api
security: []
tags:
  - name: public
    description: Public facing endpoints
  - name: workflows
    description: Workflow management
  - name: actions
    description: Action management
  - name: triggers
    description: Workflow triggers
  - name: secrets
    description: Secret management
  - name: variables
    description: Workspace variable management
paths:
  /settings/security:
    get:
      tags:
        - settings
      summary: Get Security Settings
      operationId: settings-get_security_settings
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SecuritySettingsRead'
      security:
        - APIKeyCookie: []
components:
  schemas:
    SecuritySettingsRead:
      properties:
        ip_allowlist_enabled:
          type: boolean
          title: Ip Allowlist Enabled
        ip_allowlists:
          items:
            $ref: '#/components/schemas/IPAllowlist'
          type: array
          title: Ip Allowlists
      type: object
      required:
        - ip_allowlist_enabled
        - ip_allowlists
      title: SecuritySettingsRead
      description: Organization security settings.
    IPAllowlist:
      properties:
        name:
          type: string
          maxLength: 100
          minLength: 1
          title: Name
          description: Human-readable name, e.g. 'Corporate VPN'.
        description:
          anyOf:
            - type: string
              maxLength: 500
            - type: 'null'
          title: Description
          description: Optional note on what this allowlist covers and who owns it.
        cidrs:
          items:
            type: string
          type: array
          maxItems: 50
          minItems: 1
          title: Cidrs
          description: IPv4 or IPv6 addresses or CIDR ranges.
      type: object
      required:
        - name
        - cidrs
      title: IPAllowlist
      description: A named group of allowed IP addresses or CIDR ranges.
  securitySchemes:
    APIKeyCookie:
      type: apiKey
      in: cookie
      name: fastapiusersauth

````