Platform & Security
An IP whitelist (allowlist) is a list of IP addresses from which an exchange API key, a webhook endpoint or a server may be used; requests from any other address are rejected, so a stolen key or a forged webhook is useless unless the attacker also controls a listed address.
Credentials leak; addresses are harder to steal. Binding an API key to the execution servers' addresses means that even a leaked key cannot be used from an attacker's machine, and several exchanges expire unrestricted keys after a period for exactly that reason. On the webhook side, verifying that a request really comes from TradingView's published addresses, or from an address you control, is what makes a URL-based webhook safe to use for live trading, since TradingView cannot send authentication headers.
AlgoVesta sends crypto orders from execution servers with fixed public IP addresses that are shown in the dashboard and in the exchange setup guides, so you can add them to your API key's allowlist; the servers are consistent, and a key restricted to them cannot be used from anywhere else even if it leaks. For TradingView webhooks, live execution is accepted only when the request comes from TradingView's published IP addresses or from an address you have allowlisted for that strategy; requests from elsewhere are logged and not traded, and an empty or unparseable source address never counts as verified. The platform never asks you to whitelist its main server, which stays behind a CDN. See Supported exchanges and the TradingView bot page.
A trader creates a Bybit trade-only key, restricts it to the two execution IP addresses listed in the dashboard, and connects it. Months later the secret appears in a leaked file. Anyone trying to use it from another machine is rejected by Bybit, while AlgoVesta's servers continue to trade normally, and the trader rotates the key at leisure.