# How to 'whitelist' IP address's that can access Node RED

**URL:** <https://discourse.nodered.org/t/how-to-whitelist-ip-addresss-that-can-access-node-red/83990>\
**Category:** FAQs\
**Tags:** security\
**Created:** [23 December 2023 16:58 UTC](https://discourse.nodered.org/t/how-to-whitelist-ip-addresss-that-can-access-node-red/83990 "2023-12-23T16:58:59Z")\
**Posts on this page:** 1\
**Showing post:** 29

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [12 January 2024 14:18 UTC](https://discourse.nodered.org/t/how-to-whitelist-ip-addresss-that-can-access-node-red/83990/29 "2024-01-12T14:18:20Z")

</div>

I have updated the security FAQ with references to Node.js security best practices, the blocklist functions and this thread.

> [@Safely accessing Node-RED over the Internet](https://discourse.nodered.org/t/safely-accessing-node-red-over-the-internet/45024):
>
> Update 2025-02-19 The best advice for most people doing home automation is still: Don't expose Node-RED to the outside world! Where you really have to have some outside access, keep it as hands-off and restricted as possible. For example, using a Telegram bot. Also keep it as minimal as possible, e.g. Don't expose the Editor - EVER! If you want to provide remote control of your heating or the precious plants in your greenhouse, provide explicit controls with strong limits. Don't expose ever…

---

_[View the full topic](https://discourse.nodered.org/t/how-to-whitelist-ip-addresss-that-can-access-node-red/83990)._
