Allowing the scanner's IP

1 min read

Why this is needed

A scan makes a lot of requests in a short time from a single IP, exactly the pattern a WAF, rate limiter or CDN (Cloudflare, Vercel...) is built to block. If your app has one, the scan can come back marked "blocked" before it finishes.

detektd always egresses from the same fixed IP address (never rotated): that's the one to allowlist once, permanently. It's shown in the dashboard, in the panel that appears before your first scan or whenever a scan comes back blocked.

By platform

  • Cloudflare: Dashboard → Security → WAF → IP Access Rules → "Create": IP = the address shown in your dashboard, Action = "Allow". Available even on the free plan.
  • Vercel: Project → Settings → Firewall → add an "Allow" (or "Bypass") rule for that IP. Custom rules may require a paid plan.

For nginx, exclude our IP from your limit_req zone: an empty key disables the limit for that IP.

nginx
geo $detektd_ip {
    default 0;
    <IP detektd> 1;
}
map $detektd_ip $rl_key {
    0 $binary_remote_addr;   # everyone else: limited by IP
    1 "";                    # detektd: empty key = no limit
}
limit_req_zone $rl_key zone=app:10m rate=10r/s;

The fastest way: a prompt for your AI

The "Allow our IP" panel (dashboard, before your first scan or after a blocked one) ships a ready-made prompt (your URL and our IP already filled in) to paste into Cursor, Lovable, Windsurf or whatever assistant you use to configure your infra. It's the fastest path if you don't manage this by hand; the manual steps above stay under a collapsible section of that same panel for anyone who'd rather follow them directly.

The panel is guidance only: it never blocks you from starting a scan. We always egress from the same IP whether it's allowlisted or not; allowlisting just lowers the risk of being blocked by YOUR infra, not ours.

Was this article helpful?