Skip to content
Fixedmark
Use case · Indian fintech

Static IP for Bank, UPI, and GSP APIs in India

Indian banks, UPI partner banks, and GST Suvidha Providers usually accept API calls only from server IPs you have whitelisted with them. Fixedmark gives your app a dedicated static IP pair in Mumbai, so you whitelist once and keep deploying on Vercel, Railway, or any serverless platform.

Why Indian financial APIs require whitelisted IPs

Corporate banking APIs for payouts, account validation, and virtual accounts are a common example. Banks treat the source IP as one layer of authentication on top of client certificates, keys, and signed payloads. During onboarding you fill in a form listing your production server IPs, and the bank's network team adds them to its firewall. Requests from any other address are dropped before they reach the API.

The same pattern shows up across the stack. UPI apps and payment service providers integrate through NPCI member partner banks, which whitelist the technology provider's servers. GST e-invoicing and e-way bill integrations go through GST Suvidha Providers, which commonly ask for the IPs that will call their APIs. Insurers, NBFC partners, and credit bureaus often follow the same process.

The problem with deploying on modern platforms

Whitelisting changes at a bank can take days or weeks, and each change goes through a ticket. That works for a fixed data center. It breaks when your backend runs on Vercel Functions, Railway, Render, or AWS Lambda, where the outbound IP changes on redeploys, cold starts, or region moves. Native static IP options exist on some platforms, but they cost around $100 per month per project or set on Vercel and Render, and some are shared with other customers.

With Fixedmark, the whitelisted addresses belong to your account, not to a server. You can move from Railway to Render, split a monolith into functions, or add a staging environment, and the bank keeps seeing the same pair.

What to tell your bank or GSP

Give the bank both IPs of your pair and say they are your production egress IPs in an active-active setup. Most onboarding forms have room for at least two addresses. If the form asks for a hosting provider or data center, answer that outbound traffic leaves through a dedicated egress service in Mumbai.

Your TLS session runs end to end from your code to the bank. Fixedmark forwards the encrypted connection without decrypting it, so request bodies, signatures, and certificates are never visible to the proxy. Use a destination allowlist to restrict the proxy token to the bank's API hostname, so a leaked token cannot reach anything else.

Set up static egress for a bank API

The steps are the same for payout APIs, UPI partner banks, and GSPs. Route only the calls that need the whitelisted IP through the proxy.

Fixedmark is in early access. Proxy URLs are issued at launch. Join early access to get yours when your region opens.

  1. 1
    Create a dedicated pair in MumbaiA dedicated pair keeps your whitelist entry unique to you. Shared IPs are fine for testing, not for bank onboarding.
  2. 2
    Submit both IPs in the onboarding formList both addresses for UAT and production. Ask the bank to whitelist them for the exact API hosts and ports you will call.
  3. 3
    Store the proxy URLAdd FIXEDMARK_PROXY_URL as an environment variable on your platform, for example in Vercel project settings or Railway service variables.
  4. 4
    Send bank calls through the proxyCreate one HTTP client with the proxy configured and use it only for bank and GSP calls. Other traffic stays direct.
  5. 5
    Lock the token to the bank hostAdd a destination allowlist, such as api.yourbank.example:443, and check connection logs during your first UAT calls.
// npm install undici  (undici 8 needs Node.js 22.19+)
import { fetch, ProxyAgent } from "undici";

// FIXEDMARK_PROXY_URL=https://APP_ID:TOKEN@mum.egress.fixedmark.com:443
const proxy = new ProxyAgent(process.env.FIXEDMARK_PROXY_URL);

const res = await fetch("https://api.partner.example/v1/orders", {
  dispatcher: proxy,
  headers: { authorization: `Bearer ${process.env.PARTNER_API_KEY}` },
});
console.log(res.status, await res.json());

Pro plan

Planned launch pricing

A dedicated IP pair for one production app and its bank or partner allowlists.

Price
$29/mo
IPs
Dedicated IP pair, 1 region
Included
500,000 requests, 200 GB

Planned launch pricing. Available at launch. Regions at launch: Mumbai, Singapore, Frankfurt, New York, and Virginia.

Frequently asked questions

Why does my bank API need a static IP?

Banks whitelist the source IPs of API clients at their firewall as an extra authentication layer. Requests from addresses that are not on the list are dropped before they reach the API.

Can Fixedmark see my payout requests?

No. HTTPS requests pass through as an encrypted CONNECT tunnel. Fixedmark logs connection metadata such as destination host, bytes, and result, never request contents.

Do UPI partner banks and GSPs accept proxy IPs?

They whitelist addresses, not providers, so a dedicated IP that only your app uses fits their process. Confirm with your bank or GSP during onboarding.

Is a Mumbai region available?

Mumbai is planned for launch alongside Singapore, Frankfurt, New York, and Virginia. Fixedmark is in early access, and proxy URLs are issued at launch.

Make it fixed.

Fixedmark is in early access. Join the list to get dedicated static IPs when your region opens.