Keygen Static IPs, Powered by QuotaGuard

Keygen officially uses QuotaGuard to give Ent customers dedicated static IPs for firewall-restricted access to Keygen Cloud.

Your customer's network gets a small, stable destination allowlist while Keygen keeps operating the licensing API.

Keygen Already Chose QuotaGuard for This Requirement

Keygen's official documentation states that it uses QuotaGuard to offer dedicated static IP addresses to Keygen Cloud customers on an Ent tier.

This is not a theoretical compatibility claim. QuotaGuard is the infrastructure behind Keygen's documented static-IP option.

A Stable Destination for Restricted Networks

Keygen's normal API hostname uses dynamic cloud addresses. An enterprise firewall that requires fixed destination IPs cannot safely maintain a narrow allowlist against that changing infrastructure. The QuotaGuard-backed endpoint gives the customer up to two stable addresses instead.

Provisioned Through Keygen

Keygen customers request this option from Keygen on an Ent tier. Keygen provisions the replacement hostname and addresses; the customer does not need to design or operate a proxy deployment.

Managed Behind the Feature

QuotaGuard supplies the static network identity and managed proxy infrastructure while Keygen owns the product experience and customer relationship.

The Base URL Changes. Your Licensing Workflow Stays With Keygen.

Keygen documents the static-IP option as a replacement API hostname. The fixed hostname resolves to the QuotaGuard-backed addresses and forwards the request to Keygen Cloud.

Replace the Keygen API Base URL

Keygen supplies the exact account-specific hostname and paths during provisioning. Put that URL in the same server-side configuration where the application currently stores the Keygen API base URL.

Allowlist Every Supplied Address

Send all addresses Keygen supplies to the customer's network team. Keygen documents up to two static IPs. Omitting one can interrupt access when traffic reaches the other healthy route.

Keep Application Security Intact

The fixed destination does not replace Keygen credentials, license validation, TLS, request signing, authorization, or rate controls. It solves the network destination requirement and nothing more.

Standard Keygen Cloud endpoint

https://api.keygen.sh/v1/accounts/example-com/licenses/actions/validate-key

Example QuotaGuard-backed endpoint from Keygen's documentation

https://a62b1d0b4983db763450411fd393b3ce-eu-west-1.getstatica.com/v1/licenses/actions/validate-key

Do Not Confuse a Fixed Destination With Fixed Outbound Identity

The same words—static IP and allowlist—describe two opposite connection problems. The direction determines which QuotaGuard architecture applies.

Keygen's Feature Is a Stable Destination

The customer application opens the connection. Its enterprise firewall needs a known destination before traffic may leave the network. The QuotaGuard-backed Keygen hostname supplies that fixed destination.

Outbound Proxy Is a Stable Source

A normal QuotaGuard outbound proxy solves the opposite requirement: your application calls a vendor, database, or client system that evaluates your application's source address.

Use the Architecture the Firewall Actually Checks

If the rule says where the customer may connect, use a stable inbound destination. If the destination checks who is connecting, use stable outbound egress. QuotaGuard supports both patterns.

Building a SaaS Product? Offer the Same Enterprise Capability

Keygen demonstrates the commercial pattern: make static destination IPs an enterprise feature, keep the product on flexible cloud infrastructure, and let QuotaGuard operate the network layer.

Read how SaaS companies can pass enterprise firewall reviews with managed static inbound IPs.

Keep Your Existing Cloud Origin

The public customer-facing address stays stable even when your actual application scales, redeploys, or moves. The forwarding target remains under your control.

Sell the Requirement Without Operating It

You can satisfy the procurement checkbox without taking ownership of proxy hosts, operating-system patches, capacity planning, health checks, failover, and after-hours infrastructure incidents.

Use Dedicated Infrastructure When Exclusivity Is Required

Standard direct plans include inbound proxy capability. When the customer requires customer-only addresses or dedicated proxy resources, use a dedicated Enterprise architecture and confirm the provisioning model with QuotaGuard engineering.

FAQs

Common questions about Keygen static IPs and QuotaGuard's inbound proxy architecture.

Does Keygen officially use QuotaGuard?

Yes. Keygen's current static-IP documentation names QuotaGuard as the provider it uses to offer dedicated static IP addresses to Keygen Cloud customers on an Ent tier.

How many static IP addresses does Keygen provide?

Keygen documents up to two static IP addresses for the replacement QuotaGuard-backed hostname. Add every address Keygen supplies to the enterprise firewall.

Can I obtain Keygen's static-IP option directly from QuotaGuard?

Keygen customers should request the Keygen-branded option through Keygen because Keygen provisions the correct account-specific hostname and forwarding route. SaaS companies building a similar feature for their own customers can work with QuotaGuard directly.

Is this an inbound or outbound proxy?

From Keygen's perspective it is an inbound proxy: customer requests enter through the QuotaGuard-backed address and are forwarded to Keygen Cloud. From the customer's firewall perspective, those same addresses are the approved outbound destinations.

Why not allowlist Keygen's ordinary cloud IP addresses?

Keygen states that its normal API IPs are dynamic and should not be allowlisted. Its dedicated static-IP option exists for customers whose networks require a small fixed destination list.

Does the static IP replace Keygen authentication?

No. A fixed destination satisfies a network rule. Keep Keygen authentication, license validation, TLS, authorization, request signatures, and other application controls in place.

Can a SaaS vendor offer the same pattern to its customers?

Yes. Configure a QuotaGuard inbound proxy to forward a stable public hostname to your existing HTTPS origin. When the enterprise contract requires customer-only addresses or dedicated resources, use an approved Enterprise architecture.

Do standard QuotaGuard plans include inbound proxy capability?

QuotaGuard documents inbound proxies as available on direct Starter plans and above, and on Micro plans and above through the Heroku, AWS, and Azure marketplaces. Dedicated customer-only infrastructure is an Enterprise configuration.

🚀 Ready to Get Started? Choose Your QuotaGuard Path

QuotaGuard STATIC

Why: You need a rock-solid, fixed IP for general API access, AI workflows, or standard third-party integrations.
Best For: Developers, startups, and general application connectivity.
Key Feature: SOCKS5 support for secure database access.
Sign Up for QG Static

QuotaGuard SHIELD

Why: You handle PHI, payment card data, or sensitive PII and require TLS encryption on the customer-to-proxy hop while preserving your application’s HTTPS session to its destination.
Best For: Regulated industries, financial services, and healthcare.
Key Feature: TLS-encrypted proxy connection with the destination HTTPS session preserved.
Sign Up for QG Shield

Trusted by Engineering Teams Everywhere

Reliability Engineered for the Modern Cloud

For over a decade, QuotaGuard has provided reliable, high-performance static IP and proxy solutions for cloud environments like Heroku, Kubernetes, and AWS.

Get the fixed identity and security your application needs today.