# How to control access to private ipfs api address

**URL:** <https://discuss.ipfs.tech/t/how-to-control-access-to-private-ipfs-api-address/4428>\
**Category:** Uncategorized\
**Created:** [December 9, 2018, 8:05am UTC](https://discuss.ipfs.tech/t/how-to-control-access-to-private-ipfs-api-address/4428 "2018-12-09T08:05:56Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![aminfda](https://avatars.discourse-cdn.com/v4/letter/a/c57346/32.png) [@aminfda](https://discuss.ipfs.tech/u/aminfda)\
**Post date:** [December 9, 2018, 8:05am UTC](https://discuss.ipfs.tech/t/how-to-control-access-to-private-ipfs-api-address/4428/1 "2018-12-09T08:05:56Z")

</div>

I’ve setup a private IPFS network, which comprised of few known nodes … API of each node are now publicly available and every one who know the API ip:port and the hash can remove files. i need that API to be available only for specified origin with API key … how can i restrict the access to API? i’ve set CROS origin in config file but still every origin in their browser can call it.

---

<div class="post-metadata">

**Author:** ![koalalorenzo](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ipfs.tech/koalalorenzo/32/745_2.png) [@koalalorenzo](https://discuss.ipfs.tech/u/koalalorenzo)\
**Post date:** [December 11, 2018, 7:57am UTC](https://discuss.ipfs.tech/t/how-to-control-access-to-private-ipfs-api-address/4428/2 "2018-12-11T07:57:54Z")

</div>

You might want to change the API multi address and expose it to localhost instead. Have a look at the configuration file, you should find `Address.API` to equal `/ip4/0.0.0.0/tcp/5001`, you need to change that.

Example:

```auto
  "Addresses": {
    "API": "/ip4/127.0.0.1/tcp/5001",
    [...]
  }

```
