> ## Documentation Index
> Fetch the complete documentation index at: https://docs.deck.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Static IPs

> Run every task against a source from a fixed IP range you can allowlist.

<Note>
  Available on Enterprise plans as an add-on.
</Note>

By default, Deck picks the IP address that gives each task run against a source the best chance of succeeding. For sources that only accept allowlisted IP addresses, static IPs send every task run from a fixed range owned by Deck.

Static IPs are a setting on the source. Every credential, task, trigger, and task run against the source inherits it.

If the static IP range is unavailable, task runs against the source can fall back to Deck's default IPs. Those task runs come from addresses outside the range, so a source that enforces its allowlist may reject them.

## Turning static IPs on

Turn on the **Static IPs** toggle on the source's detail page in the [Console](https://console.deck.co), or set `network` on [`POST /sources`](/api-reference/sources/create-a-source) or [`PATCH /sources/{source_id}`](/api-reference/sources/update-a-source):

```json theme={null}
{
  "type": "website",
  "website": { "url": "https://portal.example.com" },
  "network": { "type": "static_ips" }
}
```

`network` is always returned on the source. A source using static IPs also carries the range under `network.static_ips`:

```json theme={null}
{
  "id": "src_AbC123xYz456",
  "object": "source",
  "name": "Acme Portal",
  "type": "website",
  "website": { "url": "https://portal.example.com" },
  "network": {
    "type": "static_ips",
    "static_ips": { "cidr": "203.0.113.0/26" }
  },
  "created_at": "2026-08-24T12:00:00Z",
  "updated_at": "2026-08-24T12:00:00Z",
  "request_id": "req_a1b2c3d4"
}
```

To turn static IPs off, send `"network": { "type": "default" }`. Omitting `network` on create gives the source Deck's default network, and omitting it on update leaves the setting unchanged.

## Getting the range

The range is available from the [Console](https://console.deck.co) and the API. In the Console, it appears on the source's detail page once static IPs are on. To get it before you turn static IPs on, so the source's allowlist is in place before the first task run, call [`GET /static-ips`](/api-reference/platform/retrieve-the-static-ip-range):

```json theme={null}
{
  "object": "static_ips",
  "cidr": "203.0.113.0/26",
  "request_id": "req_a1b2c3d4"
}
```

`cidr` is the range to allowlist, and it's the same for every source in your organization. Allowlist the whole range, since the specific addresses your runs use can change at any time. `cidr` is omitted until static IPs are enabled for your organization.

## Range changes

Deck gives 30 days' notice before changing the range. From the start of the notice window, the API returns the new range, and the old range keeps working until the window closes. A session never changes IP address during its lifetime.

## Errors

Any of the following returns `invalid_field_value`:

* A `network.type` other than `default` or `static_ips`.
* `network.static_ips` on create or update. The range is read-only.
* A `session_id` from a session that didn't start on static IPs, used for a static-IP source. Start a new session instead.

Setting `network.type` to `static_ips` before static IPs are enabled for your organization returns `feature_not_available`.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.