> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tracecat.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Update Security Settings

> Update the organization IP allowlist.

Enabling a non-empty allowlist that excludes the caller's own IP is
rejected so an admin cannot lock themselves out of the organization.



## OpenAPI

````yaml https://platform.tracecat.com/api/openapi.json patch /settings/security
openapi: 3.1.0
info:
  title: Tracecat API
  summary: Tracecat API
  description: The open source AI automation platform for security teams and agents.
  termsOfService: >-
    https://docs.google.com/document/d/e/2PACX-1vQvDe3SoVAPoQc51MgfGCP71IqFYX_rMVEde8zC4qmBCec5f8PLKQRdxa6tsUABT8gWAR9J-EVs2CrQ/pub
  contact:
    name: Tracecat Founders
    email: founders@tracecat.com
  license:
    name: AGPL-3.0
    url: https://www.gnu.org/licenses/agpl-3.0.html
  version: '1'
servers:
  - url: /api
security: []
tags:
  - name: public
    description: Public facing endpoints
  - name: workflows
    description: Workflow management
  - name: actions
    description: Action management
  - name: triggers
    description: Workflow triggers
  - name: secrets
    description: Secret management
  - name: variables
    description: Workspace variable management
paths:
  /settings/security:
    patch:
      tags:
        - settings
      summary: Update Security Settings
      description: |-
        Update the organization IP allowlist.

        Enabling a non-empty allowlist that excludes the caller's own IP is
        rejected so an admin cannot lock themselves out of the organization.
      operationId: settings-update_security_settings
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SecuritySettingsUpdate'
        required: true
      responses:
        '204':
          description: Successful Response
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
      security:
        - APIKeyCookie: []
components:
  schemas:
    SecuritySettingsUpdate:
      properties:
        ip_allowlist_enabled:
          type: boolean
          title: Ip Allowlist Enabled
          description: >-
            Restrict organization API access to the configured IP allowlists.
            Has no effect while no allowlists exist.
          default: false
        ip_allowlists:
          items:
            $ref: '#/components/schemas/IPAllowlist'
          type: array
          maxItems: 100
          title: Ip Allowlists
          description: Named groups of allowed IP addresses or CIDR ranges.
      type: object
      title: SecuritySettingsUpdate
      description: Organization security settings.
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    IPAllowlist:
      properties:
        name:
          type: string
          maxLength: 100
          minLength: 1
          title: Name
          description: Human-readable name, e.g. 'Corporate VPN'.
        description:
          anyOf:
            - type: string
              maxLength: 500
            - type: 'null'
          title: Description
          description: Optional note on what this allowlist covers and who owns it.
        cidrs:
          items:
            type: string
          type: array
          maxItems: 50
          minItems: 1
          title: Cidrs
          description: IPv4 or IPv6 addresses or CIDR ranges.
      type: object
      required:
        - name
        - cidrs
      title: IPAllowlist
      description: A named group of allowed IP addresses or CIDR ranges.
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
        input:
          title: Input
        ctx:
          type: object
          title: Context
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError
  securitySchemes:
    APIKeyCookie:
      type: apiKey
      in: cookie
      name: fastapiusersauth

````